When an Offense is triggered, it only shows the events that triggered the Offense. The analyst wants to investigate further to see more events around the incident, not only those that triggered the Offense. The analyst clicks on the event count and sees the events belonging to the Offense.
How can the analyst processed to see a more detailed picture of what occurred?
A. Right-click on the source IP, and choose More Options, then Information, and then Search Events
B. Right-click and filter on the Destination IP.
C. Right-click on the source IP, and choose View in DSM Editor.
D. Right-click on the destination IP, and choose More Options, then Raw Events.
正解:B
質問 2:
An analyst wants to create a report using the report wizard.
What are key elements used by the wizard to create the report?
A. Report templates, layout, saved searches
B. Report templates, user groups, permissions.
C. Layout, container, content
D. Report templates, layout, content.
正解:D
質問 3:
What is the reason for this system notification?
"Time synchronization to primary or Console has failed"
A. Deny ntpdate communication on port 323.
B. Deny ntpdate communication on port 223.
C. Deny ntpdate communication on port 123
D. Deny ntpdate communication on port 423.
正解:C
解説: (Pass4Test メンバーにのみ表示されます)
質問 4:
An analyst needs to review additional information about the Offense top contributors, including notes and annotations that are collected about the Offense.
Where can the analyst review this information?
A. In the bottom portion of the Offense main view
B. In the top portion of the Offense Summary window
C. In the top portion of the Offense main view
D. In the bottom portion of the Offense Summary window
正解:D
解説: (Pass4Test メンバーにのみ表示されます)
質問 5:
Which are the supported protocol configurations for Check Point integration with QRadar? (Choose two.)
A. SFTP
B. SYSLOG
C. CHECKPOINT REST API
D. OPSEC/LEA
E. JDBC
正解:B,D
質問 6:
Which QRadar component stores Event data?
A. Flow Collector
B. App Host
C. Event Processor
D. Event Collector
正解:B
質問 7:
What is the maximum time period for 3 subsequent events to be coalesced?
A. 60 seconds
B. 5 minutes
C. 10 minutes
D. 10 seconds
正解:D
解説: (Pass4Test メンバーにのみ表示されます)
質問 8:
The administrator had set up several scheduled reports that can be executed by analysts every Monday, and the first day of each month. On Thursday, an executive requests one of the weekly reports.
If the analyst executes the report on Thursday, what information will the report contain?
A. Data from Monday to Thursday from the current week.
B. Data from Monday to Wednesday from the current week.
C. Data from Monday to Sunday from the previous week.
D. Data from Thursday from the previous week to Wednesday from the current week
正解:A
原田** -
過去問でどのくらいの結果が出るか楽しみです。
C1000-018の問題を解きながら解説も理解できるので学び易いと思います。IBM好き