A deployment professional sees that there are occasional spikes in the EPS (Events per second). The host has
1000 EPS allocated but the occasional spikes go up to 1185 EPS.
What happens with the events when they go over the allocated amount?
A. Events are moved to a temporary queue.
B. Events are shown normally, but no offenses are generated.
C. Events are dropped.
D. Events are shown normally, QRadar has 20% buffer.
正解:A
質問 2:
A deployment professional needs to include a network inspection device in a banking organization as per the new security guidelines. Real time threat investigation has to be done along with the post-incident analysis. A QRadar Incident Forensics has been included in the design for post-incident forensic analysis.
Which devices should be chosen for the realtime analysis?
A. Flow Collector (FC) and Flow Processor (FP)
B. Flow Collector (FC) and QRadar Network Insight (QNI)
C. Network PCAP and Flow Processor (FP)
D. QRadar Network Insight (QNI) and Flow Processor (FP)
正解:C
質問 3:
A deployment professional needs to create a SIEM architecture plan. The deployment professional needs to consider applying a set of security policies (or questions) about the client's network and monitor the policies for changes. It is important also to query all network connections, compare device configurations, filter the network topology, and simulate the possible effects of updating device configurations.
Which component can be added to the deployment to meet this security business objective?
A. QRadar Vulnerability Manager
B. QRadar Incident Forensics
C. QRadar Risk Manager
D. QRadar Network Insights
正解:A
質問 4:
A deployment professional needs to add a new log source using the Log File protocol. The log source should be limited to 2000 EPS.
Which option of a log source should be configured?
A. Maximum EPS
B. Maximum FPM
C. FPM Throttle
D. EPS Throttle
正解:A
質問 5:
A deployment professional needs to install a new QRadar application downloaded from the IBM Security App Exchange.
Which option would the deployment professional select from the QRadar Console GUI under Admin: System Configuration to install the downloaded application?
A. Application Management.
B. Content Management.
C. Extensions Management.
D. Customization Management.
正解:B
安川** -
この1冊に詰まっています。C1000-055合格に必要な力を手に入れました。ゼロから丁寧に解説されていて解りやすい。