Which property types can be used to reduce the overall data volume searched and shorten search time to address searches taking longer than expected?
A. Indexed properties
B. Tabled properties
C. Stored properties
D. Common properties
正解:A
解説: (Pass4Test メンバーにのみ表示されます)
質問 2:
An analyst must create a reference set collection containing the IPv6 addresses of command-and-control servers in an IBM X-Force Exchange collection in order to write a rule to detect any enterprise traffic with those malicious IP addresses.
What value type should the analyst select for the reference set?
A. IPv6
B. AlphaNumeric (Ignore Case)
C. IP
D. IPv4 or IPv6
正解:A
解説: (Pass4Test メンバーにのみ表示されます)
質問 3:
To test for authorized access to a patent, create a list that uses a custom event property for Patent id as the key, and the username parameter as the value. Data is stored in records that map a key to multiple values and every key is unique. Use this list to populate a list of authorized users.
The example above refers to what kind of reference data collections?
A. Reference map
B. Reference map of sets
C. Reference map of maps
D. Reference table
正解:B
解説: (Pass4Test メンバーにのみ表示されます)
質問 4:
What feature in QRadar uses existing asset profile data so administrators can define unknown server types and assign them to a server definition in building blocks and in the network hierarchy?
A. Server discovery
B. Server roles
C. Server profiles
D. Active servers
正解:A
解説: (Pass4Test メンバーにのみ表示されます)
質問 5:
Which two (2) aggregation types are available for the pie chart in the Pulse app?
A. Middle
B. Total
C. First
D. Average
E. Last
正解:B,C
解説: (Pass4Test メンバーにのみ表示されます)
質問 6:
What does this example of a YARA rule represent?
A. Flags containing hex sequence and str1 less than three times
B. Flags for str1 at an offset of 25 bytes into the file
C. Flags content that contains the hex sequence, and str1 greater than three times
D. Flags content that contains the hex sequence, and hex! at least three times
正解:B
解説: (Pass4Test メンバーにのみ表示されます)
質問 7:
How do events appear in QRadar if there was an error in the JSON parser for a new log source to which a custom log source extension was created?
A. CRE events
B. Parsed events
C. SIM events
D. Stored events
正解:A
解説: (Pass4Test メンバーにのみ表示されます)
大塚** -
勉強はちょっと大変だと思います。
でも最後まで頑張りました。合格できるのは何よりです。