What is needed to send the same events and flows to separate data centers or geographically separate sites and enable data redundancy in IBM Security QRadar SIEM V7.2.8?
A. A load balancer or other method to deliver the same data to mirrored appliances.
B. Use the Backup and Recovery automation feature in QRadar and a dedicated fiber channel connection.
C. A Flashcopy or GlobalMirror License.
D. A dark fibre network and proper configuration of the backup and recovery feature.
正解:A
解説: (Pass4Test メンバーにのみ表示されます)
質問 2:
On a flow search dashboard item in IBM Security QRadar SIEM V7.2.8, search results display real-time last-minute data on chart.
What are the supported chart types?
A. Bar, Line, Pie, Table
B. Bar, Line, Histogram, Pie
C. Bar, Pie, Table, Time Series
D. Histogram, Pie, Table, Time Series
正解:C
質問 3:
Which permission can be assigned to a user from User Roles in the IBM Security QRadar SIEM V7.2.8 Console?
A. DSM Updates
B. Admin
C. Configuration Management
D. Flow Activity
正解:B
解説: (Pass4Test メンバーにのみ表示されます)
質問 4:
Which AQL query, when run from IBM Security QRadar SIEM V7.2.8, will show EPS broken down by domains?
A. select DOMAINNAME (domainqid) as LogSource, sum(eventcount) / ((max(endTime) - min(startTime)) / 1000 ) as EPS from events group by domainqid order by FPM desc last 24 hours
B. select DOMAINNAME (domainid) as LogSource, sum(eventcount) / ((max(endTime) - min(startTime)) / 1000 ) as EPS from events group by domainid order by EPS desc last 24 hours
C. select DOMAINNAME (domainid) as LogSource, sum(events) / ((max(endTime) - min(startTime)) /
1000 ) as EPS from events group by domainid order by EPS desc last 24 hours
D. select DOMAINNAME (domainid) as LogSource, sum(events) / ((max(endTime) - min(startTime)) /
1000 ) as EPS from events group by domainid order by FPM desc last 24 hours
正解:B
解説: (Pass4Test メンバーにのみ表示されます)
質問 5:
Which is an officially supported web browser for managing IBM Security QRadar SIEM V7.2.8?
A. Safari
B. Vivaldi
C. Opera Netscape
D. Mozilla Firefox ESR
正解:D
解説: (Pass4Test メンバーにのみ表示されます)
質問 6:
An Administrator working with IBM Security QRadar SIEM V7.2.8 needs to enable the PCI report template.
What is the procedure to accomplish this task?
A. Reports Tab -> Clear "Hide Inactive Reports" box -> Group List -> Compliance -> PCI
B. Report Tab -> Enable "Show all templates" -> Group List -> Compliance -> PCI
C. Admin Tab -> Reports -> Templates -> Compliance -> PCI -> uncheck "Hide Template"
D. Admin Tab -> Reports -> Templates -> Compliance -> PCI -> Select "Enable"
正解:A
解説: (Pass4Test メンバーにのみ表示されます)
質問 7:
An Administrator using IBM Security QRadar SIEM V7.2.8 is using the following RegEx:
([-+]?\d*$)
What type of information is it designed to extract?
A. Integer
B. IP address
C. Domain name
D. Port number
正解:A
解説: (Pass4Test メンバーにのみ表示されます)
質問 8:
An Administrator is unable to access the IBM Security QRadar SIEM V7.2.8 web GUI.
What could the Administrator do to determine the reason for the issue?
A. Check if the console is over the EPS and FPS license.
B. Check if the postgres database is running.
C. Check the status of ecs-ec and ecs-ep.
D. Check the status of tomcat and httpd.
正解:D
Nishi -
私はフィリピン出身です。試験に合格するにはC2150-624試験ガイドで十分です。