An administrator needs to import a list of HR staff logins into a reference set.
Which file type can be used with the import function in the reference set editor window?
A. xml
B. csv
C. xls
D. json
Due to regulatory constraints, an administrator must increase the minimum password length and complexity.
In which QRadar section can the administrator change this setting?
A. Admin / System settings
B. Admin / Password policy
C. Admin / Security profiles
D. Admin / Authentication
An administrator has been tasked to create a saved search that shows a list of multiple login failures for a single user by username. The administrator has done the following:
1.
Selected Last Hour in the view option.
2.
In the Add filter window, selected the search parameter Custom Rule [Indexed].
3.
Selected Equals for Operator.
4.
Selected Authentication for Rule Group.
What is the next step the administrator needs to perform for the Rule option?
A. Select login failures followed by success to the same username
B. Select multiple login failures from the same source
C. Select multiple login failures to the same destination
D. Select multiple login failures for a single username
An administrator has been asked to configure a new QRadar console high availability (HA) deployment. Both the primary and secondary consoles have been installed with the QRadar software.
What should the administrator do to complete the HA configuration?
A. Add the secondary console to the deployment, and then create the HA host.
B. Reinstall the QRadar software on the secondary console using an "HA Recovery Setup".
C. Select "Secondary Host" on the wizard when adding the secondary host to the deployment.
D. Create the HA host to add the secondary console to the deployment.
An administrator needs to combine multiple extraction and calculation-based properties into a single property.
Which Ariel Query Language (AQL) statement can be used?
A. AQL-based custom properties
B. AQL functions and SELECT, FROM, or database names
C. AQL functions and AQL-based custom properties
D. AQL functions
An administrator needs to complete the upgrade process from V7.3.1 to V7.3.2. What is the correct procedure?
A. Copy the ISO file extension to the recommended directories and use this file
B. Use the ISO file to execute the upgrade process
C. Do a clean installation using the ISO file on a bootable USB device
D. Copy the SFS file extension to the recommended directories and use this file
What should an administrator do to successfully upgrade an IBM Security QRadar system from an older version?
A. Verify the upgrade path, and review the software, hardware and high availability requirements.
B. Verify the upgrade path and update the QRadar apps.
C. Review the release notes and review the architecture.
D. Review the software, hardware and high availability requirements, and consider to update the firmware on IBM Security QRadar appliances.
An administrator receives an expensive custom rule notification.
Which tool can now be enabled via the Advanced `System Settings' ?Custom Rule Settings to help troubleshoot this?
A. Offense Analysis
B. Rule Analysis
C. Custom Rule Analysis
D. Performance Analysis
An administrator enters the QRadar web console into a web browser but does not get a response. Which process is responsible for the QRadar GUI?
A. tomcat
B. consoled
C. magistrated
D. guid
An administrator needs to save a search to use it in the dashboards.
To do so, which search feature does the administrator need to select in the "Include in my Dashboard" checkbox?
A. Filter events of the last 7 days
B. Filter events of the last month
C. Filter events of the last 5 minutes
D. Group by some property