Labour Day Special Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: suredis

IBM C1000-026 IBM Security QRadar SIEM V7.3.2 Fundamental Administration Exam Practice Test

Page: 1 / 6
Total 60 questions

IBM Security QRadar SIEM V7.3.2 Fundamental Administration Questions and Answers

Testing Engine

  • Product Type: Testing Engine
$42  $119.99

PDF Study Guide

  • Product Type: PDF Study Guide
$36.75  $104.99
Question 1

A QRadar upgrade is planned and a maintenance window is scheduled. The administrator must stage the

FIXPACK from IBM Fix Central.

Which QRadar FIXPACK file type must the administrator download?

Options:

A.

RPM

B.

IMG

C.

SFS

D.

XFS

Question 2

An administrator enabled the base license of QRadar Vulnerability Manager.

How many assets can be scanned using this license?

Options:

A.

up to 128

B.

up to 256

C.

up to 100

D.

up to 512

Question 3

An administrator wants to have all QRadar apps running on a new App Host that was configured to have

dedicated CPU, storage and memory resources for the Apps. Several issues were presented during the

installation of the App Host.

To troubleshoot, what should the administrator check?

Options:

A.

If the completion of the /opt/qradar/check_app_host.sh script was successful

B.

If port 5000 is opened on the console

C.

If an IP table entry was already created to allow traffic from the App Host IP

D.

If IP tables are disabled on the console

Question 4

An administrator needs to know if a custom rule is being correlated correctly.

Which QRadar component is responsible for this process?

Options:

A.

QRadar Event Collector

B.

QRadar Console

C.

Magistrate

D.

QRadar Event Processor

Question 5

An administrator would like to extend the functionality of QRadar using an external application.

Which file format is supported to successfully upload an application from the QRadar Console?

Options:

A.

.zip

B.

.tgz

C.

.sh

D.

.exe

Question 6

An administrator installed a new App Host and would like to move the existing applications from the Console to the App Host.

What steps should be performed?

Options:

A.

Admin Tab > Extension Management > Click to change where apps are run

B.

Admin Tab > System Settings > Move apps

C.

Admin Tab > Extension Management > Move apps

D.

Admin Tab > System and License Management > Click to change where apps are run

Question 7

An administrator needs to complete the upgrade process from V7.3.1 to V7.3.2.

What is the correct procedure?

Options:

A.

Copy the ISO file extension to the recommended directories and use this file

B.

Use the ISO file to execute the upgrade process

C.

Do a clean installation using the ISO file on a bootable USB device

D.

Copy the SFS file extension to the recommended directories and use this file

Question 8

An administrator has to change the system hardware clock of the QRadar server. The administrator has

already restarted the main services (hostservices, tomcat, hostcontext) and needs to synchronize the QRadar

Console time with the QRadar managed hosts.

Which command can the administrator use to accomplish this?

Options:

A.

/opt/qradar/support/all_servers.sh systemctl restart systemd-timedated.service

B.

/opt/qradar/support/all_servers.sh /opt/qradar/bin/time_sync.sh

C.

/sbin/hwclock –systohc /opt/qradar/bin/time_sync.sh

D.

/opt/qradar/support/all_servers.sh service ntpd restart

Question 9

An administrator has been tasked to create a saved search that shows a list of multiple login failures for a

single user by username. The administrator has done the following:

1. Selected Last Hour in the view option.

2. In the Add filter window, selected the search parameter Custom Rule [Indexed].

3. Selected Equals for Operator.

4. Selected Authentication for Rule Group.

What is the next step the administrator needs to perform for the Rule option?

Options:

A.

Select login failures followed by success to the same username

B.

Select multiple login failures from the same source

C.

Select multiple login failures to the same destination

D.

Select multiple login failures for a single username

Page: 1 / 6
Total 60 questions