Summer Special Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: exc65

An administrator is reviewing the system notifications and discovers this error:

Insufficient disk space to complete data export request.

The Export Directory property in the System Settings has the default configuration.

Which disk partition does the administrator need to check?

A.

/store/ariel/events/exports

B.

/var/log/exports

C.

/storetmp/exports

D.

/store/exports

Which is a valid routing rule combination?

A.

Drop and Bypass Correlation

B.

Drop and Log Only

C.

Forward and Bypass Correlation

D.

Bypass Correlation and Log Only

In the QRadar GUI. you notice that no new offenses were generated today. A review of the notifications shows:

MPC: Unable to create new offense. The maximum number of active offenses has been reached.

What is the default value of the maximum number?

A.

3500

B.

1500

C.

5000

D.

2500

From which two (2) resources can an administrator download QRadar security content?

A.

QRadar Application Repository

B.

IBM Applications Database

C.

IBM Fix Central

D.

IBM App Central

E.

IBM Security App Exchange

An administrator would like to optimize event and flow payload searches for log data that is stored for up to a month. What does an administrator need to do to achieve that requirement?

A.

Perform a clean on the search model.

B.

Configure the retention period for property indexes.

C.

Configure the retention period for payload indexes.

D.

Configure the retention period for search indexes.

Which profile database does the Server Discovery function use to discover several types of servers on a network?

A.

Flow profile database

B.

Network profile database

C.

Domain profile database

D.

Asset profile database

You want to use a quick filter search to look for certain elements:

. 10.100.100.*

• BlueCoat

• TCP_REFRESH_MIS

Which string provides the correct results?

A.

(10.100.100.- Bluecoat TCP_REFRESH_MIS)

B.

10.100.100.*%Bluecoat%TCP_REFRESH_MIS

C.

"10.100.100.*%AND%Bluecoat%AND%TCP_REFRESH_MIS"

D.

(10.100.100/ AND Bluecoat AND TCP_REFRESH_MIS)

A ORadar administrator is trying to tune a rule so that it cannot send an email more than 10 times in a 24-hour period. Which method can be used to accomplish this goal?

A.

Using a special rule test that limits the number of rule triggers

B.

Using the "response limiter"

C.

Tuning the rule conditions to make it trigger fewer times

D.

Using the "execute custom action" rule response