Summer Special Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: exc65

The Use Case Manager app has an option to see MITRE heat map.

Which two (2) factors are responsible for the different colors in MITRE heat map?

A.

Number of offenses generated

B.

Number of events associated to offense

C.

Number of rules mapped

D.

Level of mapping confidence

E.

Number of log sources associated

Which two (2) types of categories comprise events?

A.

Unsupported

B.

Unfound

C.

Stored

D.

Found

E.

Parsed

An analyst is looking at flow payload. The analyst noted the payload is truncated.

|at default value size for the payload is exceeded where the payload might contain additional information that is not shown in the QRadar surface?

A.

32 bytes

B.

64 bytes

C.

256 bytes

D.

128 bytes

What does an analyst need to do before configuring the QRadar Use Case Manager app?

A.

Create a privileged user.

B.

Create an authorized service token.

C.

Check the license agreement.

D.

Run a QRadar health check.

Which two (2) of these custom property expression types are supported in QRadar?

A.

XLS

B.

YAML

C.

JSON

D.

Regex

E.

HTML

Many offenses are generated and an analyst confirms that they match some kind of vulnerability scanning.

Which building block group needs to be updated to include the source IP of the vulnerability assessment (VA) scanner to reduce the number of offenses that are being generated?

A.

Host reference

B.

Host definitions

C.

Behavior definition

D.

Device definition

QRadar analysts can download different types of content extensions from the IBM X-Force Exchange portal. Which two (2) types of content extensions are supported by QRadar?

A.

Custom Functions

B.

Events

C.

Flows

D.

FGroup

E.

Offenses

What are the behavioral rule test parameter options?

A.

Behavioral rule. Current traffic level, Predicted value

B.

Season, Anomaly detection. Current traffic trend

C.

Season, Current traffic level, Predicted value

D.

Current traffic behavior. Behavioral rule. Current traffic level

Which reference set data element attribute governs who can view its value?

A.

Tenant Assignment

B.

Origin

C.

Reference Set Management MSSP

D.

Domain

Which two (2) columns are valid for searches in the My Offenses and All Offenses tabs in QRadar?

A.

Impact

B.

Source IPs

C.

Relevance

D.

Weight

E.

Id