3 Months Free Update
3 Months Free Update
3 Months Free Update
In the QRadar GUI. you notice that no new offenses were generated today. A review of the notifications shows:
MPC: Unable to create new offense. The maximum number of active offenses has been reached.
What is the default value of the maximum number?
The Report wizard provides a step-by-step guide to design, schedule, and generate reports. Which three (3) key elements does the report wizard use to help you create a report?
You want to use a quick filter search to look for certain elements:
. 10.100.100.*
• BlueCoat
• TCP_REFRESH_MIS
Which string provides the correct results?
Which event advanced search query will check an IP address against the Spam X-Force category with a confidence greater than 3?
Which User Management option manages the QRadar functions that the user can access?
A ORadar administrator is trying to tune a rule so that it cannot send an email more than 10 times in a 24-hour period. Which method can be used to accomplish this goal?
Which two (2) open standards does the QRadar Threat Intelligence app use for feeds?
You analyzed network flows and decided that you want to track any network bandwidth violations by any application that comes from your network source. You want to report on all applications that create traffic and the amount of data (total bytes) from each IP. You want to store the IP address, the application, and the amount of data in the reference data collection.
What type of reference data collection must you create to support this use case?
Which is a valid statement about the process of restoring a backup archive?
An administrator wants to export a list of events to a CSV file. Which items are in the default columns of the search result?
How can you configure a log source to provide events to different domains?
A QRadar administrator needs to quickly check the disk space for all managed hosts. Which command does the administrator use?