IBM QRadar SIEM V7.3.2 Deployment - C1000-055 Exam Practice Test
A deployment professional sees that there are occasional spikes in the EPS (Events per second). The host has
1000 EPS allocated but the occasional spikes go up to 1185 EPS.
What happens with the events when they go over the allocated amount?
1000 EPS allocated but the occasional spikes go up to 1185 EPS.
What happens with the events when they go over the allocated amount?
Correct Answer: C
A company has specific data retention policies to keep log data online for 5 years. The current QRadar storage will not handle this amount of data.
Which are possible solutions? (Choose two)
Which are possible solutions? (Choose two)
Correct Answer: B,D
A company has a large network with multiple segments. The manufacturing area network and the research and development (R&D) area network are separated from the product area network, and the customer does not want to run scanners through firewalls. A deployment professional has been tasked with proposing a strategy to ensure vulnerability assessment operations cover all company assets.
In addition to a scanner in the production area network, which option should the deployment professional follow?
In addition to a scanner in the production area network, which option should the deployment professional follow?
Correct Answer: A
A deployment professional has to decide where data will be stored in a newly configured environment to submit a plan for storage and network connectivity bandwidth.
Which QRadar components within a deployment can store raw or normalized events locally? (Choose two)
Which QRadar components within a deployment can store raw or normalized events locally? (Choose two)
Correct Answer: A,E
Explanation: Only visible for ExamsLabs members. You can sign-up / login (it's free).
A deployment professional needs to include a network inspection device in a banking organization as per the new security guidelines. Real time threat investigation has to be done along with the post-incident analysis. A QRadar Incident Forensics has been included in the design for post-incident forensic analysis.
Which devices should be chosen for the realtime analysis?
Which devices should be chosen for the realtime analysis?
Correct Answer: C
What are anomaly detection rules used for?
Correct Answer: B
The deployment professional needs to pull events from an HR system that are recorded in a database. Which protocol would be used to collect the data?
Correct Answer: B