Sunteți pe pagina 1din 3

Sample Questions for:

Test C2150-624, IBM Security QRadar SIEM V7.2.8, Fundamental Administration

Note: The bolded response option is the correct answer

C2150-624.1.1.3
Which IBM Security QRadar SIEM V7.2.8 component uses the Custom Rules Engine (CRE) to
match events to custom rules?

A. Flow Processor
B. QFlow Collector
C. Event Collector
D. Event Processor

C2150-624.2.2.2
An Administrator is performing an IBM Security QRadar SIEM V7.2.8 High Availability (HA)
installation using the HA Wizard to configure primary and secondary hosts. The Administrator
checked that secondary HA host has a valid HA activation key.

What else does the Administrator need to validate to ensure the HA installation works well?

A. The support of virtual IP addressing.


B. The capacity of the disk on the primary HA host.
C. The secondary HA host is not part of another HA cluster.
D. The latency between primary and secondary HA host is less than 10 milliseconds.

C2150-624.3.1.5
An Administrator working with IBM Security QRadar SIEM V7.2.8 is asked to attach new log
sources for Microsoft SharePoint 2010 & 2013.

Which protocol is supported for these DSMs?

A. JDBC
B. LEEF
C. Syslog
D. WinCollect

C2150-624.3.2.5
When using IBM Security QRadar SIEM V7.2.8, which option defines the functions a user can
access?

A. user roles
B. individual users
C. network objects
D. authorized services
C2150-624.3.4.6
An Administrator needs to configure authentication types for an IBM Security QRadar SIEM
V7.2.8 system.

What are two available authentication types?

A. Telnet and SSH


B. IBM X-force and Google Account
C. RADIUS and IBM Passport Advantage
D. System Authentication and Microsoft Active Directory

C2150-624.3.5.1
An IBM Security QRadar SIEM V7.2.8 Administrator needs to create an immediate backup.

After clicking on the System Configuration button in the Admin tab, which option is found in the
Backup and Recovery configuration window?

A. Restore
B. Export Now
C. Backup Now
D. On Demand Backup

C2150-624.3.13.3
An Administrator working with IBM Security QRadar SIEM V7.2.8 has created a new report
template and is viewing reports on the Reports Tab. From this page, the Administrator wants to
generate the output of the new template.

How is this accomplished?

A. Actions -> Generate


B. Actions -> Run Report
C. Actions -> Report -> Generate
D. Actions -> Report -> Run Report

C2150-624.4.4.6
What needs to be done on the client computer before accessing the environment on a freshly
upgraded IBM Security QRadar SIEM V7.2.8 environment?

A. Reinstall the renewed Browser Extensions for QRadar.


B. Reboot the system before accessing the QRadar environment.
C. Clear the Browser Cache and the Java Cache on the computer.
D. Reinstall the Browser before accessing the QRadar environment.

C2150-624.5.2.7
How would an Administrator working with IBM Security QRadar SIEM V7.2.8 go about tuning an
existing Asset Reconciliation Exclusion rule?
A. Duplicate the rule.
B. Run the Tuning Wizard.
C. Duplicate the Reference Set.
D. Disable the threshold parameter while modifying the Rule.

C2150-624.6.5.4
When a QFlow process in the Deployment Editor on an IBM Security QRadar SIEM V7.2.8
appliance cannot establish time synchronization, it will give an error message similar to:

“Flow collector could not establish initial time synchronization”

How can this issue be resolved?

A. Restart the service.


B. Deploy full configuration.
C. Clear the value in the Time Synchronization Server IP Address field.
D. Review /var/log/qradar.log to determine the cause of the notification.

S-ar putea să vă placă și