A ORadar administrator is trying to tune a rule so that it cannot send an email more than 10 times in a 24-hour period. Which method can be used to accomplish this goal?
Which is a benefit of a lazy search?
An administrator opens the Offenses section and goes to Rules to edit the system notification rule. What is the rule name for system notifications?
When creating an identity exclusion search, what time range do you select?
Which two (2) open standards does the QRadar Threat Intelligence app use for feeds?
A ORadar administrator needs to upgrade the system to patch a vulnerability. In what order does the administrator upgrade the managed hosts?
Before configuring a WinCollect log source, which two ports does a QRadar administrator ensure are open?
In the QRadar GUI. you notice that no new offenses were generated today. A review of the notifications shows:
MPC: Unable to create new offense. The maximum number of active offenses has been reached.
What is the default value of the maximum number?
Which is the default port for the first NetFlow flow source that is configured in QRadar?
An administrator would like to optimize event and flow payload searches for log data that is stored for up to a month. What does an administrator need to do to achieve that requirement?
From which site can you download software updates for QRadar?
What parameter contributes to the magnitude score of an offense?
When adjusting a custom email template, which two elements do you edit to include the customizations?
Which two (2) data sources can be assigned to a domain in the Domain Management function?
From which two (2) resources can an administrator download QRadar security content?
Which field is mandatory when you use the DSM Editor to map an event to a OID?
What is the primary method used by QRadar to alert users to problems?
You analyzed network flows and decided that you want to track any network bandwidth violations by any application that comes from your network source. You want to report on all applications that create traffic and the amount of data (total bytes) from each IP. You want to store the IP address, the application, and the amount of data in the reference data collection.
What type of reference data collection must you create to support this use case?