New Year Special 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: save70

IBM C1000-140 Based on Real Exam Environment

Page: 2 / 2
Total 62 questions

IBM Security QRadar SIEM V7.4.3 Deployment Questions and Answers

Question 5

A QRadar deployment professional is asked to migrate the configuration of a system from Log Manager to QRadar SIEM.

How should the custom rules, saved searches, and reports be migrated?

Options:

A.

Use the QRadar config backup and restore process to transfer all configurations.

B.

Use the content management tool (CMT) to transfer the security configuration.

C.

The only option is to use the GUI to manually recreate any required content.

D.

Use rsync to transfer the contents of the /store partition to the new system.

Question 6

Which QRadar log file contains information about the rates of EPS?

Options:

A.

/var/log/eps.log

B.

/var/qradar.log

C.

/var/log/qradar.log

D.

/var/log/qradar.old

Question 7

What approach does QRadar take when it imposes EPS license (not hardware) limits on events that temporarily spike above that limit?

Options:

A.

Excessive events in a spike cause a System Notification that advises the customer to increase their EPS license allocation.

B.

QRadar EPS license allocation is implemented with a hard cutoff to ensure resources are not saturated.

C.

During the spike, excess events are written to a queue, and they are processed after the EPS rate drops.

D.

QRadar EPS licensing is measured as an average over a 24-hour period, which allows spikes to be handled gracefully.

Question 8

What must be done on all managed hosts after the restoration of a config backup on a new console?

Options:

A.

Restart the hostcontext service

B.

Re-add all managed hosts

C.

Restart the docker service

D.

Delete all users

Page: 2 / 2
Total 62 questions