1.
A mail server typically communicates with 50 hosts per second in the middle of the night and then suddenly starts communicating with 1.000 hosts a second. The administrator wants to get an email alert whenever this situation is being observed. Which type of rule should an administrator create to monitor this situation?
2.
What should be the latency between the primary and secondary HA hosts?
3.
What functionalities of QRadar provide the ability to collect, understand, and properly categorize events from external sources?


 
4.
What is a benefit of enabling indexes on event properties?
5.
Which IP address of a NATed server is used to access the server from outside the network?
6.
What does Server discovery allow the QRadar administrator to do?
7.
What is used to collect netflow and jflow traffic in a QRadar Distributed Deployment?
8.
What should the format of a CSV file be while importing assets on the QRadar console?
9.
Which option needs to be specified in the syslinux configuration file to reinstall an IBM QRadar appliance via serial port from an USB flash-drive?
10.
With a Data Deletion Policy of "When storage is required", data will remain in storage until which scenario is reached?