1.
A Deployment Professional has detected a big spike in a customer's "Malware infection detected" rule that monitors their endpoint anti-virus solution. The spike happened over the weekend, but when the rule was checked, it was not changed. Since Monday morning, the rule has spiked and has not yet stopped generating offenses. What was added to the customer's QRadar log sources that caused this problem?
2.
In IBM Security QRadar SIEM V7.2.7, the number of Aggregated Data Management Views were increased. How many additional views were added?
3.
You are tasked with configuring IBM Security QRadar SIEM V7.2.7 to pull a log file that generated daily at midnight from a custom application on a Microsoft© Windows Server. Which log source protocol should be used to accomplish this task?
4.
A Deployment Professional has a reference list of usernames that is used in rules. The Deployment Professional needs to be able to remove a username from the reference list when an offense is detected from a log event. How can a Deployment Professional accomplish this goal?
5.
A Deployment Professional has come on-site to upgrade a IBM Security QRadar SIEM V7.2.7 deployment to a new fix level. Before running the upgrade, the software and fix versions must be verified. What must the Deployment Professional verify?
6.
A Deployment Professional has been asked to create a new dashboard which consists of utilizing a saved search. Which box should be checked when creating this search?
7.
A Deployment Professional is performing a new deployment, and the customer wants to monitor network traffic by sending raw data packets from a network device to IBM Security QRadar SEAM V7.2.7. Which method should be used?
8.
A Deployment Professional was asked to investigate the following error: Custom Rule Engine has detected a total of 20487 dropped event(s). 20487 event(s) were dropped in the last 62 seconds. Queue is at 99 percent capacity The Deployment Professional needs to run the command "/opt/qradar/bin/findExpensiveCustomRules.sh" to gather the necessary troubleshooting logs. When should this command be run?
9.
What is the impact on network bandwidth when selecting 'Global' on a rule instead of 'Local' in a distributed environment?
10.
A Deployment Professional using IBM Security QRadar SIEM V7.2.7 needs to discover all mail servers, but some of the mail servers are listening on TCP port 10025. Which server type and port could be configured in server discovery to accomplish this goal?