Security QRadar, Associate Analyst Flashcards
7 cards from real IBM Certification practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Security QRadar, Associate Analyst flashcards as text
Which QRadar search field would an analyst use to find all events sourced from a specific subnet, such as 192.168.1.0/24?
Answer: sourceip INCIDR '192.168.1.0/24'
In AQL, the INCIDR operator is used to match IP addresses within a specified CIDR range.
What is a QRadar 'Building Block' rule?
Answer: A rule that tests a condition and can be reused as a test component inside other rules
Building Blocks are rules that do not generate offenses on their own but can be referenced as reusable test conditions by other rules.
An analyst needs to view network communication patterns between two hosts over the past 24 hours. Which QRadar tab provides the most relevant data?
Answer: Network Activity
The Network Activity tab displays flow data (NetFlow, sFlow, J-Flow) showing communication patterns, ports, bytes, and packets between hosts.
What is the maximum number of responses a custom rule can have in IBM QRadar?
Answer: Multiple responses can be configured, including email, SNMP trap, and offense creation simultaneously
QRadar custom rules support multiple simultaneous response actions such as creating an offense, sending email, dispatching an SNMP trap, and adding to a reference set.
In QRadar's offense management, what does 'closing an offense with reason: Non-Issue' indicate?
Answer: The offense was investigated and determined to be a false positive or benign activity
Closing an offense as 'Non-Issue' documents analyst judgment that the triggered activity was not a real security threat.
Which QRadar component performs the actual correlation of events and flows against defined rules in a distributed deployment?
Answer: Event Processor
The Event Processor normalizes events and runs rule correlation; in a distributed setup multiple Event Processors share the load.
What is the function of the 'credibility' score in a QRadar offense?
Answer: It indicates how reliable the log source reporting the event is considered to be
Credibility reflects confidence in the accuracy of the reporting log source, helping analysts weigh whether an event is a genuine indicator.