Security QRadar, Associate Analyst Flashcards
7 cards from real IBM Certification practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Security QRadar, Associate Analyst flashcards as text
An analyst wants to identify all failed login attempts to a Windows server in the last hour using QRadar. Which event category should they filter on?
Answer: Authentication
QRadar normalizes login-related events under the 'Authentication' high-level category, which covers successful and failed authentication attempts.
What is the purpose of a QRadar 'Log Source Extension' (LSX)?
Answer: It extends or overrides an existing DSM's parsing rules to handle custom or modified log formats
An LSX allows administrators to customize how QRadar parses events from a log source without modifying the base DSM.
In IBM QRadar, what is a 'flow' in the context of Network Activity?
Answer: A summarized record of a network communication session including source/destination IP, port, bytes, and packets
A flow is a bidirectional summary record of a network session, derived from NetFlow or similar protocols, showing connection metadata but not payload content.
Which QRadar feature allows an analyst to group multiple related offenses together for coordinated investigation?
Answer: Cases (via QRadar Incident Forensics or offense notes/grouping)
QRadar allows related offenses to be linked or grouped using notes and assignments, and integrated case management tools can correlate multiple offenses.
What does the QRadar 'Relevance' score in an offense measure?
Answer: How important the targeted asset is based on its assigned weight in the asset model
Relevance reflects the importance of the targeted destination asset as defined in QRadar's asset model, prioritizing offenses targeting critical systems.
An analyst sees a QRadar rule with the test 'when the event(s) were detected by more than 1 log sources'. What type of test is this?
Answer: Multi-source accumulation test that adds confidence by requiring multiple independent sensors to detect the same event
Requiring multiple log sources to detect the same activity reduces false positives by demanding corroboration from independent devices.
What is the correct way to schedule a QRadar report to run automatically every Monday morning?
Answer: Configure the report's schedule to 'Weekly' and select Monday as the day and the desired delivery time
QRadar's reporting module includes built-in scheduling options (daily, weekly, monthly) configurable directly in the report's properties.