On the Reports tab in QRadar. what does the message "Queued (position in the queue)" indicate when generating a report?
What process is used to perform an IP address X-Force Exchange Lookup in QRadar?
What right-click menu option can an analyst use to find information about an IP or URL?
Which two (2) columns are valid for searches in the My Offenses and All Offenses tabs in QRadar?
On the Log Activity tab in QRadar. what are the options available when right-clicking an IP address of an event to access more event filter information?
The magnitude rating of an offense in QRadar is calculated based on which values?
An analyst wishes to review an event which has a rules test against both event and flow data.
What kind of rule is this?
After how much time will QRadar mark an Event offense dormant if no new events or flows occur?
How long will an AQL statement remain in execution if a time criteria is not specified, such as start, end, or last?
An analyst must create a reference set collection containing the IPv6 addresses of command-and-control servers in an IBM X-Force Exchange collection in order to write a rule to detect any enterprise traffic with those malicious IP addresses.
What value type should the analyst select for the reference set?
A Security Analyst has noticed that an offense has been marked inactive.
How long had the offense been open since it had last been updated with new events or flows?
A QRadar analyst wants to limit the time period for which an AOL query is evaluated. Which functions and clauses could be used for this?
What two (2) guidelines should you follow when you define your network hierarchy?
Which parameter should be used if a security analyst needs to filter events based on the time when they occurred on the endpoints?
Select all that apply
What is the sequence to create and save a new search called "Offense Data" that shows all the CRE events that are associated with offenses?
The Use Case Manager app has an option to see MITRE heat map.
Which two (2) factors are responsible for the different colors in MITRE heat map?
For a rule containing the test "and when the source is located in this geographic location" to work properly, what must a QRadar analyst configure?