Download IBM Security QRadar SIEM V7-2-7 Deployment.PracticeTest.C2150-614.1e.35q.vcex

Download Exam

File Info

Exam IBM Security QRadar SIEM V7.2.7 Deployment
Number C2150-614
File Name IBM Security QRadar SIEM V7-2-7 Deployment.PracticeTest.C2150-614.1e.35q.vcex
Size 540 Kb
Posted August 01, 2018
Downloads 51

How to open VCEX & EXAM Files?

Files with VCEX & EXAM extensions can be opened by ProfExam Simulator.

Purchase
Coupon: EXAM_HUB

Discount: 20%

 
 



Demo Questions

Question 1
A custom with IBM Security QRadar SIEM V7.2.7 is using Active Directory to authenticate users. After a crash, the authentication servers are down and some users tried to log in before the authentication servers came back up. 
What will happen to these users?

  • A: Local users are able to log in with their local password.
  • B: Active Directory users are able to log in with their password.
  • C: Administrative and non-administrative users are unable to log in with their password until authentication servers come back online.
  • D: Logging on is restricted to administrative users and non-administrative will needed to wait until the authentication server comes back online.



Question 2
Which CLI command should be used to change the default password from PASSWORD to S3cure for the username USERID?

  • A: /opt/ibm/toolscenter/asu/asu set IMM. Password S3cure --ksu
  • B: /opt/ibm/toolscenter/asu/asu set IMM. Password.1 S3cure --ksu
  • C: /opt/ibm/toolscenter/asu/asu64 set IMM. Password S3cure -- ksu
  • D: /opt/ibm/toolscenter/asu/asu64 set IMM.Password.1 S3cure -- ksu



Question 3
A Deployment Professional is performing a new deployment, and the customer wants to monitor network traffic by sending raw data packets from a network device to IBM Security QRadar SEAM V7.2.7. 
Which method should be used?

  • A: AGP card
  • B: Napatech card
  • C: SFlow protocol
  • D: NetFlow protocol



Question 4
A Deployment Professional was asked to investigate the following error:
Custom Rule Engine has detected a total of 20487 dropped event(s). 20487 event(s) were dropped in the last 62 seconds. Queue is at 99 percent capacity 
The Deployment Professional needs to run the command 
“/opt/qradar/bin/findExpensiveCustomRules.sh” to gather the necessary troubleshooting logs. 
When should this command be run?

  • A: Right after a reboot
  • B: Run “service hostcontext restart” first
  • C: While the system is dropping events
  • D: Restart ECS, then run command



Question 5
A current banking customer has just expanded by purchasing a small rural bank with a low bandwidth WAN connection. 
The customer wants to expand its current QRadar SIEM 3105 all-in-one deployment to capture log events from the newly acquired branch and to forward them on a schedule, after hours during the trough of activity to the main branch. There is plenty of room for this additional EPS growth. 
Which device will meet the requirements?

  • A: 1202 QFlow Collector
  • B: 1400 Data Node
  • C: 1501 Event Collector
  • D: 1605 Event Processor



Question 6
What is the impact on network bandwidth when selecting 'Global' on a rule instead of 'Local' in a distributed environment?

  • A: All events are sent to the QRadar Console for processing and therefore, the QRadar Console uses more bandwidth.
  • B: All matching events are sent to the QRadar Console for processing and therefore, the QRadar Console uses more bandwidth.
  • C: All events are sent to each QRadar Event Processor for processing and therefore, all Events Processors use more bandwidth.
  • D: All matching events are sent to each QRadar Event Processor for processing and therefore, all Event Processor use more bandwidth.



Question 7
A Deployment Professional using IBM Security QRadar SIEM V7.2.7 needs to discover all mail servers, but some of the mail servers are listening on TCP port 10025. 
Which server type and port could be configured in server discovery to accomplish this goal?

  • A: Mail Servers predefined server type should be used.
  • B: Application predefined server type with destination port 10025 only should be used.
  • C: Mail Servers predefined server type with destination port 10025 added to BB:PortDefinition: Mail Ports should be used.
  • D: Application Servers predefined server type with destination port 10025 added to BB:PortDefinition: Mail Ports should be used.



Question 8
A Deployment Professional is looking over event and flow data for a new customer and sees that the customer is hitting 4,000 EPS/300,000 FPM, with bursts of up to 5,000 EPS/400,000 FPM. The customer is asking for the least amount of appliances to be installed to handle this traffic without any throttling. 
Which combination should be installed?

  • A: Install the IBM Security QRadar 3105 (Console) and add a QRadar 1805
  • B: Install the IBM Security QRadar 3105 (Console) and add a QRadar Flow Processor 1705
  • C: Install the IBM Security QRadar 3105 (Console) and add a QRadar Flow Processor 1828
  • D: Install the IBM Security QRadar 3105 (Console) and add a QRadar Event Processor 1605



Question 9
A Deployment Professional has received complaints from a customer stating that events from a satellite Location in Hong Kong are being delayed, which is affecting records processing. The Deployment Professional wants to improve event transfer from that location to the IBM Security QRadar SIEM V7.2.7 Console in Mexico. 
Which appliance could be installed in the satellite location to accomplish this goal?

  • A: Data Node
  • B: Flow Collector
  • C: Event Collector
  • D: Event Processor



Question 10
A Deployment Professional needs to create and share a saved search with other users. 
What are the requirements for this action?

  • A: The user must be in the Admin role, and the saved search must have at least one “Grouped By” field.
  • B: Any user can share a saved search that must have exactly one “Grouped by” field.
  • C: The user must be in the Admin role, and the saved search must have at least one “[indexed]” field.
  • D: Any user can share a saved search that must contain at least one “Grouped By” + and one “[indexed] fields.






CONNECT US


ProfExam
PROFEXAM WITH A 20% DISCOUNT

You can buy ProfExam with a 20% discount..

Get Now!


HOW TO OPEN VCEX AND EXAM FILES

Use ProfExam Simulator to open VCEX and EXAM files
ProfExam Screen



HOW TO OPEN VCE FILES

Use VCE Exam Simulator to open VCE files
Avanaset