[Apr-2022] C1000-055 Exam Dumps, C1000-055 Practice Test Questions [Q33-Q55]

Share

[Apr-2022] C1000-055 Exam Dumps, C1000-055 Practice Test Questions

Attested C1000-055 Dumps PDF Resource [2022]

NEW QUESTION 33
A deployment professional has been asked to create some Reference Data to be used to provide additional information in the results of Ariel Query Language (AQL) queries. The data will enable a lookup that finds the users's Department based on the username which will be returned by the required AQL function when looked up in the reference data.
Which Reference Data should the deployment professional create for this purpose?

  • A. Reference Map of Tables
  • B. Reference Map
  • C. Reference Set
  • D. Reference Map of Sets

Answer: D

 

NEW QUESTION 34
A deployment professional just installed new QRadar deployment which comes with a temporary license key.
How many days does a deployment professional have before the temporarylicensekey expires?

  • A. 30 days from the installation date.
  • B. 45 days from the installation date.
  • C. 35 days from the installation date.
  • D. 15 days from the installation date.

Answer: A

 

NEW QUESTION 35
A customer has a Network Vulnerability Scanner which is not supported by IBM QRadar.
How can a deployment professional integrate such a scanner with IBM QRadar?

  • A. Using the AXIS Scanner option of IBM QRadar
  • B. Using a Custom Flow Source
  • C. By creating a Log Source Extension (LSX)
  • D. Creating a uDSM using the DSM Editor

Answer: A

 

NEW QUESTION 36
A deployment professional sees that there are occasional spikes in the EPS (Events per second). The host has
1000 EPS allocated but the occasional spikes go up to 1185 EPS.
What happens with the events when they go over the allocated amount?

  • A. Events are dropped.
  • B. Events are shown normally, but no offenses are generated.
  • C. Events are shown normally, QRadar has 20% buffer.
  • D. Events are moved to a temporary queue.

Answer: D

 

NEW QUESTION 37
A deployment professional is asked to create QRadar deployment architecture for a company.
The company has three branch offices with WAN connection between them. The head office data center requires 14000 EPS and 200000 FPM. Each branch requires 4000 EPS and 200000 FPM.
Which deployment solution will meet the minimum requirements?

  • A. QRadar 3105 (Console) and QRadar Event and Flow Processor 1829 in head office + QRadar 1805 Event and Flow Processor in each branch office
  • B. QRadar 3129 (All-in-One) in head office
  • C. QRadar 3129 (Console) in head office + QRadar 1805 Event and Flow Processor in each branch office
  • D. QRadar 3105 (Console) in head office + QRadar 1805 Event and Flow Processor in each branch office

Answer: D

 

NEW QUESTION 38
A deployment professional needs to configure network devices to send IPFIX to a QRadar deployment consisting of 1 QRadar Console 3129 and 2 QRadar Event Processors 1629. The routers will send more than 1
000 000 FPM.
Which component should be added to the existing deployment?

  • A. Flow Processor
  • B. AppHost
  • C. Event Collector
  • D. DataNode

Answer: C

 

NEW QUESTION 39
A systems team has configured their application to send syslog via tcp to a QRadar event collector. The deployment professional has noted that no such logs have arrived for the pre-defined log source.
To troubleshoot this and to prove this traffic has/has not arrived at the event collector, what command can be used from the event collector CLI?
(The Device_Address is an IPv4 address or a host name)

  • A. pcap -s 0 -A host Device_Address and udp port 514
  • B. tcpdump -s 0 -A host DeviceAddress and port 514
  • C. tcpdump -s 0 -A host Device Address and udp port 514
  • D. pcap -s 0 -A host Device Address and port 514

Answer: D

 

NEW QUESTION 40
A deployment professional is creating an architecture for a customer who has locations which regularly go out of contact with the rest of the network. The requirement is to receive logs locally and then have a scheduled connection to QRadar to upload the events.
Which QRadar appliances should be deployed in these locations?

  • A. 31 xx All-in-One with Online Forwarding configured
  • B. Disconnected Log Collector with UDP configured
  • C. 16xx Event Processor with a Store and Forward schedule
  • D. 15xx Event Collector with a Store and Forward schedule

Answer: C

 

NEW QUESTION 41
A client uses the IBM Security QRadar Vulnerability Manager to discover vulnerabilities on the network devices, applications, and software. They run the QRadar Vulnerability Manager from an All-in-one system, where the scanning and processing functions are on the Console. As the client's QRadar deployment is growing, they are also considering deploying scanners.
What is a valid client motivation for deploying additional scanners?

  • A. To find more vulnerabilities on a given system.
  • B. To patch assets for their vulnerabilities.
  • C. To scan an asset in the same geographic region as the QRadar Vulnerability Manager processor.
  • D. To avoid scanning through a firewall that is a log source.

Answer: A

 

NEW QUESTION 42
A deployment professional is about to execute Server Discovery to populate the Host Definition Building Blocks. The deployment professional is working in a monitored environment and does not wish to set off any network scanner alarms.
What step should the deployment professional take to ensure that good results are returned and that no alarms are raised?

  • A. Warn the network monitoring team that QRadar is about to run a network port scan
  • B. Ensure that events from the relevant servers are being collected successfully
  • C. Set the 'Passive discovery' flag in Advanced System Settings in the Admin tab
  • D. Ensure that the flow sources are configured correctly and collecting data

Answer: C

 

NEW QUESTION 43
As a small company has grown, no standard was defined. Each time the network was expanded, the bid with the lowest cost was accepted. As a result, the infrastructure is a mix of equipment from different manufactures.
A deployment professional is planning on standardizing flow collection. Which flow source data format should the deployment professional use?

  • A. sFlow
  • B. NetFlow
  • C. A-Flow
  • D. J-Flow

Answer: A

 

NEW QUESTION 44
The iSCSI offboard storage is being configured. Which sequence should be used?

  • A. Stop services on QRadar > Mount iSCSI file system > Migrate the data to iSCSI > Configure iSCSI
  • B. Stop services on QRadar > Configure iSCSI > Mount iSCSI file system /store > Migrate the data to iSCSI
  • C. Configure iSCSI > Stop services on QRadar > Migrate the data to iSCSI > Mount iSCSI file system
  • D. Stop services on QRadar > Migrate the data to iSCSI > Configure iSCSI > Mount iSCSI file system

Answer: C

 

NEW QUESTION 45
A deployment professional is challenged with incomplete report results. The report is being created but it not displaying all data.
What would be the first thing the deployment professional would do to determine whether or not the report is incomplete?

  • A. Review notification messages for incomplete report data.
  • B. Run a search again from the log activity tab.
  • C. Run a search again from the network activity tab.
  • D. Run the report manually.

Answer: B

 

NEW QUESTION 46
A deployment professional is faced with the following system notification.
38750107 - The last attempt to read in rules (usually due to a rule change) has failed. Please see the message details and error log for information on how to resolve this.
What should the deployment professional do after trying to disable and enabling the rule?

  • A. Delete and recreate the rule.
  • B. Modify the rule.
  • C. Create a new rule without deleting the old rule.
  • D. Before doing anything else, call customer support.

Answer: D

 

NEW QUESTION 47
Some customers do not fully understand the benefits of using dedicated appliances to collect events and flows, complaining about the complexity of the deployments.
How should the deployment professional clarify any doubts that may arise?

  • A. Using All-in-One appliances are a good choice for environments greater than 100.000 EPS.
  • B. Dedicated event collectors when deployed in VMs include an on-board event processor that can be directly attached to an All-in-One Virtual console type 3199.
  • C. The operation of the QRadar security intelligence platform consists of three layers, and applies to any QRadar deployment structure, regardless of its size and complexity.
  • D. Event Processor collect events from various log sources and continuously forwards these events to an Event Collector.

Answer: A

 

NEW QUESTION 48
A deployment professional sees the following notification in the IBM QRadar Notification Section. "The Accumulator has fallen behind." To which performance issues does the notice refer to?

  • A. External Storage
  • B. Event Pipeline
  • C. Flow Pipeline
  • D. Global Views

Answer: A

 

NEW QUESTION 49
A deployment professional is working on integrating an unsupported log source. The log source is able to send events in multiple formats. The administrators of the log source ask which event format should be configured.
Which event format should the deployment professional choose to be able to use direct parsing support in QRadar's DSM editor?

  • A. Regex
  • B. LEEF
  • C. SAML
  • D. BLOB

Answer: D

 

NEW QUESTION 50
A deployment professional has to decide where data will be stored in a newly configured environment to submit a plan for storage and network connectivity bandwidth.
Which QRadar components within a deployment can store raw or normalized events locally? (Choose two)

  • A. Event Collector
  • B. Event Processor
  • C. Data Diode
  • D. Data Node
  • E. Flow Collector

Answer: B,D

Explanation:
Explanation
https://www.ibm.com/docs/en/SS42VS_7.3.3/com.ibm.qradar.doc/b_siem_deployment.pdf

 

NEW QUESTION 51
A deployment professional decides to improve visibility in the network and successfully installs the Flow Collector.
What should the deployment professional connect the Flow Collector to?

  • A. LAN port
  • B. SPAN port
  • C. WAN port
  • D. SAN port

Answer: B

 

NEW QUESTION 52
A deployment professional is working with a client that develops their own in house applications. The customer would like to log events from these applications. Because these applications are hosted on Windows servers inside of the clients DMZ, the client wants to limit the ports on which they will allow access. All logs are written to a flat file named debugJog in the c:\app\logs folder of the host.
Which option is a developed strategy for integrating these logs with QRadar SIEM?

  • A. Install managed Wincollect instances, create a custom DSM and use the Microsoft Security Event Log DSM to create a xpath query to ingest the data.
  • B. Create a custom DSM and use the MSRPC protocol communicate with the servers and ingest the log file.
  • C. Install managed Wincollect instances on the servers, create a custom DSM and use the Wincollect Log Forwarder protocol to ingest events from the log file.
  • D. Install unmanaged Wincollect instances on the servers, create a custom DSM and use the Wincollect File Forwarder protocol to ingest events from the log file.

Answer: D

 

NEW QUESTION 53
A deployment professional receives instructions to virtualize the currently installed QRadar SIEM All-in-One appliance and to provide requirements. VM specifications must suffice for 4000 EPS.
What are the minimum processor and memory requirements that the deployment professional must use?

  • A. 32 GB Memory, 16 CPU Cores
  • B. 8 GB Memory, 4 CPU Cores
  • C. 128 GB Memory, 16 CPU Cores
  • D. 256 GB Memory, 32 CPU Cores

Answer: B

 

NEW QUESTION 54
A deployment professional needs to find out which rules are generating most of the offenses. What should the deployment professional do? (Choose two)

  • A. Generate Report "System Summary"
  • B. Use search where Log source is Custom Rule Engine-8 :: <qradar hostname> and choose Grouping by Event Name
  • C. Offenses -> By Category
  • D. Offenses -> Rules -> Sort by Offense Count
  • E. Use search where Log source is Health Metrics-2 :: <qradar hostname> and choose Grouping by Event Name

Answer: A,D

 

NEW QUESTION 55
......


IBM C1000-055 Exam Syllabus Topics:

TopicDetails
Topic 1
  • Design a deployment to meet a set of security business objectives
  • Generate an architecture based on design objectives (i.e., events per second (EPS), flows per minute (FPM), data retention)
Topic 2
  • Implement authentication and authorization methods (i.e., LDAP, SSO)
  • Install and configure various QRadar appliances according to architecture
Topic 3
  • Integrate unsupported log sources and show how to use the DSM Editor to create custom log sources
  • Execute Server Discovery to populate host definitions building blocks
Topic 4
  • Detect tuning opportunities for common information (e.g. network hierarchy, reference data, and expensive rule.)
  • Analyze Windows Event Collection options (e.g., WinCollect, Snare, MSRPC, SMBTail, Windows Event Forwarding)
Topic 5
  • Determine performance issues based on QRadar warnings, logs and notifications
  • Create expansion plans for growth (e.g., All-in-One (AIO) to Distributed, EP to EP and EC, EP to EP and DN)
Topic 6
  • Illustrate the equivalent VM specifications for appliances
  • Choose appliance models that fit the sizing requirements
Topic 7
  • Determine types of log and flow data and suitability for security monitoring, data storage
  • Determine how log source locations and information gathering mechanisms can affect QRadar component
Topic 8
  • Demonstrate how to monitor and investigate network and log activity search issues
  • Explain how an integration of a threat feed is done using an app
Topic 9
  • Determine the suitablility of high availability (HA) for a given set of requirements
  • Model and design the information required by Rules and Building Blocks

 

Latest C1000-055 Actual Free Exam Questions Updated 62 Questions: https://www.itcertmagic.com/IBM/real-C1000-055-exam-prep-dumps.html