An Administrator working with IBM Security QRadar SIEM V7.2.8 needs to assign a report to a group
named Network Management.
What is the process for this task to be completed?
A. Reports Tab -> Select report -> Actions -> Assign Groups -> Item Groups -> select Network Management -> Assign Groups
B. Admin Tab -> Report Permissions -> select report -> Actions -> Assign Groups -> select Network Management -> Assign
C. Reports Tab -> Select report -> Actions -> Assign Users -> User Groups -> select Network Management -> Assign Users
D. Admin Tab -> Report Permissions -> select report -> Actions -> Assign Users -> select Network Management -> Assign
An IBM Security QRadar SIEM V7.2.8 Administrator will install a High Availability (HA) pair of appliances.
The primary and secondary hosts are formatted with the same file system.
To ensure compatibility between hosts, which statement is considered a prerequisite?
A. The size of the /home partition on the secondary must be larger than the /home partition of the primary.
B. The size of the /var/opt/ha on the secondary must be larger than the /var/opt/ha partition of the primary.
C. The size of the /store partition on the secondary must be lesser than the /store partition of the primary.
D. The size of the /store partition on the secondary must be equal to or larger than the /store partition of the primary.
An Administrator is tasked with installing additional log sources into an IBM Security QRadar SIEM V7.2.8
deployment, bringing the total number of log source to 900. The deployment is using the default license
and the Administrator is getting an error attempting to add these additional log sources.
Why is this error happening?
A. The default license only allows 250 log sources.
B. The default license only allows 500 log sources.
C. The default license only allows 750 log sources.
D. The default license only allows 800 log sources.
Where are system notifications located in IBM Security QRadar SIEM V7.2.8?
A. Only in the Admin Tab -> System Messages.
B. Only on the banner above the QRadar navigation tabs.
C. On the banner above the QRadar navigation tabs or on the System Monitoring dashboard.
D. On the banner above the QRadar navigation tabs or in the Admin Tab -> System Messages.
What are the four categories of notifications found in IBM Security QRadar SIEM V7.2.8 system notifications?
A. Errors, Critical, Minor and Information
B. Errors, Warning, Information, and Health
C. Warning, Information, System and Critical
D. Errors, Warning, Information, and Performance
An Administrator working with an IBM Security QRadar SIEM V7.2.8 deployment needs to build an Ariel
Query to find all flow data send in the last 24 hours where the amount of bytes being sent and received are
larger than 64 bytes.
What Query needs to be used?
A. SELECT * FROM flows WHERE sourceBytes> 64 anddestinationBytes> 64 LAST 1 DAY
B. SELECT * FROM flows WHERE sourceBytes> 64 AND destinationBytes> 64 LAST 1 DAYS
C. SELECT * FROM flowsdata WHERE sourceBytes> 64 AND destinationBytes> 64 LAST 1 DAY
D. SELECT * FROM flowsdata WHERE sourceBytes> 64 AND destinationBytes> 64 LAST 1 DAYS
An IBM Security QRadar SIEM V7.2.8 Administrator needs to restore a backup archive after a hardware
failure.
The Administrator has navigated to the System Configuration tab with the Navigation menu, what are the
next steps to restore?
A. System Settings -> upload the backup file that you want to restore -> Configure the parameters >Restore -> OK
B. Backup and Recovery -> select the archive that you want to restore -> Configure -> configure the parameters -> Restore -> OK
C. System Settings -> select the archive that you want to restore -> On Demand Restoration ->Configure > Configure the parameters -> Restore -> OK -> OK
D. Backup and Recovery -> select the archive that you want to restore -> Restore, on the Restore a Backup window -> Configure the parameters -> Restore -> OK -> OK
When upgrading IBM Security QRadar SIEM V7.2.8, the upgrade file needs to be made accessible to the
operating system.
Which command will accomplish this task?
A. mount -o loop -t iso9660
B. mount -o loop -t squashfs
C. umount -o loop -t iso9660
D. umount -o loop -t squashfs
How would an Administrator working with IBM Security QRadar SIEM V7.2.8 review all logs?
A. Admin Tab -> System Configuration -> Actions -> Collect Log Files
B. Admin Tab -> System Configuration -> Actions -> Collect All Log Files
C. Admin Tab -> System and License Management -> Actions -> Collect Log Files
D. Admin Tab -> System and License Management -> Actions -> Collect All Log Files
An Administrator is creating custom rules and configuring log sources on an IBM Security QRadar SIEM
V7.2.8 console. This data needs to be retained so that it can be recovered in case of any system failure
with minimal effort.
Which option can the Administrator utilize from the Backup and Recovery Wizard to accomplish this task?
A. Data backups
B. Ariel database
C. Configuration and Data backups
D. Configuration and DB2 database