Exam Code: C2150-195 (Practice Exam Latest Test Questions VCE PDF)
Exam Name: IBM Security QRadar V7.0 MR4
Certification Provider: IBM
Free Today! Guaranteed Training- Pass C2150-195 Exam.
2021 Apr C2150-195 Study Guide Questions:
Q61. What are two ways that asset profiles can be populated? (Choose two.)
A. Flow data
B. Heartbeat traffic
C. Router configuration
D. Windows application logs
E. Vulnerability assessment scans
Answer: A,E
Explanation:
Q62. How does a user access the Extract a Custom Property section from a paused event screen in the Log Activity tab?
A. Actions menu > Extract Property
B. Double-click the event > Extract Property
C. Actions menu > Show All > Extract Custom Property
D. Right-click on the event > Properties > Extract Property
Answer: B
Explanation:
Q63. What is the main difference between a QFlow record versus a netflow capable router or switch?
A. QFlow can be used to trigger an alert.
B. QFlow cannot capture the communication payload.
C. QFlow can also be viewed in the Event Viewer window.
D. QFlow and vFlow can capture the communication payload.
Answer: D
Explanation:

Replace C2150-195 book:
Q64. Which two fields are common in the Network Activity and Log Activities tabs? (Choose two.)
A. Source IP
B. Username
C. Application
D. Source Bytes
E. Destination Port
Answer: A,E
Explanation:
Q65. What action must be taken to view reports related to PCI specifically?
A. Right-click on Compliance and select PCI group.
B. There are no filtering or grouping capabilities for reports.
C. Click on the Group drop-down menu and select the category.
D. SSH to the Console and execute a GREP command to find PCI report options.
Answer: C
Explanation:
Q66. Everyone involved in a forensic analysis is now convinced that account management events involving promotion of accounts to AD administrator groups must be reported on daily. What is the most efficient method to accomplish this in IBM Security QRadar V7.0 MR4 (QRadar)?
A. Such a report requires additional parsing of events using extra custom properties and then including these properties in a manual report.
B. A new rule must be created which triggers an offense every time an account is assigned to an AD administrator group. By examining the event in detail it can be determined if this was really an offense or not.
C. The detailed search that the user has used to identify the relevant events must be saved first. Once it is saved, then it can be reused on demand, and it can also be used to build a custom report which can then be scheduled.
D. Automation or scripting is out of the question. The user has to repeat the analysis manually every time a similar incident occurs. The best the user can do is document the steps so that it is repeatable by anyone with access to the QRadar interface.
Answer: C
Explanation:

Precise C2150-195 practice exam:
Q67. On the Offenses tab, which option displays offenses by access, exploit, or malware?
A. By Rules
B. By Category
C. By Definition
D. By Source IP
Answer: B
Explanation:
Q68. If an IBM Security QRadar V7.0 MR4 operator wants to detect a specific data string in the flow content, which search parameter should be used as a filter?
A. Source IP
B. Event Name
C. Remote Network
D. Source Payload Contains
Answer: D
Explanation:
Q69. Which regex should be used to capture only the domain name blackbox.computerfor all future machine names based on this example?
‘Computer=3 8 9.blackbox.computer’
A. Computer= (. *?) s
B. Computer=389. (.*?)s
C. Computer=(389..*?)s
D. Computer=. *?. (.*?)s
Answer: D
Explanation:
Q70. How can a user quickly add a filter?
A. Actions > Add Filter
B. Click the Add Filter menu icon
C. Search > Edit Search, and add the filter
D. Right-click the column header > Add Filter
Answer: B
Explanation: