Exam Code: C2150-612 (Practice Exam Latest Test Questions VCE PDF)
Exam Name: IBM Security QRadar SIEM V7.2.6 Associate Analyst
Certification Provider: IBM
Free Today! Guaranteed Training- Pass C2150-612 Exam.
♥♥ 2021 NEW RECOMMEND ♥♥
Free VCE & PDF File for IBM C2150-612 Real Exam (Full Version!)
★ Pass on Your First TRY ★ 100% Money Back Guarantee ★ Realistic Practice Exam Questions
Free Instant Download NEW C2150-612 Exam Dumps (PDF & VCE):
Available on:
http://www.surepassexam.com/C2150-612-exam-dumps.html
Q1. How does flow data contribute to the Asset Database?
A. Correlated Flows are used to populate the Asset Database.
B. It provides administrators visibility on how systems are communicating on the network.
C. Flows are used to enrich the Asset Database except for the assets that were discovered by scanners.
D. It delivers vulnerability and ports information collected from scanners responsible for evaluating network assets.
Answer: C
Q2. What is a main function of a Cisco Adaptive Security Appliance (ASA)?
A. A Proxy
B. A Switch
C. A Firewall
D. An Authentication device
Answer: C
Q3. Which information can be found under the Network Activity tab?
A. Flows
B. Events
C. Reports
D. Offenses
Answer: A
Q4. What is the difference between TCP and UDP?
B. UDP is connectionless, whereas TCP is connection based
C. TCP is connectionless, whereas UDP is connection based
D. TCP runs on the application layer and UDP uses the Transport layer
Answer: B
Q5. A mapping of a username to a user’s manager can be stored in a Reference Table and output in a search or a report.
Which mechanism could be used to do this?
A. Quick Search filters can select users based on their manager’s name.
B. Reference Table lookup values can be accessed in an advanced search.
C. Reference Table lookup values can be accessed as custom event properties.
D. Reference Table lookup values are automatically used whenever a saved search is run.
Answer: B
Q6. Which QRadar add-on component can generate a list of the unencrypted protocols that can
communicate from a DMZ to an internal network?
A. QRadar Risk Manager
B. QRadar Flow Collector
C. QRadar Incident Forensics
D. QRadar Vulnerability Manager
Answer: A
Q7. What is the largest differentiator between a flow and event?
A. Events occur at a moment in time while flows have a duration.
B. Events can be forwarded to another destination, but flows cannot.
C. Events allow for the creation of custom properties, but flows cannot.
D. Flows only contribute to local correlated rules, while events are global.
Answer: A
Q8. Which log source and protocol combination delivers events to QRadar in real time?
A. Sophos Enterprise console via JDBC
B. McAfee ePolicy Orchestrator via JDBC
C. McAfee ePolicy Orchestrator via SNMP
D. Solaris Basic Security Mode (BSM) via Log File Protocol
Answer: C
Q9. Which QRadar rule could detect a possible potential data loss?
A. Apply “Potential data loss” on event of flows which are detected by the local system and when any IP is part of any of the following XForce premium Premium_Malware
B. Apply “Potential data loss” on flows which are detected by the local system and when at least 1000 flows are seen with the same Destination IP and different source in 2 minutes
C. Apply “Potential data loss” on events which are detected by the local system and when the event category for the event is one of the following Authentication and when any of Username are contained in any of Terminated_User
D. Apply “Potential data loss” on flows which are detected by the local system and when the source bytes is greater than 200000 and when at least 5 flows are seen with the same Source IP, Destination Port Destination IP in 12 minutes
Answer: D
Q10. Which kind of information do log sources provide?
A. User login actions
B. Operating system updates
C. Flows generated by users
D. Router configuration exports.
Answer: A