C1000-162 IBM Security QRadar SIEM V7.5 Administration Practice Questions
Prepare for C1000-162 with more than an answer.
- Exam fee
- $200 USD
- Level
- Intermediate
- Valid for
- Not specified - certification does not expire
Domains covered on the exam 5
- Offense Analysis23%
- Rules and Building Block Design18%
- Threat Hunting24%
- Dashboard Management14%
- Searching and Reporting21%
- 1
The command
SELECT QIDNAME(qid) as 'Event Name', COUNT(*) as 'Count' FROM events GROUP BY qid LAST 24 HOURSis used for what purpose in QRadar?Show answer details
Correct answer: B
This AQL query counts the occurrences of each unique QRadar Identifier (qid) in the last 24 hours. The
QIDNAME(qid)function translates the numeric qid into its human-readable event name. By grouping by qid and counting, the query effectively generates a summary of the most frequently occurring event types, which is crucial for baselining and identifying anomalies. - 2
A SOC Manager wants to create a dashboard in the default QRadar UI (not Pulse) that shows a pie chart of offenses by category and a list of the top 10 most recent offenses. How can an analyst accomplish this?
Show answer details
Correct answer: C
The default QRadar UI provides a library of pre-built dashboard items (widgets). To fulfill the request, an analyst would create a new dashboard, then drag and drop the 'Offenses by Category' item (which displays as a pie chart) and the 'Top 10 Offenses' item (which displays a list) onto the canvas. These widgets are specifically designed for this type of summary view.
- 3
When triaging a new offense, an analyst wants to understand its potential business impact and priority. Which component of the offense is specifically designed to provide a calculated score representing the overall threat level, combining factors like relevance, credibility, and severity?
Show answer details
Correct answer: C
Magnitude is a calculated value from 1 to 10 that represents the overall importance of an offense. It is a weighted calculation that takes into account three key factors: Severity (how critical the underlying event/rule is), Relevance (how important the affected assets are), and Credibility (the integrity of the source device and the likelihood that the event is legitimate). This score is the primary indicator used to prioritize offense investigations.
- 4
A new content pack for detecting cloud-based threats has been installed from the IBM Security App Exchange. After installation, what is the most important reason for an analyst to review the new rules and building blocks included in the pack?
Show answer details
Correct answer: B
Content packs provide generic, best-practice rules that are not tailored to any specific environment. It is crucial for an analyst or administrator to review the installed components to tune them. This includes updating building blocks to reference the correct local network hierarchy, adjusting thresholds to match internal baselines, and ensuring the rules align with the organization's security policies to maximize accuracy and minimize false positives.
- 5
An analyst is investigating an offense involving an internal host communicating with a known command-and-control server. The analyst needs to understand the full sequence of events that led to the offense. The following diagram shows the typical flow of investigation. At which stage should the analyst examine the specific rule tests that were met?
flowchart TD A[Triage Offense] --> B{Initial Assessment}; B --> C[Analyze Source/Destination IPs]; C --> D[Break Down Triggered Rules]; D --> E[Investigate Payload]; E --> F[Contain & Remediate];Show answer details
Correct answer: B
After identifying the key players (source/destination), the next logical step is to understand why QRadar flagged this activity as malicious. Stage D, 'Break Down Triggered Rules', involves looking at the offense summary to see which rules fired, and then drilling down into those rules to see the specific tests (e.g., 'and when the destination IP is in reference set Malicious_C2_Servers') that were met. This explains the reason for the offense.
- 6
A Tier 2 SOC analyst at a financial services firm is investigating a high-magnitude offense related to 'Anomalous Database Activity'. The offense is triggered by a rule that correlates login events from a privileged user account with subsequent large data extractions from a production database. To distinguish between a legitimate administrative task and a potential insider threat, which investigative step should the analyst prioritize?
Show answer details
Correct answer: B
The most effective next step is to analyze the payload of the associated events. This will reveal the specific SQL queries run, which provides crucial context to differentiate between a routine backup/maintenance script (e.g., SELECT * FROM table_backup) and a malicious data exfiltration attempt (e.g., SELECT ssn, credit_card FROM customers). Escalating without this context is premature, reviewing past offenses is less direct, and checking asset profiles does not explain the specific action taken.
- 7
A threat hunter is using an AQL query to find evidence of a slow data exfiltration attempt where small amounts of data were sent to multiple external IP addresses over a long period. The current query is returning too many results and timing out. Which TWO of the following AQL query modifications would most effectively optimize the search and narrow the results to the most relevant indicators? (Select TWO)
Show answer details
Correct answer: B, C
Grouping by the destination IP and then counting unique source IPs can quickly highlight a single external IP being contacted by many internal systems, a potential C2 server. This aggregation is computationally efficient.
The
HAVINGclause is used afterGROUP BYto filter aggregated results. By summing the bytes sent to each destination and filtering for a total that is suspiciously large but spread out, the analyst can pinpoint slow exfiltration targets. - 8
While analyzing an offense, a security analyst needs to quickly determine if an IP address flagged as a source of malicious activity is part of a known botnet. Which QRadar feature provides the most direct and context-rich method for this investigation?
Show answer details
Correct answer: B
The right-click investigation feature is designed for this exact purpose. It provides context-sensitive actions, including querying integrated threat intelligence feeds (like X-Force Exchange) for data on IPs, hashes, or URLs. This is the most direct and efficient method to check if an IP is associated with known malicious infrastructure like a botnet.
- 9
A new log source for a custom in-house application is sending events to QRadar, but they are all appearing as 'Unknown'. The application logs contain a unique 'transactionID' field that is critical for correlating user activity. The security team has recommended creating a custom event property to extract this ID. After the custom property is created and deployed, what is the immediate next step an analyst should take to make this field usable in searches and rules?
Show answer details
Correct answer: A
While creating the custom property is the first step, it is not searchable in quick filters or performant in AQL queries until it is enabled for indexing. Enabling indexing tells QRadar to specifically parse and store this property in the Ariel database for fast retrieval, which is essential for its effective use in rules, searches, and analysis.
- 10
True or False: The primary purpose of a Building Block in QRadar is to trigger an offense and generate a notification when its conditions are met.
Show answer details
Correct answer: B
This statement is false. Building Blocks are collections of reusable test conditions that, by themselves, do not create offenses or trigger responses. They are designed to be used as components within other rules to simplify complex logic and avoid redundancy. Only a Rule can trigger an offense or response.
