Skip to content

C1000-156 Qradar Siem V7.5 Administration Practice Questions

Prepare for C1000-156 with more than an answer.

202 questions in the full set20 sample questionsUpdated Aug 11, 2025
Exam fee
$200 USD
Level
Administrator
Valid for
3 years
Domains covered on the exam 8
  1. System Configuration20%
  2. Performance Optimization13%
  3. Data Source Configuration14%
  4. Accuracy Tuning10%
  5. User Management6%
  6. Reporting, Searching, and Offense Management13%
  7. Tenants and Domains8%
  8. Troubleshooting16%
  1. 1

    A QRadar deployment is consistently showing 'License throttled' system notifications, and new events are being dropped. The administrator needs to identify which log sources are contributing the most to the Events Per Second (EPS) rate to investigate the issue. Which of the following methods is the most direct way to get this information?

    Show answer details

    Correct answer: C

    The Log Source Management app contains a 'Log Source Statistics' view which provides a real-time and historical breakdown of EPS rates on a per-log-source basis. This is the most direct and intended method for identifying the 'noisiest' or 'top talker' log sources that are consuming the license.

  2. 2

    Which of the following are valid reasons to use a Building Block in QRadar? (Select THREE)

    Show answer details

    Correct answer: A, B, D

  3. 3

    True or False: After creating a new custom event property, you must perform a full 'Deploy Changes' before the property will be extracted from new, incoming events.

    Show answer details

    Correct answer: A

    Changes to the event pipeline, including the creation of new custom event properties, modifications to parsing, or updates to rules, require a 'Deploy Changes' operation. This pushes the new configuration to the relevant components (like the Event Processor) so they can begin applying the new logic to the live event stream.

  4. 4

    A QRadar administrator is configuring a backup schedule. The company's policy requires a daily configuration backup and a weekly data backup. The data backup must be moved to an off-board NFS mount for disaster recovery purposes. Which of the following statements accurately describes how to configure this?

    Show answer details

    Correct answer: B

    The QRadar Backup and Recovery feature schedules and creates backup archives on the local disk of the QRadar host (typically in /store/backup/). To move these archives to an external location like an NFS mount, the administrator must configure a separate process, such as a cron job with a shell script, to copy or move the files after the backup job completes.

  5. 5

    A company has a main office and three remote branch offices. Each branch office has its own Event Collector which sends data back to the central QRadar Console and Processor at the main office. This configuration is an example of which type of QRadar architecture?

    graph TD subgraph Main Office Console[QRadar Console] Processor[Event Processor] end subgraph Branch Office A CollectorA[Event Collector] end subgraph Branch Office B CollectorB[Event Collector] end subgraph Branch Office C CollectorC[Event Collector] end CollectorA --> Processor CollectorB --> Processor CollectorC --> Processor Processor --> Console

    Show answer details

    Correct answer: C

    This is a classic example of a distributed QRadar architecture. An All-in-One system combines all components onto a single appliance. A distributed architecture separates components onto different appliances, such as placing Event Collectors at remote sites to collect and forward data to a central processing and console location.

  6. 6

    A financial institution is implementing a multi-tenant QRadar deployment to serve three distinct business units: Retail Banking, Investment Banking, and Wealth Management. Compliance mandates strict data segregation between these units. The administrator has created a separate Domain for each unit. During testing, it's discovered that a shared, central authentication log source is visible to users in all three domains. What is the most appropriate action to ensure the shared log source's data is correctly segregated and assigned to the relevant domain based on event payloads?

    Show answer details

    Correct answer: D

    When a log source contains data relevant to multiple domains, it should not be assigned to a single domain. Instead, the log source should be left unassigned. Then, a custom event property can be created to parse a unique identifier from the event payload (e.g., a business unit ID). This custom property is then configured to tag events to the correct domain, ensuring proper data segregation at the event level.

  7. 7

    An administrator is tasked with integrating a new third-party threat intelligence feed that provides a list of malicious C2 server IPs. The goal is to create a rule that generates an offense when any internal asset communicates with an IP from this feed. Which combination of QRadar components is the most efficient and scalable way to implement this?

    Show answer details

    Correct answer: C

    The most efficient and scalable method is to use a reference set. Threat intelligence feeds can be configured to automatically populate and update the reference set with the latest malicious IPs. A rule can then use a simple, high-performance test to check if a source or destination IP 'is contained in' this reference set. This avoids inefficient regex parsing or manual updates.

  8. 8

    A new administrator is trying to understand user permissions. They find that a junior analyst, who is assigned a specific User Role and Security Profile, is unable to view events from a critical log source, even though their Security Profile explicitly grants access to it. Which QRadar component is most likely overriding the Security Profile and causing this restriction?

    Show answer details

    Correct answer: B

    In a multi-tenant environment, tenant assignments are a primary layer of data access control. Even if a user's Security Profile grants access to a log source, they will not be able to see its data if their assigned Tenant does not have access to the Domain where that log source resides. Tenant permissions take precedence in this scenario.

  9. 9

    During a performance audit, an administrator identifies a custom rule that uses the following test: and when the event payload contains this regex '.∗(user|admin|root) failed login.∗'. This rule is causing a significant load on the Custom Rule Engine (CRE). What is the BEST practice to optimize this rule while maintaining its security value?

    Show answer details

    Correct answer: C

    Payload-based regex searches are computationally expensive. The best practice is to create optimized, field-based custom event properties (e.g., 'Username', 'Login Status') at the log source level. The rule can then use highly efficient tests against these indexed properties instead of performing a regex search on the entire payload for every event, dramatically improving performance.

  10. 10

    An administrator needs to create a daily report of all offenses that were closed with the closing reason 'False Positive'. The report should be automatically generated at 8 AM every morning and emailed to the security management team. Which steps must be taken to configure this? (Select TWO)

    Show answer details

    Correct answer: A, C

Create an account to continue.