Qradar Siem V7.5 Administration Free Sample Questions

20 free sample questions202 in the full practice test

Try simulator

C1000-156 Sample Questions

  1. Question 1

    A financial institution is implementing a multi-tenant QRadar deployment to serve three distinct business units: Retail Banking, Investment Banking, and Wealth Management. Compliance mandates strict data segregation between these units. The administrator has created a separate Domain for each unit. During testing, it's discovered that a shared, central authentication log source is visible to users in all three domains. What is the most appropriate action to ensure the shared log source's data is correctly segregated and assigned to the relevant domain based on event payloads?

    Answer and explanation

    Correct answer: D

    When a log source contains data relevant to multiple domains, it should not be assigned to a single domain. Instead, the log source should be left unassigned. Then, a custom event property can be created to parse a unique identifier from the event payload (e.g., a business unit ID). This custom property is then configured to tag events to the correct domain, ensuring proper data segregation at the event level.

  2. Question 2

    An administrator is tasked with integrating a new third-party threat intelligence feed that provides a list of malicious C2 server IPs. The goal is to create a rule that generates an offense when any internal asset communicates with an IP from this feed. Which combination of QRadar components is the most efficient and scalable way to implement this?

    Answer and explanation

    Correct answer: C

    The most efficient and scalable method is to use a reference set. Threat intelligence feeds can be configured to automatically populate and update the reference set with the latest malicious IPs. A rule can then use a simple, high-performance test to check if a source or destination IP 'is contained in' this reference set. This avoids inefficient regex parsing or manual updates.

  3. Question 3

    A new administrator is trying to understand user permissions. They find that a junior analyst, who is assigned a specific User Role and Security Profile, is unable to view events from a critical log source, even though their Security Profile explicitly grants access to it. Which QRadar component is most likely overriding the Security Profile and causing this restriction?

    Answer and explanation

    Correct answer: B

    In a multi-tenant environment, tenant assignments are a primary layer of data access control. Even if a user's Security Profile grants access to a log source, they will not be able to see its data if their assigned Tenant does not have access to the Domain where that log source resides. Tenant permissions take precedence in this scenario.

  4. Question 4

    During a performance audit, an administrator identifies a custom rule that uses the following test: and when the event payload contains this regex '.∗(user|admin|root) failed login.∗'. This rule is causing a significant load on the Custom Rule Engine (CRE). What is the BEST practice to optimize this rule while maintaining its security value?

    Answer and explanation

    Correct answer: C

    Payload-based regex searches are computationally expensive. The best practice is to create optimized, field-based custom event properties (e.g., 'Username', 'Login Status') at the log source level. The rule can then use highly efficient tests against these indexed properties instead of performing a regex search on the entire payload for every event, dramatically improving performance.

  5. Question 5

    Multiple answers

    An administrator needs to create a daily report of all offenses that were closed with the closing reason 'False Positive'. The report should be automatically generated at 8 AM every morning and emailed to the security management team. Which steps must be taken to configure this? (Select TWO)

    Answer and explanation

    Correct answers: A, C

  6. Question 6

    A QRadar administrator is investigating an issue where NetFlow data from a core router is not appearing in the 'Network Activity' tab. The administrator has verified that the router is configured to send NetFlow v9 packets to the correct IP address of the Flow Processor and that there are no firewalls blocking the traffic. The output of tcpdump on the Flow Processor shows UDP packets arriving from the router on the configured port. What is the most likely reason the flows are not being processed by QRadar?

    Answer and explanation

    Correct answer: B

    Even if flow packets are successfully arriving at the Flow Processor, QRadar will not process them until a corresponding flow source is configured in the Admin tab. This configuration tells QRadar to expect flows from a specific IP address and how to interpret them (e.g., NetFlow version, domain assignment). Without this, the incoming packets are ignored.

  7. Question 7

    An administrator has deployed a new QRadar App Host to handle a growing number of applications. After installation and adding the App Host to the deployment, several apps fail to start, and the system notifications show errors related to resource allocation. What is the first and most critical configuration step that must be performed on the App Host to ensure applications have sufficient resources?

    Answer and explanation

    Correct answer: B

    After adding an App Host to the deployment, the administrator must explicitly allocate memory and CPU resources to it from the System and License Management settings. By default, the allocation might be zero or insufficient. This step reserves the necessary system resources for the App Host to run applications effectively.

  8. Question 8

    True or False: When configuring a new user role, permissions assigned at the role level will override any conflicting, more restrictive permissions set in the user's assigned Security Profile.

    Answer and explanation

    Correct answer: B

    QRadar applies the most restrictive set of permissions. A user's effective permissions are the intersection of their User Role, Security Profile, and Tenant assignments. A Security Profile can only restrict access further; it cannot grant permissions that are denied by the User Role.

  9. Question 9

    A new custom log source for a proprietary application is sending events that are not being correctly parsed and are appearing as 'Unknown'. The administrator has confirmed the events are reaching the Event Collector. The goal is to create a custom Log Source Type to parse these events correctly. What is the first tool the administrator should use to begin this process?

    Answer and explanation

    Correct answer: C

    The DSM (Device Support Module) Editor is the primary tool within QRadar for creating and modifying Log Source Types. It provides an interface to define parsing rules, map events to QID records, and extract custom properties for log sources that are not natively supported.

  10. Question 10

    An administrator is attempting to use the interactive REST API console to troubleshoot an application. When trying to access the API documentation page, the browser returns a '401 Unauthorized' error. The administrator is logged into the QRadar console with full administrative privileges. What is the most likely cause of this issue?

    Answer and explanation

    Correct answer: B

    Access to the QRadar REST API requires an authorized service token, not just an active GUI session. The administrator must first create an authorized service in the Admin tab, generate a token, and then use that token in the header of their API requests for authentication. The interactive API console also requires this token to be entered for authorization.

Register free to unlock 10 more sample questions

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 202 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon