IBM Security QRadar SIEM V7.5 Administration Free Sample Questions

20 free sample questions235 in the full practice test

Try simulator

C1000-162 Sample Questions

  1. Question 1

    A Tier 2 SOC analyst at a financial services firm is investigating a high-magnitude offense related to 'Anomalous Database Activity'. The offense is triggered by a rule that correlates login events from a privileged user account with subsequent large data extractions from a production database. To distinguish between a legitimate administrative task and a potential insider threat, which investigative step should the analyst prioritize?

    Answer and explanation

    Correct answer: B

    The most effective next step is to analyze the payload of the associated events. This will reveal the specific SQL queries run, which provides crucial context to differentiate between a routine backup/maintenance script (e.g., SELECT * FROM table_backup) and a malicious data exfiltration attempt (e.g., SELECT ssn, credit_card FROM customers). Escalating without this context is premature, reviewing past offenses is less direct, and checking asset profiles does not explain the specific action taken.

  2. Question 2

    Multiple answers

    A threat hunter is using an AQL query to find evidence of a slow data exfiltration attempt where small amounts of data were sent to multiple external IP addresses over a long period. The current query is returning too many results and timing out. Which TWO of the following AQL query modifications would most effectively optimize the search and narrow the results to the most relevant indicators? (Select TWO)

    Answer and explanation

    Correct answers: B, C

    Grouping by the destination IP and then counting unique source IPs can quickly highlight a single external IP being contacted by many internal systems, a potential C2 server. This aggregation is computationally efficient.

    The HAVING clause is used after GROUP BY to filter aggregated results. By summing the bytes sent to each destination and filtering for a total that is suspiciously large but spread out, the analyst can pinpoint slow exfiltration targets.

  3. Question 3

    While analyzing an offense, a security analyst needs to quickly determine if an IP address flagged as a source of malicious activity is part of a known botnet. Which QRadar feature provides the most direct and context-rich method for this investigation?

    Answer and explanation

    Correct answer: B

    The right-click investigation feature is designed for this exact purpose. It provides context-sensitive actions, including querying integrated threat intelligence feeds (like X-Force Exchange) for data on IPs, hashes, or URLs. This is the most direct and efficient method to check if an IP is associated with known malicious infrastructure like a botnet.

  4. Question 4

    A new log source for a custom in-house application is sending events to QRadar, but they are all appearing as 'Unknown'. The application logs contain a unique 'transactionID' field that is critical for correlating user activity. The security team has recommended creating a custom event property to extract this ID. After the custom property is created and deployed, what is the immediate next step an analyst should take to make this field usable in searches and rules?

    Answer and explanation

    Correct answer: A

    While creating the custom property is the first step, it is not searchable in quick filters or performant in AQL queries until it is enabled for indexing. Enabling indexing tells QRadar to specifically parse and store this property in the Ariel database for fast retrieval, which is essential for its effective use in rules, searches, and analysis.

  5. Question 5

    True or False: The primary purpose of a Building Block in QRadar is to trigger an offense and generate a notification when its conditions are met.

    Answer and explanation

    Correct answer: B

    This statement is false. Building Blocks are collections of reusable test conditions that, by themselves, do not create offenses or trigger responses. They are designed to be used as components within other rules to simplify complex logic and avoid redundancy. Only a Rule can trigger an offense or response.

  6. Question 6

    A security analyst is building a report to show the top 10 internal hosts that have communicated with countries on a 'High-Risk Geo-Locations' reference set over the past 30 days. Which QRadar feature is essential for creating this report?

    Answer and explanation

    Correct answer: C

    To achieve this, the analyst must use an advanced search with AQL. The key is to use the GEO::LOOKUP function to enrich the flow data with geolocation information for the destination IP. This result is then filtered against the 'High-Risk Geo-Locations' reference set. Finally, grouping by sourceip allows the analyst to count and rank the internal hosts. This saved search can then be used as the basis for the report.

  7. Question 7

    A hospital's security team is trying to reduce the number of false positive offenses generated by a rule that detects 'Multiple Login Failures from Dormant Account'. The rule correctly identifies login failures but often triggers on accounts that are not truly dormant, such as those used by on-call staff who log in infrequently. What is the most effective way to tune this rule to improve its accuracy?

    Answer and explanation

    Correct answer: C

    The core problem is that the rule lacks the context to differentiate between truly dormant accounts and legitimately infrequent users. Creating a reference set of authorized infrequent users (like on-call staff) and adding a condition to the rule like 'and when the username is not contained in On-Call Staff Accounts reference set' is the most precise way to tune it. This directly addresses the source of the false positives without weakening the rule's ability to detect actual threats against other accounts.

  8. Question 8

    Multiple answers

    An analyst wants to create a QRadar Pulse dashboard that provides an at-a-glance view of all active offenses, color-coded by magnitude, and a real-time chart of event rates from critical servers. Which Pulse dashboard items would be most appropriate to build this view? (Select TWO)

    Answer and explanation

    Correct answers: A, C

    A time series chart is the ideal way to visualize data over time. By using an AQL query that filters for events from critical servers (...WHERE logsourceid IN (...)) and groups them by time, the analyst can create the required real-time chart of event rates.

    The Offense Summary dashboard item is specifically designed for this purpose. It can be configured to display active offenses and has built-in options to use the offense magnitude to set the background color, providing an immediate visual indicator of severity.

  9. Question 9

    A junior analyst is investigating an offense and notices that several contributing events are labeled as 'Stored'. What does this indicate about those events?

    Answer and explanation

    Correct answer: C

    An event is marked as 'Stored' when QRadar's coalescing mechanism determines it is a duplicate of an event that occurred within a short time frame (e.g., multiple failed login attempts from the same source to the same destination). The system processes the first event fully and increments its event count, while subsequent identical events are 'stored' without being fully processed to save resources. This prevents rule chains from being flooded with redundant data but ensures the activity is recorded.

  10. Question 10

    An analyst is using the Log Activity tab to investigate a potential malware infection on a user's workstation. They need to find all events related to DNS queries for a specific suspicious domain, 'malicious-domain.com', that occurred in the last 24 hours. What is the most efficient way to perform this search using the quick filter bar?

    Answer and explanation

    Correct answer: A

    The 'Payload Contains' quick filter performs a simple text search on the full, unparsed payload of every event. This is the most direct and efficient method for finding a specific string like a domain name, especially when you are unsure which specific parsed field (if any) might contain it. Combining this with the time range filter for 'Last 24 Hours' precisely meets the analyst's requirements.

Register free to unlock 10 more sample questions

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 235 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon