🌍 All Study Guides📊 Dashboard📰 Blog💡 About
IBM Cybersecurity Analyst Professional Certificate • STUDY MODE

PRACTICE QUIZ

QUESTION 1 OF 21

Which three (3) of the following are core functions of a SIEM? (Select 3)

A
Consolidates log events and network flow data from thousands of devices, endpoints and applications distributed throughout a networkCorrect Answer
B
Blocks actions or packet flows that violate security policies
C
Manages network security by monitoring flows and eventsCorrect Answer
D
Collects logs and other security documentation for analysisCorrect Answer
QUESTION 2 OF 21

True or False. SIEMs capture network flow data in near real time and apply advanced analytics to reveal security offenses.

A
TrueCorrect Answer
B
False
QUESTION 3 OF 21

Which of these describes the process of data normalization in a SIEM?

A
Removes duplicate records from incoming data
B
Compresses incoming
C
Turns raw data into a format that has fields that SIEM can useCorrect Answer
D
Encrypts incoming data
QUESTION 4 OF 21

True or False. A SIEM considers any event that is anomalous, or outside the norm, to be an offense.

A
TrueCorrect Answer
B
False
QUESTION 5 OF 21

True or False. A large company might have QRadar event collectors in each of their data centers that are configured to forward all collected events to a central event processor for analysis.

A
TrueCorrect Answer
B
False
QUESTION 6 OF 21

The triad of a security operations centers (SOC) is people, process and technology. Which part of the triad would vendor-specific training belong? ARTIFICIAL INTELLIGENCE IN SIEMS KNOWLEDGE CHECK

A
PeopleCorrect Answer
B
Process
C
Technology
D
None of the above
QUESTION 7 OF 21

True or False. Information is often overlooked simply because the security analysts do not know how it is connected.

A
TrueCorrect Answer
B
False
QUESTION 8 OF 21

The partnership between security analysts and technology can be said to be grouped into 3 domains, human expertise, security analytics and artificial intelligence. The human expertise domain would contain which three (3) of these topics?

A
Bias elimination
B
Common senseCorrect Answer
C
GeneralizationCorrect Answer
D
MoralsCorrect Answer
E
Pattern identification
F
Anomaly detection
QUESTION 9 OF 21

A robust cybersecurity defense includes contributions from 3 areas, human expertise, security analytics and artificial intelligence. Which of these areas would contain the ability for abstraction? SIEM PLATFORMS GRADED ASSESSMENT

A
Human expertiseCorrect Answer
B
Artificial intelligence
C
Security analytics
QUESTION 10 OF 21

True or False. SIEMs can be available on premises and in a cloud environment.

A
TrueCorrect Answer
B
False
QUESTION 11 OF 21

For a SIEM, what are logs of specific actions such as user logins referred to?

A
Logs
B
Actions
C
EventsCorrect Answer
D
Flows
QUESTION 12 OF 21

When a data stream entering a SIEM exceeds the volume it is licensed to handle, what are three (3) ways the excess data is commonly handled, depending upon the terms of the license agreement? (Select 3)

A
The data stream is throttled to accept only the amount allowed by the licenseCorrect Answer
B
The data is processed and the license is automatically bumped up to the next tier.
C
The excess data is droppedCorrect Answer
D
The excess data is stored in a queue until it can be processedCorrect Answer
QUESTION 13 OF 21

Which five (5) event properties must match before the event will be coalesced with other events? (Select 5)

A
Source Port
B
Destination PortCorrect Answer
C
Source IPCorrect Answer
D
QIDCorrect Answer
E
UsernameCorrect Answer
F
Destination IPCorrect Answer
QUESTION 14 OF 21

What is the goal of SIEM tuning?

A
To get the SIEM to present all recognized offenses to the investigators
B
To get the SIEM to sort out all false-positive offenses so only those that need to be investigated are presented to the investigatorsCorrect Answer
C
To increase the speed and efficency of the data processing so license caps are never exceeded.
D
To automatically resolve as many offenses as possible with automated actions
QUESTION 15 OF 21

True or False. QRadar event collectors send all raw event data to the central event processor for all data handling such as data normalization and event coalescence.

A
True
B
FalseCorrect Answer
QUESTION 16 OF 21

The triad of a security operations centers (SOC) is people, process and technology. Which part of the triad would containment belong?

A
People
B
ProcessCorrect Answer
C
Technology
D
None of the above
QUESTION 17 OF 21

True or False. There is a natural tendency for security analysts to choose to work on cases that they are familiar with and to ignore those that may be important but for which they have no experience.

A
TrueCorrect Answer
B
False
QUESTION 18 OF 21

The partnership between security analysts and technology can be said to be grouped into 3 domains, human expertise, security analytics and artificial intelligence. The security analytics domain contains which three (3) of these topics?

A
Data correlationCorrect Answer
B
Generalization
C
Common sense
D
Anomaly detectionCorrect Answer
E
Pattern identificationCorrect Answer
F
Natural language
QUESTION 19 OF 21

A robust cybersecurity defense includes contributions from 3 areas, human expertise, security analytics and artificial intelligence. Which of these areas would contain the ability for data visualization?

A
Artificial intelligence
B
Security analyticsCorrect Answer
C
Human expertise
QUESTION 20 OF 21

The triad of a security operations centers (SOC) is people, process and technology. Which part of the triad would vendor-specific training belong?

A
PeopleCorrect Answer
B
Process
C
Technology
D
None of the above
QUESTION 21 OF 21

A robust cybersecurity defense includes contributions from 3 areas, human expertise, security analytics and artificial intelligence. Which of these areas would contain the ability for abstraction?

A
Human expertiseCorrect Answer
B
Artificial intelligence
C
Security analytics

Ready to test your recall?

Which three (3) of the following are core functions of a SIEM? (Select 3)

💡Select all 3 correct answers before submitting (0 of 3 selected).
A
Consolidates log events and network flow data from thousands of devices, endpoints and applications distributed throughout a network
B
Blocks actions or packet flows that violate security policies
C
Manages network security by monitoring flows and events
D
Collects logs and other security documentation for analysis

How confident are you in this answer?