What is the most restrictive permissions a user needs in order to see all of the events from a particular log source in the Log Activity tab?
When restoring backups of your apps in a QRadar environment, what information is restored?
Which authentication type in QRadar encrypts the username and password and forwards the username and password to the external server for authentication?
An administrator opens the Offenses section and goes to Rules to edit the system notification rule. What is the rule name for system notifications?
When do you consider reconfiguring your QRadar environment to a distributed deployment?
The Report wizard provides a step-by-step guide to design, schedule, and generate reports. Which three (3) key elements does the report wizard use to help you create a report?
You analyzed network flows and decided that you want to track any network bandwidth violations by any application that comes from your network source. You want to report on all applications that create traffic and the amount of data (total bytes) from each IP. You want to store the IP address, the application, and the amount of data in the reference data collection.
What type of reference data collection must you create to support this use case?
An administrator would like to optimize event and flow payload searches for log data that is stored for up to a month. What does an administrator need to do to achieve that requirement?
What is the default day and time setting for when QRadar generates weekly reports?
A ORadar administrator creates a new saved search in QRadar and wants to add the search to a dashboard, but the option "Include in my Dashboard" cannot be selected.
What is a possible reason it is unavailable?