Thursday 21 September 2017

C2150-612 IBM Security QRadar SIEM V7.2.6 Associate Analyst

Test information:
Number of questions: 54
Time allowed in minutes: 90
Required passing score: 66%
Languages: English, Japanese

Related certifications:
IBM Certified Associate Analyst - Security QRadar SIEM V7.2.6

The test consists of 5 sections containing a total of approximately 54 multiple-choice questions. The percentages after each section title reflect the approximate distribution of the total question set across the sections.

Section 1 - General Networking and QRadar SIEM concepts (17%)
Compare different protocols, traffic types, and port numbers.
Describe and illustrate log source types.
Compare the different event log transport methods.
Discuss security device concepts (firewall, IDS/IPS, Proxy, Authentication devices, and antivirus software).
Explain how environment information can be used to enrich event and flow data intelligently.
Explain data normalization and categorization.
Enumerate the common characteristics of a SIEM.

Section 2 - QRadar basics (26%)
Explain the different types of correlations (CRE and ADE).
Illustrate the function of a DSM.
Explain how Log sources, flow sources, vulnerability scanners, and reference data are used in Qradar.
Compare flows to events.
Explain QRadar network hierarchy and how it aids in "seeing the whole picture" .
Describe additional QRadar add-on components (QVM, QRM, QRIF).
Distinguish offenses from triggered rules.
Distinguish search results from reports.
Distinguish rules from building blocks.
Compare rule responses and rule actions.
Explain the core system functionality of �Host Definition� building blocks.
Summarize QRadar Components; Console, Event Processor, Event Collector, Flow Processor, Data Nodes and Flow Collector.

Section 3 - QRadar login and navigation (13%)
Explain how to login to and navigate the GUI console.
Describe the types of information available on the DASHBOARD tab.
Describe the types of information available on the OFFENSES tab.
Describe the types of information available on the LOG ACTIVITY and NETWORK ACTIVITY tabs.
Describe the types of information available on the ASSETS tab.
Describe the types of information available on the REPORT tab.
Demonstrate the appropriate procedure to navigate to, from and within an offense.

Section 4 - QRadar functions and capabilities (18%)
Explain the different ways to assign offenses and add notation.
Summarize offense search functionalities.
Illustrate examples of dashboard customizations.
Distinguish right click functionality (plugins, information, navigate, other).
Demonstrate the use of right-click event filtering.
Explain how to explore the content of an event, review the normalized fields and the payload.
Show the Offense lifecycle.
Compare Event/Flow/Common/Offense/Anomaly/Behavioral/ Threshold Rules.
Demonstrate how to export Flow/Event data for external analysis.

Section 5 - QRadar data interpretation (26%)
Explain Offense details on offense details view.
Explain why payloads (raw data) may need to be reviewed.
Distinguish offenses from triggered rules.
Examine the differences between an offense magnitude and an event magnitude.
Describe how to run Reports and the formats in which they can be output.
Outline Offense Closing Procedures.
Discuss the Asset Database and how assets are profiled.
Outline simple Offense naming mechanisms (Removed: not testable).
Explain differences between various event/flow timestamps.
Understand the capabilities of different sources of flows.
Give examples of how QRadar can show different security concerns (i.e., Advanced Persistent Threat (APT), Brute Force, DDoS, etc.)
Describe coalescing.
Compare Standard Custom Properties, User-defined Custom Properties and Normalized properties.
Compare the different types of searches that can be performed (AQL, Quick Searches, and Searches via the Edit Search GUI panel).
Explain the information provided by flows.
Describe a use where flows provide more information than events.

IBM Certified Associate Analyst - Security QRadar SIEM V7.2.6

Job Role Description / Target Audience
This entry level certification is intended for security analysts who wish to validate their comprehensive knowledge of IBM Security QRadar SIEM V7.2.6.

These security analysts will understand basic networking, SIEM, and QRadar concepts, including how to login to, navigate within, explain capabilities of, and access, interpret, and report data in a QRadar deployment.

To attain the IBM Certified Associate Analyst - Security QRadar SIEM V7.2.6 certification, candidates must pass 1 test. To prepare for the test, it is recommended to refer to the job role description and recommended prerequisite skills, and click the link to the test below to refer to the test objectives and the test preparation tab.

Recommended Prerequisite Skills

Basic knowledge of:
SIEM concepts
TCP/IP networking and protocols
network security concepts
internet security attack types
compliance and audit requirements
incident management and response

Requirements
This certification requires 1 test(s).

QUESTION: No: 1
Where can a user add a note to an offense in the user interface?

A. Dashboard and Offenses Tab
B. Offenses Tab and Offense Detail Window
C. Offenses Detail Window, Dashboard, and Ad min Tab
D. Dashboard, Offenses Tab, and Offense Detail Window

Answer: B

QUESTION: No: 2
When might a Security Analyst want to review the payload of an event?

A. When immediately after login, the dashboard notifies the analyst of payloads that must be investigated
B. When "Review payload" is added to the offense description automatically by the "System: Notification" rule
C. When the event is associated with an active offense, the payload may contain information that is not normalized or extracted fields
D. When the event is associated with an active offense with a magnitude greater than 5, the payload should be reviewed, otherwise it is not necessary

Answer: C

QUESTION: No: 3
Which key elements does the Report Wizard use to help create a report?

A. Layout, Container, Content
B. Container, Orientation, Layout
C. Report Classification, Time, Date
D. Pagination Option, Orientation, Date

Answer: A

QUESTION: No: 4
How is an event magnitude calculated?

A. As the sum of the three properties Severity, Credibility and Relevance of the Event
B. As the sum of the three properties Severity, Credibility and Importance of the Event
C. As a weighted mean of the three properties Severity, Credibility and Relevance of the Event
D. As a weighted mean of the three properties Severity, Credibility and Importance of the Event

Answer: C

QUESTION: No: 5
What is a benefit of using a span port, mirror port, or network tap as flow sources for QRadar?

A. These sources are marked with a current timestamp.
B. These sources show the ASN number of the remote system .
C. These sources show the username that generated the flow.
D. These sources include payload for layer 7 application analysis.

Answer: D

Saturday 2 September 2017

Exam 70-735 OEM Manufacturing and Deployment for Windows 10

Published: June 19, 2017
Languages: English
Audiences: IT Professionals
Technology: Windows 10
Credit toward certification: MCP

Skills measured
This exam measures your ability to accomplish the technical tasks listed below. The percentages indicate the relative weight of each major topic area on the exam. The higher the percentage, the more questions you are likely to see on that content area on the exam. View video tutorials about the variety of question types on Microsoft exams.

Please note that the questions may test on, but will not be limited to, the topics described in the bulleted text.

Do you have feedback about the relevance of the skills measured on this exam? Please send Microsoft your comments. All feedback will be reviewed and incorporated as appropriate while still maintaining the validity and reliability of the certification process. Note that Microsoft will not respond directly to your feedback. We appreciate your input in ensuring the quality of the Microsoft Certification program.

If you have concerns about specific questions on this exam, please submit an exam challenge.

If you have other questions or feedback about Microsoft Certification exams or about the certification program, registration, or promotions, please contact your Regional Service Center.

Prepare the Imaging Environment (20-25%)
Install deployment tools and scripts
Prepare the Windows Assessment and Deployment Kit (Windows ADK), prepare the required tools from the Windows ADK installation
Add customizations to the image
Use tools to design an answer file that will add branding to the device, add OEM information such as support URL or phone support number, provide the default product key for OEM Activation implementation, set the default user languages, add the custom logo and wallpaper
Create a Windows Preinstallation Environment (Windows PE)
Use the Windows ADK scripts to create the Windows PE source files, add optional packages, add default languages, add custom scripts, create a bootable USB or ISO file of the Windows PE, add device drivers

Service the Offline Image (40-45%)
Add drivers to the image
Choose the recommended installation paths for adding drivers, add INF-based drivers offline, add INF-based drivers from a folder path using deployment tools
Add language packs to the image
Distinguish the difference between a language pack and a language interface pack; determine when to use Feature on Demand language packs, how to apply the ordering of Feature on Demand language packs when adding new languages to the image, and which language packs should be applied to the Recovery image; set the default time zone in the image; set the default input and system locales in the image
Add update packages to the image
Choose which updates to apply, select which updates to apply to Windows image and Recovery image
Service in-box applications
Reapply in-box applications, select the appropriate dependency packages for each application bundle, troubleshoot installation failures, pin apps to Start layout and taskbar
Optimize the image
Mark updates in a Recovery image as permanent, export a Recovery image, set scratch space size, check the overall size of a Recovery image for partition layout schemes
Deploy the image
Select the disk partition layout, run DISM to apply the image, set up the recovery environment, boot into Audit mode for online servicing

Service the Online Image (35-40%)
Preinstall Office 2016
Prepare office files for preinstallation, create configuration files, add multiple languages, set up the first user experience
Create restore packages
Use ScanState to create restore packages of installed desktop applications, registry settings, and application settings
Prepare the recovery environment
Create extensibility scripts, create configuration files, create migration files, copy backup files to the recovery folder for Push Button Reset
Reseal the image
Use Sysprep to reseal the image to OOBE, boot to Windows PE for final capture, optimize the image for disk footprint, mark update packages as permanent, optimize the image for deployment, use deployment tools to capture the final image for mass deployment
Deploy and validate the image
Test the final image deployment, verify that settings are correct, the image passes system validation tests, and Push Button Reset restores the image to its correct state
QUESTION 1
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You are building a new image of Windows 10 that contains a push-button reset solution.
You need to test whether push-button reset works as expected.
Solution: From Windows 10. you press and hold the SHIFT key, and then you restart the computer. After the computer restarts, you click Troubleshoot, and then you click Reset this PC.
Does this meet the goal?

A. Yes
B. No

Answer: B


QUESTION 2
Note: This question is part of a series of questions that use the same or similar answer choices. An answer choice may be correct for more than one question in the series. Each question Is independent of the other questions in this series. Information and details provided in a question apply only to that question.
You have a computer named Computer1 that runs Windows 10. Computer1 has the Windows Assessment and Deployment Kit (Windows ADK) installed.
You are building a new image of Windows 10.
You copy the installation media for Windows 10 to Computer1.
You need to add drivers to the Windows 10 image.

A. Mount the Install.wim file.
B. Mount the Boot.wim file.
C. Modify the Winpeshl.ini file.
D. Create an answer file.
E. Modify the Windows.ini file.
F. Create a provisioning package.
G. Load a catalog file (.clg).
H. Create a cabinet file (.cab).

Answer: B


QUESTION 3
This question requires that you evaluate the underlined text to determine if it is correct.
To provide the default product key for OEM activation, you create an answer file by using Windows System Image Manager (Windows SIM), and you add the Microsoft-Windows-Shell-Setup component and the ProductKey component to the generalize pass.
Review the underlined text. It it makes the statement correct, select "No change is needed." If the statement is incorrect, select the answer choice that makes the statement correct.

A. No change is needed
B. auditSystem pass
C. specialize pass
D. windowsPE pass

Answer: C


QUESTION 4
You deploy an image of Windows 10.
From audit mode, you install several applications for a customer, and then you run sysprep.exe /oobe /quit.
You need to identify whether any errors occurred when you ran sysprep.exe.
Which folder contains the log files?

A. %WINDIR%\Logs
B. %WlNDIR%\System32\LogFiles
C. %WINDIR%\Panther\
D. %WINDIR%\System32\Sysprep\Panther

Answer: D