Full Name: IBM Certified Associate Administrator - IBM QRadar SIEM V7.3.2
Exam Code: C1000-026
IBM QRadar SIEM Fundamental Administration Exam Summary:
Exam Name
|
IBM Certified Associate Administrator - IBM QRadar SIEM V7.3.2
|
Exam Code
|
C1000-026
|
Exam Price
|
$200 (USD)
|
Duration
|
90 minutes
|
Number of Questions
|
60
|
Passing Score
|
67%
|
Training
|
|
Sample Questions
|
|
Practice Exam
|
IBM C1000-026 Exam Syllabus Topics:
Topic | Details | Weights |
Implementing | - Plan and design QRadar deployment. - Implement and install QRadar. - Add Managed Hosts. |
8% |
Migrating and upgrading | - Plan QRadar upgrade and migration. - Review documentation and release notes. - Perform QRadar updates, patches and upgrades. - Perform migration (e.g., backup and restore, import and export content). |
12% |
Configuring and administering tasks | - Configure event flow sources and custom properties. - Maintain configuration and data backups. - Create and administer users, user roles, and security profiles. - Manage the license per allocation. - Create, review and modify rules, building blocks and reference sets. - Configure and manage retention policies (i.e., data and assets). - Create and manage saved searches, index, global views, dashboards and reports. - Deploy and manage applications and content packages. - Configure global system notifications. - Configure and apply network hierarchy. - Configure and manage domain and tenants. - Use the asset database. - Schedule and run a VA scan. |
42% |
Monitoring | - Monitor QRadar Notifications and error messages. - Review and interpret system monitoring dashboards. - Verify QRadar processes and services. - Monitor QRadar performance. - Use apps and tools for monitoring (e.g., QDI, assistant app, incident overview, DrQ). - Check system maintenance and health of appliances. - Monitor offenses and detect anomalies. |
25% |
Troubleshooting | - Demonstrate knowledge of key commands to interpret QRadar services and processes. - Explain error messages and notifications. - Interpret the basic logs (e.g., qradar.error, qradar.log). - Use embedded troubleshooting tools and scripts. |
13% |
0 comments:
Post a Comment