C1000-156 Sample Questions & Answers
System configuration and deployment architecture take the top share, plus optimizing performance and rules, setting up flow and log sources, tuning accuracy, managing users and multi-tenant domains, reporting, and troubleshooting notifications.
Launch the full C1000-156 simulator →Showing 10 of 20 free samples.
- Question 1Advanced
Troubleshooting · Troubleshoot common documented issues
A QRadar administrator is investigating an issue where NetFlow data from a core router is not appearing in the 'Network Activity' tab. The administrator has verified that the router is configured to send NetFlow v9 packets to the correct IP address of the Flow Processor and that there are no firewalls blocking the traffic. The output of
tcpdumpon the Flow Processor shows UDP packets arriving from the router on the configured port. What is the most likely reason the flows are not being processed by QRadar?Show answer & explanation
Correct answer: B
Even if flow packets are successfully arriving at the Flow Processor, QRadar will not process them until a corresponding flow source is configured in the Admin tab. This configuration tells QRadar to expect flows from a specific IP address and how to interpret them (e.g., NetFlow version, domain assignment). Without this, the incoming packets are ignored.
- Question 2Beginner
System Configuration · Install and configure apps
An administrator has deployed a new QRadar App Host to handle a growing number of applications. After installation and adding the App Host to the deployment, several apps fail to start, and the system notifications show errors related to resource allocation. What is the first and most critical configuration step that must be performed on the App Host to ensure applications have sufficient resources?
Show answer & explanation
Correct answer: B
After adding an App Host to the deployment, the administrator must explicitly allocate memory and CPU resources to it from the System and License Management settings. By default, the allocation might be zero or insufficient. This step reserves the necessary system resources for the App Host to run applications effectively.
- Question 3Intermediate
User Management · Create and update user roles
True or False: When configuring a new user role, permissions assigned at the role level will override any conflicting, more restrictive permissions set in the user's assigned Security Profile.
Show answer & explanation
Correct answer: B
QRadar applies the most restrictive set of permissions. A user's effective permissions are the intersection of their User Role, Security Profile, and Tenant assignments. A Security Profile can only restrict access further; it cannot grant permissions that are denied by the User Role.
- Question 4Beginner
Data Source Configuration · Manage custom log source types
A new custom log source for a proprietary application is sending events that are not being correctly parsed and are appearing as 'Unknown'. The administrator has confirmed the events are reaching the Event Collector. The goal is to create a custom Log Source Type to parse these events correctly. What is the first tool the administrator should use to begin this process?
Show answer & explanation
Correct answer: C
The DSM (Device Support Module) Editor is the primary tool within QRadar for creating and modifying Log Source Types. It provides an interface to define parsing rules, map events to QID records, and extract custom properties for log sources that are not natively supported.
- Question 5Intermediate
Troubleshooting · Basic GUI REST-API usage
An administrator is attempting to use the interactive REST API console to troubleshoot an application. When trying to access the API documentation page, the browser returns a '401 Unauthorized' error. The administrator is logged into the QRadar console with full administrative privileges. What is the most likely cause of this issue?
Show answer & explanation
Correct answer: B
Access to the QRadar REST API requires an authorized service token, not just an active GUI session. The administrator must first create an authorized service in the Admin tab, generate a token, and then use that token in the header of their API requests for authentication. The interactive API console also requires this token to be entered for authorization.
- Question 6Advanced
Performance Optimization · Manage routing rules and event forwarding
A QRadar administrator needs to temporarily stop specific, noisy events from a non-critical server from being processed and stored in the Ariel database to reduce license usage during a maintenance window. However, they need to ensure the events are still collected and could be processed later if needed. What is the most appropriate feature to use?
Show answer & explanation
Correct answer: D
A Routing Rule can be configured to match specific events (e.g., from the noisy server) and set the action to 'Drop'. Crucially, the rule has a separate option, 'Store Event'. By enabling 'Store Event' but dropping it from further processing (like correlation), the event is written to disk but does not count against the license or generate offenses. This meets the requirement of storing the data without full processing.
- Question 7Intermediate
Accuracy Tuning · Manage and use building blocks
A new administrator is reviewing the system's accuracy and notices many offenses are being generated for 'SSH Brute Force'. Upon investigation, they realize these are all originating from their internal vulnerability scanner, which is expected behavior. What is the most effective and maintainable way to prevent the scanner from generating these false positive offenses?
Show answer & explanation
Correct answer: C
Using a building block is the most effective and maintainable solution. The administrator can create a single building block (e.g., 'BB:HostDefinition: Vulnerability Scanners') containing the scanner's IP. This block can then be easily added as an 'and not' condition to the 'SSH Brute Force' rule and any other rules to prevent false positives. If the scanner's IP changes, only the building block needs to be updated.
- Question 8Intermediate
Data Source Configuration · Manage data obfuscation
To comply with data privacy regulations, an administrator must prevent sensitive Personally Identifiable Information (PII), such as credit card numbers, from being written to the Ariel database in its raw format. The PII appears in the payload of events from a specific log source. Which QRadar feature should be used to achieve this?
Show answer & explanation
Correct answer: A
Data Obfuscation Profiles are designed specifically for this purpose. An administrator can create a profile that uses regex to identify sensitive data patterns (like credit card numbers) within event payloads from specific log sources and then masks or anonymizes that data before it is written to disk.
- Question 9Intermediate
System Configuration · Demonstrate the use of the asset database
An organization wants to integrate its HR system with QRadar to provide context on user identities. Specifically, they want to be able to see a user's real name and department alongside their username in event details and offenses. What QRadar feature allows for the enrichment of asset and identity data from an external CSV file or LDAP server?
Show answer & explanation
Correct answer: B
The Asset Profiler is responsible for building and maintaining the asset database, including user identity information. It can be configured to import identity data from external sources like LDAP directories or CSV files. This process enriches the asset database, linking usernames to additional details like full names and departments, which then becomes visible throughout the QRadar UI.
- Question 10Beginner
Tenants and Domains · Differentiate network hierarchy and domain definition
What is the primary difference between how QRadar's Network Hierarchy and Domains are used for data management?
Show answer & explanation
Correct answer: B
The Network Hierarchy is used to model the physical and logical layout of the network, which helps QRadar determine traffic direction (local-to-remote, etc.) for rule tuning. Domains, on the other hand, are a security feature used to enforce strict data segregation, typically in multi-tenant or MSSP environments, ensuring that events and flows are only visible to users and processes assigned to that specific domain.
Ready for the real thing?
The full C1000-156 simulator has every exam-style question, timed mode, and instant scoring.