Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

IBM Exam C1000-156 Topic 3 Question 24 Discussion

Actual exam question for IBM's C1000-156 exam
Question #: 24
Topic #: 3
[All C1000-156 Questions]

How can you configure a log source to provide events to different domains?

Show Suggested Answer Hide Answer
Suggested Answer: C, D

In the Domain Management function of IBM QRadar SIEM, two key data sources that can be assigned to a domain are Flow Collectors and Log Sources. Flow collectors capture and analyze network flow data, while log sources refer to various devices and applications that send log data to QRadar for analysis. By assigning these data sources to a domain, administrators can segment and manage the data more effectively, ensuring that the correct flow and log data are processed and analyzed within the designated domain. This segmentation enhances security and performance by isolating data handling according to domain-specific policies.

Reference QRadar SIEM V7.5 Administration Guide - Chapter on Domain Management and Data Source Assignment


Contribute your Thoughts:

Christiane
4 days ago
I'm not sure about that. Doesn't the Assistant app sound like a more straightforward way to update the domain information for the log source?
upvoted 0 times
...
Theodora
7 days ago
I think option C is the correct answer. Using custom properties seems like the best way to assign events from a single log source to different domains.
upvoted 0 times
...
Percy
10 days ago
I'm not sure, but D) sounds like it could also work by updating building blocks for multi domain events.
upvoted 0 times
...
Kimberely
13 days ago
I agree with Earleen, using custom properties makes sense for organizing events by domain.
upvoted 0 times
...
Earleen
15 days ago
I think the answer is C) Use custom properties to assign events from a single log source to different domains.
upvoted 0 times
...

Save Cancel