Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

IBM C1000-156 Exam - Topic 6 Question 39 Discussion

Actual exam question for IBM's C1000-156 exam
Question #: 39
Topic #: 6
[All C1000-156 Questions]

When will events or flows stop contributing to an offense?

Show Suggested Answer Hide Answer
Suggested Answer: A

In IBM QRadar SIEM V7.5, events or flows stop contributing to an offense when the offense becomes dormant. Here's how it works:

Dormant Offense: An offense becomes dormant when there is no new activity contributing to it for a specified period. This indicates that the threat or incident has not had any further related events or flows.

Contribution Stoppage: Once an offense is marked as dormant, no additional events or flows are added to it, which helps in managing the offense lifecycle and resources within QRadar.

This behavior helps in distinguishing between active and inactive threats, allowing security analysts to focus on ongoing incidents.

Reference The QRadar SIEM administration and user guides provide detailed explanations of offense management, including the conditions under which offenses become dormant and how this affects event and flow contributions.


Contribute your Thoughts:

0/2000 characters
Cortney
3 days ago
Wait, can offenses really just stop? Sounds odd.
upvoted 0 times
...
Antonio
8 days ago
Definitely B! Inactive means no more contributions.
upvoted 0 times
...
Helene
13 days ago
I think it's A or B.
upvoted 0 times
...
Curt
18 days ago
Protecting the offense sounds like it could be relevant, but I’m not confident that D is the right choice.
upvoted 0 times
...
Gabriele
23 days ago
I feel like C could be a trick answer since assigning it to an analyst doesn’t necessarily mean it stops contributing.
upvoted 0 times
...
Theresia
29 days ago
I remember a practice question about offenses becoming inactive, so I’m leaning towards B.
upvoted 0 times
...
Meaghan
1 month ago
I think the answer might be A, but I'm not entirely sure what "dormant" really means in this context.
upvoted 0 times
...

Save Cancel