Question 8
A Deployment Professional is looking over event and flow data for a new customer and sees that the customer is hitting 4,000 EPS/300,000 FPM, with bursts of up to 5,000 EPS/400,000 FPM. The customer is asking for the least amount of appliances to be installed to handle this traffic without any throttling.
Which combination should be installed?
Install the IBM Security QRadar 3105 (Console) and add a QRadar 1805
Install the IBM Security QRadar 3105 (Console) and add a QRadar Flow Processor 1705
Install the IBM Security QRadar 3105 (Console) and add a QRadar Flow Processor 1828
Install the IBM Security QRadar 3105 (Console) and add a QRadar Event Processor 1605
Correct answer: B
Explanation:
The QRadar 3105 (All-in-One) appliance requires external QRadar QFlow Collectors for layer 7 network activity monitoring. With an upgraded licence the QRadar Flow Processor 1705 supports 600,000 FPM, depending on traffic types. Note: The IBM Security QRadar 3105 (All-in-One) (MTM 4380-Q1E) appliance is an all-in-one QRadar system that can profile network behavior and identify network security threats.With a basic license it supports 25,000 FPM and 1000 EPS. With an upgraded license it supports 200,000 FPM and 5000 EPS. Incorrect Answers:A: With an upgraded licence the QRadar 1805supports 200,000 FPM and 5,000 EPS.C: With an upgraded licence the QRadar Flow Processor 1828 supports 300,000 FPM.D: QRadar Event Processor 1605 is not a Flow Collector.References: http://www.ibm.com/support/knowledgecenter/SS42VS_7.2.8/com.ibm.qradar.doc/c_hwg_3105_allone_base.htmlhttp://www.ibm.com/support/knowledgecenter/SS42VS_7.2.6/com.ibm.qradar.doc/c_hwg_flow_prcssr1705.html
The QRadar 3105 (All-in-One) appliance requires external QRadar QFlow Collectors for layer 7 network activity monitoring.
With an upgraded licence the QRadar Flow Processor 1705 supports 600,000 FPM, depending on traffic types.
Note: The IBM Security QRadar 3105 (All-in-One) (MTM 4380-Q1E) appliance is an all-in-one QRadar system that can profile network behavior and identify network security threats.
With a basic license it supports 25,000 FPM and 1000 EPS.
With an upgraded license it supports 200,000 FPM and 5000 EPS.
Incorrect Answers:
A: With an upgraded licence the QRadar 1805supports 200,000 FPM and 5,000 EPS.
C: With an upgraded licence the QRadar Flow Processor 1828 supports 300,000 FPM.
D: QRadar Event Processor 1605 is not a Flow Collector.
References:
http://www.ibm.com/support/knowledgecenter/SS42VS_7.2.8/com.ibm.qradar.doc/c_hwg_3105_allone_base.html
http://www.ibm.com/support/knowledgecenter/SS42VS_7.2.6/com.ibm.qradar.doc/c_hwg_flow_prcssr1705.html