IBM P2150-870 Exam Overview:
| Certification Vendor: | IBM |
|---|---|
| Exam Name: | Technical Sales Foundations for IBM Security Intelligence and Analytics V1 |
| Exam Number: | P2150-870 |
| Real Exam Qty: | 40 - 60 |
| Passing Score: | 62% - 70% |
| Exam Duration: | 90 minutes |
| Available Languages: | English, German, Japanese |
| Related Certifications: | IBM Security Intelligence and Analytics Sales Mastery |
| Exam Price: | $100 - $200 USD |
| Certificate Validity Period: | 2 Years |
| Exam Format: | Scenario-Based, Multiple Choice |
| Recommended Training: | IBM Security Intelligence and Analytics Learning Path IBM Security Sales Foundation Training |
| Exam Registration: | Pearson VUE Registration IBM Certification Portal |
| Sample Questions: | IBM P2150-870 Sample Questions |
| Exam Way: | Online proctored or in-person at authorized Pearson VUE test centers |
| Pre Condition: | No formal prerequisites; recommended basic knowledge of IBM Security solutions and technical sales experience |
| Official Syllabus URL: | https://www.ibm.com/certify/exams/P2150-870 |
IBM P2150-870 Exam Syllabus Topics:
| Section | Weight | Objectives |
|---|---|---|
| Topic 1: IBM QRadar SIEM | 25% | - QRadar architecture and components - Correlation rules and offense management - Event and flow data collection |
| Topic 2: IBM Security Data Protection & Governance | 20% | - Data privacy and compliance use cases - IBM Guardium database security |
| Topic 3: Application & Access Security | 15% | - IBM AppScan application security - Identity and access management basics |
| Topic 4: IBM Security Intelligence and Analytics Overview | 20% | - Customer security challenges and requirements - Solution positioning and value proposition - Security intelligence and analytics concepts |
| Topic 5: Endpoint & Network Security | 20% | - IBM BigFix endpoint management - Threat intelligence and incident response |
IBM Technical Sales Foundations for IBM Security Intelligence and Analytics V1 Sample Questions:
Which is a valid use case for implementing QRadar reference data collections?
- A. Speed up dashboard functions due to caching common widget data sets
- B. Provide an index for all data (events and flow data) in real time.
- C. Store hash values and test each incoming hash against this set
- D. Change all incoming events to add an additional field value.
Correct Answer: C 🗳️
Which case shows how approximately 1000 Events per second, using an encrypted channel, can be sent from a private cloud to a QRader processor?
- A. Place an event processor in the private cloud, and forward the events to another event collector.
- B. Place an event collector in the private cloud, and forward the event to the customers event processor.
- C. Place a packet capture appliance in the private cloud, and forward the events to a cloud events processor.
- D. Place a risk manager appliance in the private cloud, and forward the events to another event collector.
Correct Answer: A 🗳️
What do prospects typically care about for high level cyber use cases?
- A. 1. Having a proper time management system
2. Evacuation rule compliance
3. Making the sales target for the week
4. Speed of deployment and Time to value - B. 1. Having a good password change policy
2. Erasing documents which describe a recent data breach
3. keeping up to date with Windows patch updates
4. cleaning the BGP routing tables regularly - C. 1. Advanced Threats
2. Insider Threats
3. Securing the cloud
4. Critical Data Protection - D. 1. Best price for performance
2. Outside Threats
3. Patching ALL vulnerabilities found as soon as they are reported
4. Running a clean data center
Correct Answer: A 🗳️
Which is the most common formatused to send event data to a SIEM?
- A. NetFlow
- B. Syslog
- C. LEEF
- D. JSON
Correct Answer: A 🗳️

We're so confident of our products that we provide no hassle product exchange.


By Rupert


