ExamHelpDesk

Complete list of current Q & A>>

Splunk Enterprise Security Certified Admin (SPLK-3001) – Quiz

1 / 15

Category: Splunk Enterprise Security Certified Admin (SPLK-3001)

1. How is it possible to navigate to the list of currently-enabled ES correlation searches?

2 / 15

Category: Splunk Enterprise Security Certified Admin (SPLK-3001)

2. When investigating, what is the best way to store a newly-found IOC?

3 / 15

Category: Splunk Enterprise Security Certified Admin (SPLK-3001)

3. Which argument to the | tstats command restricts the search to summarized data only?

4 / 15

Category: Splunk Enterprise Security Certified Admin (SPLK-3001)

4. Which of the following is a way to test for a property normalized data model?

5 / 15

Category: Splunk Enterprise Security Certified Admin (SPLK-3001)

5. Which setting is used in indexes.conf to specify alternate locations for accelerated storage?

6 / 15

Category: Splunk Enterprise Security Certified Admin (SPLK-3001)

6. Which indexes are searched by default for CIM data models?

7 / 15

Category: Splunk Enterprise Security Certified Admin (SPLK-3001)

7. What does the risk framework add to an object (user, server or other type) to indicate increased risk?

8 / 15

Category: Splunk Enterprise Security Certified Admin (SPLK-3001)

8. Which column in the Asset or Identity list is combined with event security to make a notable event’s urgency?

9 / 15

Category: Splunk Enterprise Security Certified Admin (SPLK-3001)

9. What role should be assigned to a security team member who will be taking ownership of notable events in the incident review dashboard?

10 / 15

Category: Splunk Enterprise Security Certified Admin (SPLK-3001)

10. In order to include an eventtype in a data model node, what is the next step after extracting the correct fields?

11 / 15

Category: Splunk Enterprise Security Certified Admin (SPLK-3001)

11. The Remote Access panel within the User Activity dashboard is not populating with the most recent hour of data.
What data model should be checked for potential errors such as skipped searches?

12 / 15

Category: Splunk Enterprise Security Certified Admin (SPLK-3001)

12. The Add-On Builder creates Splunk Apps that start with what?

13 / 15

Category: Splunk Enterprise Security Certified Admin (SPLK-3001)

13. Which of the following are examples of sources for events in the endpoint security domain dashboards?

14 / 15

Category: Splunk Enterprise Security Certified Admin (SPLK-3001)

14. When creating custom correlation searches, what format is used to embed field values in the title, description, and drill-down fields of a notable event?

15 / 15

Category: Splunk Enterprise Security Certified Admin (SPLK-3001)

15. What feature of Enterprise Security downloads threat intelligence data from a web server?

Your score is

0%

Scroll to Top