Splunk Enterprise Security Certified Admin - SPLK-3001 Exam Practice Test
Which of the following is part of tuning correlation searches for a new ES installation?
Correct Answer: B
Vote an answer
Which of the following is a risk of using the Auto Deployment feature of Distributed Configuration Management to distribute indexes.conf?
Correct Answer: C
Vote an answer
Explanation: Only visible for Fast2test members. You can sign-up / login (it's free).
Which feature contains scenarios that are useful during ES implementation?
Correct Answer: C
Vote an answer
Explanation: Only visible for Fast2test members. You can sign-up / login (it's free).
Which of the following are the default ports that must be configured for Splunk Enterprise Security to function?
Correct Answer: B
Vote an answer
Explanation: Only visible for Fast2test members. You can sign-up / login (it's free).
A newly built custom dashboard needs to be available to a team of security analysts in ES.
How is it possible to integrate the new dashboard?
How is it possible to integrate the new dashboard?
Correct Answer: D
Vote an answer
Which indexes are searched by default for CIM data models?
Correct Answer: C
Vote an answer
Explanation: Only visible for Fast2test members. You can sign-up / login (it's free).
Which of the following is an adaptive action that is configured by default for ES?
Correct Answer: C
Vote an answer
Explanation: Only visible for Fast2test members. You can sign-up / login (it's free).
Both 'Recommended Actions' and 'Adaptive Response Actions' use adaptive response. How do they differ?
Correct Answer: C
Vote an answer
Explanation: Only visible for Fast2test members. You can sign-up / login (it's free).
An administrator is asked to configure an 'Nslookup' adaptive response action, so that it appears as a selectable option in the notable event's action menu when an analyst is working in the Incident Review dashboard.
What steps would the administrator take to configure this option?
What steps would the administrator take to configure this option?
Correct Answer: B
Vote an answer