SPLK-3001 Exam Questions
100 real SPLK-3001 exam questions with expert-verified answers and explanations. Page 1 of 2.
- Question #1Lookups and Identity Management
How should an administrator add a new lookup through the ES app?
lookup managementcontent managementES configurationUI navigation - Question #2Forensics, Glass Tables, and Navigation Control
Glass tables can display static images and text, the results of ad-hoc searches, and which of the following objects?
glass tablessecurity metricsdashboardsdisplay objects - Question #3Forensics, Glass Tables, and Navigation Control
Which of the following is a key feature of a glass table?
glass tablescustomizationfeatures - Question #4Risk Analysis and Adaptive Response
An administrator is asked to configure an 'Nslookup' adaptive response action, so that it appears as a selectable option in the notable event's action menu when an analyst is worki...
adaptive responserecommended actionsnotable eventsincident review - Question #5Investigations and Incident Review
What are the steps to add a new column to the Notable Event table in the Incident Review dashboard?
incident reviewnotable eventstable attributesUI configuration - Question #6Monitoring and Investigation
To observe what network services are in use in a network's activity overall, which of the following dashboards in Enterprise Security will contain the most relevant data?
protocol analysisnetwork monitoringdashboardsnetwork services - Question #7Risk Analysis and Adaptive Response
Adaptive response action history is stored in which index?
adaptive responsemodular actionsindex storagecim_modactions - Question #8Tuning Correlation Searches
Which of the following actions would not reduce the number of false positives from a correlation search?
false positivesthrottlingcorrelation search tuningseverity - Question #9Custom Add-ons
Where is the Add-On Builder available from?
Add-On BuilderSplunkBasetool availability - Question #10Custom Add-ons
Which of the following would allow an add-on to be automatically imported into Splunk Enterprise Security?
add-on naming conventionSplunk_TA_ prefixauto-importES integration - Question #11ES Deployment
ES apps and add-ons from $SPLUNK_HOME/etc/apps should be copied from the staging instance to what location on the cluster deployer instance?
search head clusteringdeployerapp deploymentshcluster - Question #12Correlation Searches and Notable Events
How is notable event urgency calculated?
notable event urgencyseverityasset priorityidentity priority - Question #13Risk Analysis and Adaptive Response
What kind of value is in the red box in this picture?
risk scorerisk analysisUI elements - Question #14Content Management and Customizations
Where is it possible to export content, such as correlation searches, from ES?
content managementcontent exportcorrelation searchesES navigation - Question #15Threat Intelligence Framework
Which of the following threat intelligence types can ES download? (Choose all that apply.)
threat intelligenceSTIX/TAXIIintelligence downloadsthreat feeds - Question #16ES Deployment
A site has a single existing search head which hosts a mix of both CIM and non-CIM compliant applications. All of the applications are mission-critical. The customer wants to caref...
ES deploymentsearch head isolationbest practicesCIM compliance - Question #17ES Introduction
Enterprise Security's dashboards primarily pull data from what type of knowledge object?
data modelsdashboardsknowledge objectsES architecture - Question #18Installation and Configuration
To which of the following should the ES application be uploaded?
ES installationsearch headdeployment target - Question #19Lookups and Identity Management
If a username does not match the 'identity' column in the identities list, which column is checked next?
identity managementidentity lookupusername matchingemail fallback - Question #20Custom Add-ons
Which of the following features can the Add-on Builder configure in a new add-on?
Add-On Builderdata normalizationCIMadd-on features - Question #21ES Deployment
What is the maximum recommended volume of indexing per day, per indexer, for a non-cloud (on-prem) ES deployment?
indexing volumecapacity planningon-prem deploymentindexer sizing - Question #22Installation and Configuration
ES needs to be installed on a search head with which of the following options?
search headapp compatibilityCIM complianceinstallation requirements - Question #23Correlation Searches and Notable Events
Which settings indicates that the correlation search will be executed as new events are indexed?
correlation search schedulingreal-time searchsearch execution modes - Question #24Investigations and Incident Review
Where are attachments to investigations stored?
investigationsKV Storeattachmentsdata storage - Question #25Risk Analysis and Adaptive Response
Which data model populates the panels on the Risk Analysis dashboard?
Risk Analysis dashboarddata modelsrisk scoring - Question #26Forensics, Glass Tables, and Navigation Control
How is it possible to navigate to the ES graphical Navigation Bar editor?
navigation barES configurationUI customization - Question #27ES Deployment
An administrator is provisioning one search head prior to installing ES. What are the reference minimum requirements for OS, CPU, and RAM for that machine?
hardware requirementssearch headCPURAM - Question #28Risk Analysis and Adaptive Response
What tools does the Risk Analysis dashboard provide?
Risk Analysis dashboardassetsidentitiesrisk scoring - Question #29Content Management and Customizations
When ES content is exported, an app with a .spl extension is automatically created. What is the best practice when exporting and importing updates to ES content?
content exportapp packagingbest practicescontent management - Question #30Investigations and Incident Review
Who can delete an investigation?
investigationsaccess controless_adminpermissions - Question #31Installation and Configuration
After installing Enterprise Security, the distributed configuration management tool can be used to create which app to configure indexers?
distributed configuration managementindexer configurationadd-onspost-install - Question #32Tuning Correlation Searches
The Brute Force Access Behavior Detected correlation search is enabled, and is generating many false positives. Assuming the input data has already been validated. How can the corr...
false positivesthreshold tuningbrute force detectioncorrelation search editing - Question #33Troubleshooting and Optimization
Which of the following actions can improve overall search performance?
search performancescheduling optimizationcorrelation search tuning - Question #34Monitoring and Investigation
Which of the following ES features would a security analyst use while investigating a network anomaly notable?
network anomaly investigationprotocol intelligencesecurity analyst workflow - Question #35Data Inputs and Collection
Which component normalizes events?
event normalizationtechnology add-onCIMdata inputs - Question #36Validating ES Data
An administrator wants to ensure that none of the ES indexed data could be compromised through tampering. What feature would satisfy this requirement?
data integrityindex tamperingdata integrity controlsecurity hardening - Question #37ES Deployment
What is the first step when preparing to install ES?
installation planningdeployment scopepre-install steps - Question #38Installation and Configuration
What is the default schedule for accelerating ES Datamodels?
data model accelerationschedulingES configuration - Question #39ES Deployment
Accelerated data requires approximately how many times the daily data volume of additional storage space per year?
storage planningdata model accelerationcapacity planning - Question #40Installation and Configuration
When installing Enterprise Security, what should be done after installing the add-ons necessary for normalizing data?
add-on configurationpost-install stepstechnology add-onsdocumentation - Question #41Content Management and Customizations
What can be exported from ES using the Content Management page?
content managementexportES content types - Question #42Installation and Configuration
Where should an ES search head be installed?
ES installationsearch headSplunk server - Question #43Investigations and Incident Review
Following the installation of ES, an admin configured users with the ess_user role the ability to close notable events. How would the admin restrict these users from being able to...
notable eventsstatus configurationrole permissionsess_user - Question #44Installation and Configuration
Which of the following actions may be necessary before installing ES?
ES pre-installationindexerscapacity planning - Question #45Troubleshooting and Optimization
A customer site is experiencing poor performance. The UI response time is high and searches take a very long time to run. Some operations time out and there are errors in the sched...
performance tuningsearch headcorrelation searchesconcurrent searches - Question #46Splunk ES Basics and Environment
What is the bar across the bottom of any ES window?
ES UIInvestigation Barnavigation - Question #47Correlation Searches and Notable Events
Which two fields combine to create the Urgency of a notable event?
urgencypriorityseveritynotable events - Question #48Threat Intelligence Framework
What do threat gen searches produce?
threat gen searchesthreat activity indexthreat intelligence - Question #49Tuning Correlation Searches
Which of the following is part of tuning correlation searches for a new ES installation?
correlation search tuningadaptive responsesnew installation - Question #50Lookups and Identity Management
Which columns in the Assets lookup are used to identify an asset in an event?
assets lookupasset identificationipmac