SPLK-3001 · Question #4
An administrator is asked to configure an 'Nslookup' adaptive response action, so that it appears as a selectable option in the notable event's action menu when an analyst is working in the Incident…
The correct answer is D. Configure -> Content Management -> Type: Correlation Search -> Notable -> Recommended. Option D is correct because the proper navigation path in Splunk Enterprise Security to expose an adaptive response action like Nslookup in the Incident Review dashboard is: Configure > Content Management > filter by Type: Correlation Search > edit the search > Notable >…
Question
An administrator is asked to configure an 'Nslookup' adaptive response action, so that it appears as a selectable option in the notable event's action menu when an analyst is working in the Incident Review dashboard. What steps would the administrator take to configure this option?
Options
- AConfigure -> Content Management -> Type: Correlation Search -> Notable -> Nslookup
- BConfigure -> Type: Correlation Search -> Notable -> Recommended Actions -> Nslookup
- CConfigure -> Content Management -> Type: Correlation Search -> Notable -> Next Steps ->
- DConfigure -> Content Management -> Type: Correlation Search -> Notable -> Recommended
How the community answered
(51 responses)- A8% (4)
- B6% (3)
- C2% (1)
- D84% (43)
Explanation
Option D is correct because the proper navigation path in Splunk Enterprise Security to expose an adaptive response action like Nslookup in the Incident Review dashboard is: Configure > Content Management > filter by Type: Correlation Search > edit the search > Notable > Recommended Actions - this is where you specify which actions analysts can select from the notable event's action menu.
Option A is wrong because it navigates directly to "Nslookup" rather than the "Recommended Actions" field, which is an incomplete and invalid path. Option B is wrong because it omits the critical Content Management step - skipping it means you cannot reach the correlation search configuration. Option C is wrong because "Next Steps" is not the actual field name in Splunk ES; the correct label is "Recommended Actions," making this a plausible but incorrect distractor.
Memory tip: Think "Content Management holds the Content, Recommended Actions hold the Recommendations" - you manage your correlation searches under Content Management, and you recommend analyst actions under Recommended Actions. The word "Recommended" in the answer matches what analysts see as "recommended" options in their workflow.
Topics
Community Discussion
No community discussion yet for this question.