nerdexam
Splunk

SPLK-3001 · Question #4

An administrator is asked to configure an 'Nslookup' adaptive response action, so that it appears as a selectable option in the notable event's action menu when an analyst is working in the Incident…

The correct answer is D. Configure -> Content Management -> Type: Correlation Search -> Notable -> Recommended. Option D is correct because the proper navigation path in Splunk Enterprise Security to expose an adaptive response action like Nslookup in the Incident Review dashboard is: Configure > Content Management > filter by Type: Correlation Search > edit the search > Notable >…

Risk Analysis and Adaptive Response

Question

An administrator is asked to configure an 'Nslookup' adaptive response action, so that it appears as a selectable option in the notable event's action menu when an analyst is working in the Incident Review dashboard. What steps would the administrator take to configure this option?

Options

  • AConfigure -> Content Management -> Type: Correlation Search -> Notable -> Nslookup
  • BConfigure -> Type: Correlation Search -> Notable -> Recommended Actions -> Nslookup
  • CConfigure -> Content Management -> Type: Correlation Search -> Notable -> Next Steps ->
  • DConfigure -> Content Management -> Type: Correlation Search -> Notable -> Recommended

How the community answered

(51 responses)
  • A
    8% (4)
  • B
    6% (3)
  • C
    2% (1)
  • D
    84% (43)

Explanation

Option D is correct because the proper navigation path in Splunk Enterprise Security to expose an adaptive response action like Nslookup in the Incident Review dashboard is: Configure > Content Management > filter by Type: Correlation Search > edit the search > Notable > Recommended Actions - this is where you specify which actions analysts can select from the notable event's action menu.

Option A is wrong because it navigates directly to "Nslookup" rather than the "Recommended Actions" field, which is an incomplete and invalid path. Option B is wrong because it omits the critical Content Management step - skipping it means you cannot reach the correlation search configuration. Option C is wrong because "Next Steps" is not the actual field name in Splunk ES; the correct label is "Recommended Actions," making this a plausible but incorrect distractor.

Memory tip: Think "Content Management holds the Content, Recommended Actions hold the Recommendations" - you manage your correlation searches under Content Management, and you recommend analyst actions under Recommended Actions. The word "Recommended" in the answer matches what analysts see as "recommended" options in their workflow.

Topics

#adaptive response#recommended actions#notable events#incident review

Community Discussion

No community discussion yet for this question.

Full SPLK-3001 Practice