SPLK-3001 Exam Questions
100 real SPLK-3001 exam questions with expert-verified answers and explanations. Page 2 of 2.
- Question #51Tuning Correlation Searches
What does the summariesonly=true option do for a correlation search?
summariesonlyaccelerated datadata modelscorrelation search - Question #52Installation and Configuration
Which of the following are the default ports that must be configured for Splunk Enterprise Security to function?
default portsSplunkWebKV StoreSplunk management - Question #53Validating ES Data
What is the main purpose of the Dashboard Requirements Matrix document?
Dashboard Requirements Matrixdata modelsdashboards - Question #54Installation and Configuration
Which of the following is a recommended pre-installation step?
pre-installationsearch head forwardingES setup - Question #55Risk Analysis and Adaptive Response
What are adaptive responses triggered by?
adaptive responsescorrelation searchesincident review - Question #56Risk Analysis and Adaptive Response
Which of the following is an adaptive action that is configured by default for ES?
adaptive actionscreate notable eventdefault configuration - Question #57Security Intelligence
Analysts have requested the ability to capture and analyze network traffic data. The administrator has researched the documentation and, based on this research, has decided to inte...
Splunk App for StreamProtocol Intelligencenetwork trafficdashboards - Question #58Creating Correlation Searches
When creating custom correlation searches, what format is used to embed field values in the title, description, and drill-down fields of a notable event?
correlation search creationnotable event fieldsfield embeddingtoken syntax - Question #59Lookups and Identity Management
Which lookup table does the Default Account Activity Detected correlation search use to flag known default accounts?
default account activitylookup tableadministrative identitiescorrelation search - Question #60ES Deployment
Which tool is used to update indexers in ES?
indexer updatesdistributed configurationSplunk_TA_ForIndexers - Question #61Installation and Configuration
How is it possible to specify an alternate location for accelerated storage?
tstatsHomePathindexes.confaccelerated storagetsidx data - Question #62Custom Add-ons
After managing source types and extracting fields, which key step comes next in the Add-On Builder?
Add-On Builderdata model mappingCIMfield extraction - Question #63Lookups and Identity Management
How does ES know local customer domain names so it can detect internal vs. external emails?
corporate domain lookupemail domainidentity configurationinitial setup - Question #64ES Introduction
Which of these is a benefit of data normalization?
data normalizationCIMCommon Information Modeltechnology independence - Question #65Security Intelligence
A security manager has been working with the executive team on long-range security goals. A primary goal for the team is to improve managing user risk in the organization. Which of...
watchlistsUser Activity dashboardweb monitoringuser risk - Question #66Security Intelligence
Which of the following is a Web Intelligence dashboard?
Web IntelligenceHTTP Category Analysisdashboardweb monitoring - Question #67Validating ES Data
After data is ingested, which data management step is essential to ensure raw data can be accelerated by a Data Model and used by ES?
CIM normalizationdata model accelerationdata managementCommon Information Model - Question #68Installation and Configuration
Which of the following are the default ports that must be configured for Splunk Enterprise Security to function?
default portsSplunkWebKV Storemanagement port - Question #69Lookups and Identity Management
What is an example of an ES asset?
assetsasset listidentity managementES concepts - Question #70Custom Add-ons
The Add-On Builder creates Splunk Apps that start with what?
Add-On BuilderTA prefixnaming conventionSplunk apps - Question #71Monitoring and Investigation
Which of the following are examples of sources for events in the endpoint security domain dashboards?
endpoint securitydata sourcesworkstationsendpoint monitoring - Question #72Creating Correlation Searches
When creating custom correlation searches, what format is used to embed field values in the title, description, and drill-down fields of a notable event?
notable eventsfield token syntaxcorrelation search$fieldname$ - Question #73Threat Intelligence Framework
What feature of Enterprise Security downloads threat intelligence data from a web server?
Threat Download Managerthreat intelligencethreat feedsdata collection - Question #74Troubleshooting and Optimization
The Remote Access panel within the User Activity dashboard is not populating with the most recent hour of data. What data model should be checked for potential errors such as skipp...
Authentication data modelRemote Access panelUser Activity dashboardtroubleshooting - Question #75Validating ES Data
In order to include an eventtype in a data model node, what is the next step after extracting the correct fields?
event typestagsdata modelCIM workflow - Question #76Investigations and Incident Review
What role should be assigned to a security team member who will be taking ownership of notable events in the incident review dashboard?
ess_analystES rolesincident reviewnotable events - Question #77Lookups and Identity Management
Which column in the Asset or Identity list is combined with event security to make a notable event's urgency?
urgencypriorityasset lookupnotable event severity - Question #78Risk Analysis and Adaptive Response
What does the risk framework add to an object (user, server or other type) to indicate increased risk?
risk frameworkrisk scorerisk objectadaptive response - Question #79Validating ES Data
Which indexes are searched by default for CIM data models?
CIM data modelsindex searchdefault configurationdata model acceleration - Question #80Installation and Configuration
Which setting is used in indexes.conf to specify alternate locations for accelerated storage?
tstatsHomePathindexes.confaccelerated storageconfiguration - Question #81Validating ES Data
Which of the following is a way to test for a property normalized data model?
CIM normalizationdata modelsdatamodel commandfield validation - Question #82Monitoring and Investigation
Which argument to the | tstats command restricts the search to summarized data only?
tstats commandsummarized datadata model accelerationsearch optimization - Question #83Investigations and Incident Review
When investigating, what is the best way to store a newly-found IOC?
IOC managementinvestigation artifactsincident responsethreat indicators - Question #84Custom Add-ons
What should be used to map a non-standard field name to a CIM field name?
CIM field mappingfield aliasdata normalizationadd-on configuration - Question #85Threat Intelligence Framework
Which of the following lookup types in Enterprise Security contains information about known hostile IP addresses?
threat intelligencehostile IPlookup typesthreat intel framework - Question #86Tuning Correlation Searches
A set of correlation searches are enabled at a new ES installation, and results are being monitored. One of the correlation searches is generating many notable events which, when e...
false positivescorrelation search tuningnotable event suppressionsensitivity tuning - Question #87Content Management and Customizations
Which of the following steps will make the Threat Activity dashboard the default landing page in ES?
navigation editordefault landing pageES UI customizationdashboard configuration - Question #88ES Deployment
When using distributed configuration management to create the Splunk_TA_ForIndexers package, which three files can be included?
distributed configuration managementSplunk_TA_ForIndexersindexes.confconfiguration files - Question #89ES Introduction
Which feature contains scenarios that are useful during ES implementation?
Use Case LibraryES implementationsecurity scenarioscontent library - Question #90Lookups and Identity Management
Where is detailed information about identities stored?
identity managementidentity lookupCSV lookupidentity data storage - Question #91Investigations and Incident Review
The option to create a Short ID for a notable event is located where?
notable eventsShort IDevent detailsincident review - Question #92Content Management and Customizations
A newly built custom dashboard needs to be available to a team of security analysts in ES. How is it possible to integrate the new dashboard?
custom dashboardnavigation editores_analyst roledashboard permissions - Question #93Correlation Searches and Notable Events
How is it possible to navigate to the list of currently-enabled ES correlation searches?
correlation searchesContent Managementenabled searchesES navigation - Question #94ES Deployment
Which of the following is a risk of using the Auto Deployment feature of Distributed Configuration Management to distribute indexes.conf?
distributed configuration managementAuto Deploymentindexes.confindexer configuration - Question #95Validating ES Data
Which of the following are data models used by ES? (Choose all that apply.)
CIM data modelsWebAuthenticationNetwork Traffic - Question #96Installation and Configuration
At what point in the ES installation process should Splunk_TA_ForIndexers.spl be deployed to the indexers?
ES installationSplunk_TA_ForIndexersdeployment sequencedistributed configuration management - Question #97Tuning Correlation Searches
Which correlation search feature is used to throttle the creation of notable events?
notable event throttlingwindow durationcorrelation search featuresevent suppression - Question #98Risk Analysis and Adaptive Response
Both 'Recommended Actions' and 'Adaptive Response Actions' use adaptive response. How do they differ?
adaptive responserecommended actionsanalyst workflownotable event response - Question #99Monitoring and Investigation
What does the Security Posture dashboard display?
Security Posture dashboardnotable events overviewES dashboardsSOC monitoring - Question #100Lookups and Identity Management
'10.22.63.159', 'websvr4', and '00:26:08:18: CF:1D' would be matched against what in ES?
asset managementIP addresshostnameMAC address