SPLK-3001 Exam Questions
100 real SPLK-3001 exam questions with expert-verified answers and explanations. Page 2 of 2.
- Question #51
What does the summariesonly=true option do for a correlation search?
- Question #52
Which of the following are the default ports that must be configured for Splunk Enterprise Security to function?
- Question #53
What is the main purpose of the Dashboard Requirements Matrix document?
- Question #54
Which of the following is a recommended pre-installation step?
- Question #55
What are adaptive responses triggered by?
- Question #56
Which of the following is an adaptive action that is configured by default for ES?
- Question #57
Analysts have requested the ability to capture and analyze network traffic data. The administrator has researched the documentation and, based on this research, has decided to inte...
- Question #58
When creating custom correlation searches, what format is used to embed field values in the title, description, and drill-down fields of a notable event?
- Question #59
Which lookup table does the Default Account Activity Detected correlation search use to flag known default accounts?
- Question #60
Which tool is used to update indexers in ES?
- Question #61
How is it possible to specify an alternate location for accelerated storage?
- Question #62
After managing source types and extracting fields, which key step comes next in the Add-On Builder?
- Question #63
How does ES know local customer domain names so it can detect internal vs. external emails?
- Question #64
Which of these is a benefit of data normalization?
- Question #65
A security manager has been working with the executive team on long-range security goals. A primary goal for the team is to improve managing user risk in the organization. Which of...
- Question #66
Which of the following is a Web Intelligence dashboard?
- Question #67
After data is ingested, which data management step is essential to ensure raw data can be accelerated by a Data Model and used by ES?
- Question #68
Which of the following are the default ports that must be configured for Splunk Enterprise Security to function?
- Question #69
What is an example of an ES asset?
- Question #70
The Add-On Builder creates Splunk Apps that start with what?
- Question #71
Which of the following are examples of sources for events in the endpoint security domain dashboards?
- Question #72
When creating custom correlation searches, what format is used to embed field values in the title, description, and drill-down fields of a notable event?
- Question #73
What feature of Enterprise Security downloads threat intelligence data from a web server?
- Question #74
The Remote Access panel within the User Activity dashboard is not populating with the most recent hour of data. What data model should be checked for potential errors such as skipp...
- Question #75
In order to include an eventtype in a data model node, what is the next step after extracting the correct fields?
- Question #76
What role should be assigned to a security team member who will be taking ownership of notable events in the incident review dashboard?
- Question #77
Which column in the Asset or Identity list is combined with event security to make a notable event's urgency?
- Question #78
What does the risk framework add to an object (user, server or other type) to indicate increased risk?
- Question #79
Which indexes are searched by default for CIM data models?
- Question #80
Which setting is used in indexes.conf to specify alternate locations for accelerated storage?
- Question #81
Which of the following is a way to test for a property normalized data model?
- Question #82
Which argument to the | tstats command restricts the search to summarized data only?
- Question #83
When investigating, what is the best way to store a newly-found IOC?
- Question #84
What should be used to map a non-standard field name to a CIM field name?
- Question #85
Which of the following lookup types in Enterprise Security contains information about known hostile IP addresses?
- Question #86
A set of correlation searches are enabled at a new ES installation, and results are being monitored. One of the correlation searches is generating many notable events which, when e...
- Question #87
Which of the following steps will make the Threat Activity dashboard the default landing page in ES?
- Question #88
When using distributed configuration management to create the Splunk_TA_ForIndexers package, which three files can be included?
- Question #89
Which feature contains scenarios that are useful during ES implementation?
- Question #90
Where is detailed information about identities stored?
- Question #91
The option to create a Short ID for a notable event is located where?
- Question #92
A newly built custom dashboard needs to be available to a team of security analysts in ES. How is it possible to integrate the new dashboard?
- Question #93
How is it possible to navigate to the list of currently-enabled ES correlation searches?
- Question #94
Which of the following is a risk of using the Auto Deployment feature of Distributed Configuration Management to distribute indexes.conf?
- Question #95
Which of the following are data models used by ES? (Choose all that apply.)
- Question #96
At what point in the ES installation process should Splunk_TA_ForIndexers.spl be deployed to the indexers?
- Question #97
Which correlation search feature is used to throttle the creation of notable events?
- Question #98
Both 'Recommended Actions' and 'Adaptive Response Actions' use adaptive response. How do they differ?
- Question #99
What does the Security Posture dashboard display?
- Question #100
'10.22.63.159', 'websvr4', and '00:26:08:18: CF:1D' would be matched against what in ES?