New Year Sale Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: pass65

SPLK-3001 Splunk Enterprise Security Certified Admin Exam Questions and Answers

Questions 4

Which of the following is a recommended pre-installation step?

Options:

A.

Disable the default search app.

B.

Configure search head forwarding.

C.

Download the latest version of KV Store from MongoDBxom.

D.

Install the latest Python distribution on the search head.

Buy Now
Questions 5

Following the installation of ES, an admin configured users with the ess_user role the ability to close notable events.

How would the admin restrict these users from being able to change the status of Resolved notable events to Closed?

Options:

A.

In Enterprise Security, give the ess_user role the Own Notable Events permission.

B.

From the Status Configuration window select the Closed status. Remove ess_user from the status

transitions for the Resolved status.

C.

From the Status Configuration window select the Resolved status. Remove ess_user from the status transitions for the Closed status.

D.

From Splunk Access Controls, select the ess_user role and remove the edit_notable_events capability.

Buy Now
Questions 6

After data is ingested, which data management step is essential to ensure raw data can be accelerated by a Data Model and used by ES?

Options:

A.

Applying Tags.

B.

Normalization to Customer Standard.

C.

Normalization to the Splunk Common Information Model.

D.

Extracting Fields.

Buy Now
Questions 7

When creating custom correlation searches, what format is used to embed field values in the title, description, and drill-down fields of a notable event?

Options:

A.

$fieldname$

B.

“fieldname”

C.

%fieldname%

D.

_fieldname_

Buy Now
Questions 8

Which setting is used in indexes.conf to specify alternate locations for accelerated storage?

Options:

A.

thawedPath

B.

tstatsHomePath

C.

summaryHomePath

D.

warmToColdScript

Buy Now
Questions 9

Both “Recommended Actions” and “Adaptive Response Actions” use adaptive response. How do they differ?

Options:

A.

Recommended Actions show a textual description to an analyst, Adaptive Response Actions show them encoded.

B.

Recommended Actions show a list of Adaptive Responses to an analyst, Adaptive Response Actions run them automatically.

C.

Recommended Actions show a list of Adaptive Responses that have already been run, Adaptive Response Actions run them automatically.

D.

Recommended Actions show a list of Adaptive Responses to an analyst, Adaptive Response Actions run manually with analyst intervention.

Buy Now
Questions 10

A customer site is experiencing poor performance. The UI response time is high and searches take a very long time to run. Some operations time out and there are errors in the scheduler logs, indicating too many concurrent searches are being started. 6 total correlation searches are scheduled and they have already been tuned to weed out false positives.

Which of the following options is most likely to help performance?

Options:

A.

Change the search heads to do local indexing of summary searches.

B.

Add heavy forwarders between the universal forwarders and indexers so inputs can be parsed before indexing.

C.

Increase memory and CPUs on the search head(s) and add additional indexers.

D.

If indexed realtime search is enabled, disable it for the notable index.

Buy Now
Questions 11

Which of the following features can the Add-on Builder configure in a new add-on?

Options:

A.

Expire data.

B.

Normalize data.

C.

Summarize data.

D.

Translate data.

Buy Now
Questions 12

ES apps and add-ons from $SPLUNK_HOME/etc/apps should be copied from the staging instance to what location on the cluster deployer instance?

Options:

A.

$SPLUNK_HOME/etc/master-apps/

B.

$SPLUNK_HOME/etc/system/local/

C.

$SPLUNK_HOME/etc/shcluster/apps

D.

$SPLUNK_HOME/var/run/searchpeers/

Buy Now
Questions 13

Which of the following actions can improve overall search performance?

Options:

A.

Disable indexed real-time search.

B.

Increase priority of all correlation searches.

C.

Reduce the frequency (schedule) of lower-priority correlation searches.

D.

Add notable event suppressions for correlation searches with high numbers of false positives.

Buy Now
Questions 14

Which argument to the | tstats command restricts the search to summarized data only?

Options:

A.

summaries=t

B.

summaries=all

C.

summariesonly=t

D.

summariesonly=all

Buy Now
Questions 15

Where is it possible to export content, such as correlation searches, from ES?

Options:

A.

Content exporter

B.

Configure -> Content Management

C.

Export content dashboard

D.

Settings Menu -> ES -> Export

Buy Now
Questions 16

Which of the following actions may be necessary before installing ES?

Options:

A.

Redirect distributed search connections.

B.

Purge KV Store.

C.

Add additional indexers.

D.

Add additional forwarders.

Buy Now
Questions 17

Enterprise Security’s dashboards primarily pull data from what type of knowledge object?

Options:

A.

Tstats

B.

KV Store

C.

Data models

D.

Dynamic lookups

Buy Now
Questions 18

Where are attachments to investigations stored?

Options:

A.

KV Store

B.

notable index

C.

attachments.csv lookup

D.

/etc/apps/SA-Investigations/default/ui/views/attachments

Buy Now
Questions 19

What do threat gen searches produce?

Options:

A.

Threat Intel in KV Store collections.

B.

Threat correlation searches.

C.

Threat notables in the notable index.

D.

Events in the threat activity index.

Buy Now
Questions 20

What is the default schedule for accelerating ES Datamodels?

Options:

A.

1 minute

B.

5 minutes

C.

15 minutes

D.

1 hour

Buy Now
Questions 21

Following the Installation of ES, an admin configured Leers with the ©ss_uso r role the ability to close notable events. How would the admin restrict these users from being able to change the status of Resolved notable events to closed?

Options:

A.

From the Status Configuration window select the Resolved status. Remove ess_user from the status transitions for the closed status.

B.

From the Status Configuration windows select the closed status. Remove ess_use r from the status transitions for the Resolved status.

C.

In Enterprise Security, give the ess_user role the own Notable Events permission.

D.

From Splunk Access Controls, select the ess_user role and remove the edit_notabie_events capability.

Buy Now
Questions 22

What is the bar across the bottom of any ES window?

Options:

A.

The Investigator Workbench.

B.

The Investigation Bar.

C.

The Analyst Bar.

D.

The Compliance Bar.

Buy Now
Questions 23

What is the main purpose of the Dashboard Requirements Matrix document?

Options:

A.

Identifies on which data model(s) each dashboard depends.

B.

Provides instructions for customizing each dashboard for local data models.

C.

Identifies the searches used by the dashboards.

D.

Identifies which data model(s) depend on each dashboard.

Buy Now
Questions 24

Which two fields combine to create the Urgency of a notable event?

Options:

A.

Priority and Severity.

B.

Priority and Criticality.

C.

Criticality and Severity.

D.

Precedence and Time.

Buy Now
Questions 25

Which of the following is a risk of using the Auto Deployment feature of Distributed Configuration Management to distribute indexes.conf?

Options:

A.

Indexes might crash.

B.

Indexes might be processing.

C.

Indexes might not be reachable.

D.

Indexes have different settings.

Buy Now
Questions 26

Which of the following would allow an add-on to be automatically imported into Splunk Enterprise Security?

Options:

A.

A prefix of CIM_

B.

A suffix of .spl

C.

A prefix of TECH_

D.

A prefix of Splunk_TA_

Buy Now
Questions 27

Which of the following is a way to test for a property normalized data model?

Options:

A.

Use Audit -> Normalization Audit and check the Errors panel.

B.

Run a | datamodel search, compare results to the CIM documentation for the datamodel.

C.

Run a | loadjob search, look at tag values and compare them to known tags based on the encoding.

D.

Run a | datamodel search and compare the results to the list of data models in the ES normalization guide.

Buy Now
Questions 28

Which correlation search feature is used to throttle the creation of notable events?

Options:

A.

Schedule priority.

B.

Window interval.

C.

Window duration.

D.

Schedule windows.

Buy Now
Questions 29

At what point in the ES installation process should Splunk_TA_ForIndexes.spl be deployed to the indexers?

Options:

A.

When adding apps to the deployment server.

B.

Splunk_TA_ForIndexers.spl is installed first.

C.

After installing ES on the search head(s) and running the distributed configuration management tool.

D.

Splunk_TA_ForIndexers.spl is only installed on indexer cluster sites using the cluster master and the splunk apply cluster-bundle command.

Buy Now
Exam Code: SPLK-3001
Exam Name: Splunk Enterprise Security Certified Admin Exam
Last Update: Dec 17, 2024
Questions: 99

PDF + Testing Engine

$57.75  $164.99

Testing Engine

$43.75  $124.99
buy now SPLK-3001 testing engine

PDF (Q&A)

$36.75  $104.99
buy now SPLK-3001 pdf