Pass4itsure > Splunk > Splunk Enterprise Security Certified Admin > SPLK-3001 > SPLK-3001 Online Practice Questions and Answers

SPLK-3001 Online Practice Questions and Answers

Questions 4

Which column in the Asset or Identity list is combined with event security to make a notable event's urgency?

A. VIP

B. Priority

C. Importance

D. Criticality

Buy Now
Questions 5

If a username does not match the `identity' column in the identities list, which column is checked next?

A. Email.

B. Nickname

C. IP address.

D. Combination of Last Name, First Name.

Buy Now
Questions 6

Which columns in the Assets lookup are used to identify an asset in an event?

A. src, dvc, dest

B. cidr, port, netbios, saml

C. ip, mac, dns, nt_host

D. host, hostname, url, address

Buy Now
Questions 7

Which settings indicated that the correlation search will be executed as new events are indexed?

A. Always-On

B. Real-Time

C. Scheduled

D. Continuous

Buy Now
Questions 8

How is notable event urgency calculated?

A. Asset priority and threat weight.

B. Alert severity found by the correlation search.

C. Asset or identity risk and severity found by the correlation search.

D. Severity set by the correlation search and priority assigned to the associated asset or identity.

Buy Now
Questions 9

Which of the following lookup types in Enterprise Security contains information about known hostile IP addresses?

A. Security domains.

B. Threat intel.

C. Assets.

D. Domains.

Buy Now
Questions 10

How should an administrator add a new lookup through the ES app?

A. Upload the lookup file in Settings -> Lookups -> Lookup Definitions

B. Upload the lookup file in Settings -> Lookups -> Lookup table files

C. Add the lookup file to /etc/apps/SplunkEnterpriseSecuritySuite/lookups

D. Upload the lookup file using Configure -> Content Management -> Create New Content -> Managed Lookup

Buy Now
Questions 11

Which component normalizes events?

A. SA-CIM.

B. SA-Notable.

C. ES application.

D. Technology add-on.

Buy Now
Questions 12

The option to create a Short ID for a notable event is located where?

A. The Additional Fields.

B. The Event Details.

C. The Contributing Events.

D. The Description.

Buy Now
Questions 13

When ES content is exported, an app with a .spl extension is automatically created. What is the best practice when exporting and importing updates to ES content?

A. Use new app names each time content is exported.

B. Do not use the .spl extension when naming an export.

C. Always include existing and new content for each export.

D. Either use new app names or always include both existing and new content.

Buy Now
Exam Code: SPLK-3001
Exam Name: Splunk Enterprise Security Certified Admin
Last Update: Apr 21, 2024
Questions: 99
10%OFF Coupon Code: SAVE10

PDF (Q&A)

$45.99

VCE

$49.99

PDF + VCE

$59.99