Free Certification Practice Questions

SPLUNK-SPLK-3001

Loading…
Accelerated data requires approximately how many times the daily data volume of additional storage space per year?
#61
When installing Enterprise Security, what should be done after installing the add-ons necessary for normalizing data?
#62
What can be exported from ES using the Content Management page?
#63
Where should an ES search head be installed?
#64
Following the installation of ES, an admin configured users with the ess_user role the ability to close notable events.How would the admin restrict these users from being able to change the status of Resolved notable events to Closed?
#65
Which of the following actions may be necessary before installing ES?
#66
A customer site is experiencing poor performance. The UI response time is high and searches take a very long time to run. Some operations time out and there are errors in the scheduler logs, indicating too many concurrent searches are being started. 6 total correlation searches are scheduled and they have already been tuned to weed out false positives.Which of the following options is most likely to help performance?
#67
What should be used to map a non-standard field name to a CIM field name?
#68
Which of the following lookup types in Enterprise Security contains information about known hostile IP addresses?
#69
A set of correlation searches are enabled at a new ES installation, and results are being monitored. One of the correlation searches is generating many notable events which, when evaluated, are determined to be false positives.What is a solution for this issue?
#70
Which of the following steps will make the Threat Activity dashboard the default landing page in ES?
#71
When using distributed configuration management to create the Splunk_TA_ForIndexers package, which three files can be included?
#72
Which feature contains scenarios that are useful during ES implementation?
#73
Where is detailed information about identities stored?
#74
The option to create a Short ID for a notable event is located where?
#75
A newly built custom dashboard needs to be available to a team of security analysts in ES.How is it possible to integrate the new dashboard?
#76
What is the bar across the bottom of any ES window?
#77
Which two fields combine to create the Urgency of a notable event?
#78
What do threat gen searches produce?
#79
Which of the following is part of tuning correlation searches for a new ES installation?
#80
Which columns in the Assets lookup are used to identify an asset in an event?
#81
What does the summariesonly=true option do for a correlation search?
#82
Which of the following are the default ports that must be configured for Splunk Enterprise Security to function?
#83
What is the main purpose of the Dashboard Requirements Matrix document?
#84
Which of the following is a recommended pre-installation step?
#85
What are adaptive responses triggered by?
#86
Which of the following is an adaptive action that is configured by default for ES?
#87
When creating custom correlation searches, what format is used to embed field values in the title, description, and drill-down fields of a notable event?
#88
Which lookup table does the Default Account Activity Detected correlation search use to flag known default accounts?
#89
Which tool is used to update indexers in ES?
#90