Pass the Splunk Splunk Enterprise Security Certified Admin SPLK-3001 Questions and answers with CertsForce

Viewing page 1 out of 3 pages
Viewing questions 1-10 out of questions
Questions # 1:

Glass tables can display static images and text, the results of ad-hoc searches, and which of the following objects?

Options:

A.

Lookup searches.


B.

Summarized data.


C.

Security metrics.


D.

Metrics store searches.


Expert Solution
Questions # 2:

A set of correlation searches are enabled at a new ES installation, and results are being monitored. One of the correlation searches is generating many notable events which, when evaluated, are determined to be false positives.

What is a solution for this issue?

Options:

A.

Suppress notable events from that correlation search.


B.

Disable acceleration for the correlation search to reduce storage requirements.


C.

Modify the correlation schedule and sensitivity for your site.


D.

Change the correlation search's default status and severity.


Expert Solution
Questions # 3:

Which of the following ES features would a security analyst use while investigating a network anomaly notable?

Options:

A.

Correlation editor.


B.

Key indicator search.


C.

Threat download dashboard.


D.

Protocol intelligence dashboard.


Expert Solution
Questions # 4:

Which columns in the Assets lookup are used to identify an asset in an event?

Options:

A.

src, dvc, dest


B.

cidr, port, netbios, saml


C.

ip, mac, dns, nt_host


D.

host, hostname, url, address


Expert Solution
Questions # 5:

“10.22.63.159”, “websvr4”, and “00:26:08:18: CF:1D” would be matched against what in ES?

Options:

A.

A user.


B.

A device.


C.

An asset.


D.

An identity.


Expert Solution
Questions # 6:

After data is ingested, which data management step is essential to ensure raw data can be accelerated by a Data Model and used by ES?

Options:

A.

Applying Tags.


B.

Normalization to Customer Standard.


C.

Normalization to the Splunk Common Information Model.


D.

Extracting Fields.


Expert Solution
Questions # 7:

What is an example of an ES asset?

Options:

A.

MAC address


B.

User name


C.

Server


D.

People


Expert Solution
Questions # 8:

Which of the following is a Web Intelligence dashboard?

Options:

A.

Network Center


B.

Endpoint Center


C.

HTTP Category Analysis


D.

stream: http Protocol dashboard


Expert Solution
Questions # 9:

Following the Installation of ES, an admin configured Leers with the ©ss_uso r role the ability to close notable events. How would the admin restrict these users from being able to change the status of Resolved notable events to closed?

Options:

A.

From the Status Configuration window select the Resolved status. Remove ess_user from the status transitions for the closed status.


B.

From the Status Configuration windows select the closed status. Remove ess_use r from the status transitions for the Resolved status.


C.

In Enterprise Security, give the ess_user role the own Notable Events permission.


D.

From Splunk Access Controls, select the ess_user role and remove the edit_notabie_events capability.


Expert Solution
Questions # 10:

Which argument to the | tstats command restricts the search to summarized data only?

Options:

A.

summaries=t


B.

summaries=all


C.

summariesonly=t


D.

summariesonly=all


Expert Solution
Viewing page 1 out of 3 pages
Viewing questions 1-10 out of questions