Pre-Winter Sale Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: pass65

Pass the Splunk Splunk Enterprise Security Certified Admin SPLK-3001 Questions and answers with CertsForce

Viewing page 2 out of 3 pages
Viewing questions 11-20 out of questions
Questions # 11:

Analysts have requested the ability to capture and analyze network traffic data. The administrator has researched the documentation and, based on this research, has decided to integrate the Splunk App for Stream with ES.

Which dashboards will now be supported so analysts can view and analyze network Stream data?

Options:

A.

Endpoint dashboards.


B.

User Intelligence dashboards.


C.

Protocol Intelligence dashboards.


D.

Web Intelligence dashboards.


Expert Solution
Questions # 12:

Which of the following is a key feature of a glass table?

Options:

A.

Rigidity.


B.

Customization.


C.

Interactive investigations.


D.

Strong data for later retrieval.


Expert Solution
Questions # 13:

ES needs to be installed on a search head with which of the following options?

Options:

A.

No other apps.


B.

Any other apps installed.


C.

All apps removed except for TA-*.


D.

Only default built-in and CIM-compliant apps.


Expert Solution
Questions # 14:

To observe what network services are in use in a network’s activity overall, which of the following dashboards in Enterprise Security will contain the most relevant data?

Options:

A.

Intrusion Center


B.

Protocol Analysis


C.

User Intelligence


D.

Threat Intelligence


Expert Solution
Questions # 15:

At what point in the ES installation process should Splunk_TA_ForIndexes.spl be deployed to the indexers?

Options:

A.

When adding apps to the deployment server.


B.

Splunk_TA_ForIndexers.spl is installed first.


C.

After installing ES on the search head(s) and running the distributed configuration management tool.


D.

Splunk_TA_ForIndexers.spl is only installed on indexer cluster sites using the cluster master and the splunk apply cluster-bundle command.


Expert Solution
Questions # 16:

After managing source types and extracting fields, which key step comes next In the Add-On Builder?

Options:

A.

Validate and package


B.

Configure data collection.


C.

Create alert actions.


D.

Map to data models.


Expert Solution
Questions # 17:

What kind of value is in the red box in this picture?

Question # 17

Options:

A.

A risk score.


B.

A source ranking.


C.

An event priority.


D.

An IP address rating.


Expert Solution
Questions # 18:

What is an example of an ES asset?

Options:

A.

MAC address


B.

User name


C.

Server


D.

People


Expert Solution
Questions # 19:

What is the maximum recommended volume of indexing per day, per indexer, for a non-cloud (on-prem) ES deployment?

Options:

A.

50 GB


B.

100 GB


C.

300 GB


D.

500 MB


Expert Solution
Questions # 20:

Which of the following are data models used by ES? (Choose all that apply)

Options:

A.

Web


B.

Anomalies


C.

Authentication


D.

Network Traffic


Expert Solution
Viewing page 2 out of 3 pages
Viewing questions 11-20 out of questions