Pre-Winter Sale Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: pass65

Pass the Splunk Splunk Enterprise Security Certified Admin SPLK-3001 Questions and answers with CertsForce

Viewing page 3 out of 3 pages
Viewing questions 21-30 out of questions
Questions # 21:

A set of correlation searches are enabled at a new ES installation, and results are being monitored. One of the correlation searches is generating many notable events which, when evaluated, are determined to be false positives.

What is a solution for this issue?

Options:

A.

Suppress notable events from that correlation search.


B.

Disable acceleration for the correlation search to reduce storage requirements.


C.

Modify the correlation schedule and sensitivity for your site.


D.

Change the correlation search's default status and severity.


Expert Solution
Questions # 22:

The Brute Force Access Behavior Detected correlation search is enabled, and is generating many false positives. Assuming the input data has already been validated. How can the correlation search be made less sensitive?

Options:

A.

Edit the search and modify the notable event status field to make the notable events less urgent.


B.

Edit the search, look for where or xswhere statements, and after the threshold value being compared to make it less common match.


C.

Edit the search, look for where or xswhere statements, and alter the threshold value being compared to make it a more common match.


D.

Modify the urgency table for this correlation search and add a new severity level to make notable events from this search less urgent.


Expert Solution
Questions # 23:

How is it possible to specify an alternate location for accelerated storage?

Options:

A.

Configure storage optimization settings for the index.


B.

Update the Home Path setting in indexes, conf


C.

Use the tstatsHomePath setting in props, conf


D.

Use the tstatsHomePath Setting in indexes, conf


Expert Solution
Questions # 24:

Where is the Add-On Builder available from?

Options:

A.

GitHub


B.

SplunkBase


C.

www.splunk.com


D.

The ES installation package


Expert Solution
Questions # 25:

When using distributed configuration management to create the Splunk_TA_ForIndexers package, which three files can be included?

Options:

A.

indexes.conf, props.conf, transforms.conf


B.

web.conf, props.conf, transforms.conf


C.

inputs.conf, props.conf, transforms.conf


D.

eventtypes.conf, indexes.conf, tags.conf


Expert Solution
Questions # 26:

Accelerated data requires approximately how many times the daily data volume of additional storage space per year?

Options:

A.

3.4


B.

5.7


C.

1.0


D.

2.5


Expert Solution
Questions # 27:

How is notable event urgency calculated?

Options:

A.

Asset priority and threat weight.


B.

Alert severity found by the correlation search.


C.

Asset or identity risk and severity found by the correlation search.


D.

Severity set by the correlation search and priority assigned to the associated asset or identity.


Expert Solution
Questions # 28:

Which of the following is a recommended pre-installation step?

Options:

A.

Disable the default search app.


B.

Configure search head forwarding.


C.

Download the latest version of KV Store from MongoDBxom.


D.

Install the latest Python distribution on the search head.


Expert Solution
Questions # 29:

Following the installation of ES, an admin configured users with the ess_user role the ability to close notable events.

How would the admin restrict these users from being able to change the status of Resolved notable events to Closed?

Options:

A.

In Enterprise Security, give the ess_user role the Own Notable Events permission.


B.

From the Status Configuration window select the Closed status. Remove ess_user from the status

transitions for the Resolved status.


C.

From the Status Configuration window select the Resolved status. Remove ess_user from the status transitions for the Closed status.


D.

From Splunk Access Controls, select the ess_user role and remove the edit_notable_events capability.


Expert Solution
Viewing page 3 out of 3 pages
Viewing questions 21-30 out of questions