Pass the Splunk Splunk Enterprise Security Certified Admin SPLK-3001 Questions and answers with CertsForce

Viewing page 3 out of 3 pages
Viewing questions 21-30 out of questions
Questions # 21:

Accelerated data requires approximately how many times the daily data volume of additional storage space per year?

Options:

A.

3.4


B.

5.7


C.

1.0


D.

2.5


Expert Solution
Questions # 22:

Which of the following are examples of sources for events in the endpoint security domain dashboards?

Options:

A.

REST API invocations.


B.

Investigation final results status.


C.

Workstations, notebooks, and point-of-sale systems.


D.

Lifecycle auditing of incidents, from assignment to resolution.


Expert Solution
Questions # 23:

The option to create a Short ID for a notable event is located where?

Options:

A.

The Additional Fields.


B.

The Event Details.


C.

The Contributing Events.


D.

The Description.


Expert Solution
Questions # 24:

What is the bar across the bottom of any ES window?

Options:

A.

The Investigator Workbench.


B.

The Investigation Bar.


C.

The Analyst Bar.


D.

The Compliance Bar.


Expert Solution
Questions # 25:

To which of the following should the ES application be uploaded?

Options:

A.

The indexer.


B.

The KV Store.


C.

The search head.


D.

The dedicated forwarder.


Expert Solution
Questions # 26:

Which component normalizes events?

Options:

A.

SA-CIM.


B.

SA-Notable.


C.

ES application.


D.

Technology add-on.


Expert Solution
Questions # 27:

What are the steps to add a new column to the Notable Event table in the Incident Review dashboard?

Options:

A.

Configure -> Incident Management -> Notable Event Statuses


B.

Configure -> Content Management -> Type: Correlation Search


C.

Configure -> Incident Management -> Incident Review Settings -> Event Management


D.

Configure -> Incident Management -> Incident Review Settings -> Table Attributes


Expert Solution
Questions # 28:

What should be used to map a non-standard field name to a CIM field name?

Options:

A.

Field alias.


B.

Search time extraction.


C.

Tag.


D.

Eventtype.


Expert Solution
Questions # 29:

ES apps and add-ons from $SPLUNK_HOME/etc/apps should be copied from the staging instance to what location on the cluster deployer instance?

Options:

A.

$SPLUNK_HOME/etc/master-apps/


B.

$SPLUNK_HOME/etc/system/local/


C.

$SPLUNK_HOME/etc/shcluster/apps


D.

$SPLUNK_HOME/var/run/searchpeers/


Expert Solution
Viewing page 3 out of 3 pages
Viewing questions 21-30 out of questions