Weekend Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: xmas50

Splunk SPLK-3001 - Splunk Enterprise Security Certified Admin Exam

Page: 3 / 3
Total 99 questions

Which lookup table does the Default Account Activity Detected correlation search use to flag known default accounts?

A.

Administrative Identities

B.

Local User Intel

C.

Identities

D.

Privileged Accounts

What do threat gen searches produce?

A.

Threat Intel in KV Store collections.

B.

Threat correlation searches.

C.

Threat notables in the notable index.

D.

Events in the threat activity index.

What does the summariesonly=true option do for a correlation search?

A.

Searches only accelerated data.

B.

Forwards summary indexes to the indexing tier.

C.

Uses a default summary time range.

D.

Searches summary indexes only.

When ES content is exported, an app with a .spl extension is automatically created. What is the best practice when exporting and importing updates to ES content?

A.

Use new app names each time content is exported.

B.

Do not use the .spl extension when naming an export.

C.

Always include existing and new content for each export.

D.

Either use new app names or always include both existing and new content.

Following the installation of ES, an admin configured users with the ess_user role the ability to close notable events.

How would the admin restrict these users from being able to change the status of Resolved notable events to Closed?

A.

In Enterprise Security, give the ess_user role the Own Notable Events permission.

B.

From the Status Configuration window select the Closed status. Remove ess_user from the status

transitions for the Resolved status.

C.

From the Status Configuration window select the Resolved status. Remove ess_user from the status transitions for the Closed status.

D.

From Splunk Access Controls, select the ess_user role and remove the edit_notable_events capability.

What tools does the Risk Analysis dashboard provide?

A.

High risk threats.

B.

Notable event domains displayed by risk score.

C.

A display of the highest risk assets and identities.

D.

Key indicators showing the highest probability correlation searches in the environment.

What is the first step when preparing to install ES?

A.

Install ES.

B.

Determine the data sources used.

C.

Determine the hardware required.

D.

Determine the size and scope of installation.

The Add-On Builder creates Splunk Apps that start with what?

A.

DA-

B.

SA-

C.

TA-

D.

App-

Adaptive response action history is stored in which index?

A.

cim_modactions

B.

modular_history

C.

cim_adaptiveactions

D.

modular_action_history