Splunk SPLK-3001 - Splunk Enterprise Security Certified Admin Exam
Page: 3 / 20
Total 100 questions
Question #11 (Topic: Single Topic)
Which setting is used in indexes.conf to specify alternate locations for accelerated storage?
A. thawedPath
B. tstatsHomePath
C. summaryHomePath
D. warmToColdScript
Answer: B
Question #12 (Topic: Single Topic)
Which of the following is a way to test for a property normalized data model?
A. Use Audit -> Normalization Audit and check the Errors panel.
B. Run a | datamodel search, compare results to the CIM documentation for the datamodel.
C. Run a | loadjob search, look at tag values and compare them to known tags based on the encoding.
D. Run a | datamodel search and compare the results to the list of data models in the ES normalization guide.
Answer: B
Question #13 (Topic: Single Topic)
Which argument to the | tstats command restricts the search to summarized data only?
A. summaries=t
B. summaries=all
C. summariesonly=t
D. summariesonly=all
Answer: C
Question #14 (Topic: Single Topic)
When investigating, what is the best way to store a newly-found IOC?
A. Paste it into Notepad.
B. Click the ג€Add IOCג€ button.
C. Click the ג€Add Artifactג€ button.
D. Add it in a text note to the investigation.
Answer: B
Question #15 (Topic: Single Topic)
How is it possible to navigate to the list of currently-enabled ES correlation searches?
A. Configure -> Correlation Searches -> Select Status ג€Enabledג€
B. Settings -> Searches, Reports, and Alerts -> Filter by Name of ג€Correlationג€
C. Configure -> Content Management -> Select Type ג€Correlationג€ and Status ג€Enabledג€
D. Settings -> Searches, Reports, and Alerts -> Select App of ג€SplunkEnterpriseSecuritySuiteג€ and filter by ג€-Ruleג€
Answer: A