Splunk SPLK-3001 - Splunk Enterprise Security Certified Admin Exam

Question #11 (Topic: Single Topic)
Which setting is used in indexes.conf to specify alternate locations for accelerated storage?
A. thawedPath B. tstatsHomePath C. summaryHomePath D. warmToColdScript
Answer: B
Question #12 (Topic: Single Topic)
Which of the following is a way to test for a property normalized data model?
A. Use Audit -> Normalization Audit and check the Errors panel. B. Run a | datamodel search, compare results to the CIM documentation for the datamodel. C. Run a | loadjob search, look at tag values and compare them to known tags based on the encoding. D. Run a | datamodel search and compare the results to the list of data models in the ES normalization guide.
Answer: B
Question #13 (Topic: Single Topic)
Which argument to the | tstats command restricts the search to summarized data only?
A. summaries=t B. summaries=all C. summariesonly=t D. summariesonly=all
Answer: C
Question #14 (Topic: Single Topic)
When investigating, what is the best way to store a newly-found IOC?
A. Paste it into Notepad. B. Click the ג€Add IOCג€ button. C. Click the ג€Add Artifactג€ button. D. Add it in a text note to the investigation.
Answer: B
Question #15 (Topic: Single Topic)
How is it possible to navigate to the list of currently-enabled ES correlation searches?
A. Configure -> Correlation Searches -> Select Status ג€Enabledג€ B. Settings -> Searches, Reports, and Alerts -> Filter by Name of ג€Correlationג€ C. Configure -> Content Management -> Select Type ג€Correlationג€ and Status ג€Enabledג€ D. Settings -> Searches, Reports, and Alerts -> Select App of ג€SplunkEnterpriseSecuritySuiteג€ and filter by ג€-Ruleג€
Answer: A
Download Exam
Page: 3 / 20
Total 100 questions