Splunk Enterprise Security Certified Admin SPLK-3001 Exam Questions

Page: 1 / 14
Total 99 questions
Question 1

What are the steps to add a new column to the Notable Event table in the Incident Review dashboard?



Answer : D


Question 2

The option to create a Short ID for a notable event is located where?



Answer : B

https://docs.splunk.com/Documentation/ES/6.4.1/User/Takeactiononanotableevent


Question 3

Where are attachments to investigations stored?



Answer : A


Question 4

Which of the following is a recommended pre-installation step?



Answer : B


Question 5

Which argument to the | tstats command restricts the search to summarized data only?



Answer : C


Question 6

Which setting is used in indexes.conf to specify alternate locations for accelerated storage?



Answer : B


Question 7

Which of the following is an adaptive action that is configured by default for ES?



Answer : A


Page:    1 / 14   
Total 99 questions