Splunk SPLK-3001 Splunk Enterprise Security Certified Admin Exam Practice Test

Page: 1 / 14
Total 99 questions
Question 1

A site has a single existing search head which hosts a mix of both CIM and non-CIM compliant applications. All of the applications are mission-critical. The customer wants to carefully control cost, but wants good ES performance. What is the best practice for installing ES?



Answer : B


Question 2

The Remote Access panel within the User Activity dashboard is not populating with the most recent hour of dat

a. What data model should be checked for potential errors such as skipped searches?



Answer : D


Question 3

At what point in the ES installation process should Splunk_TA_ForIndexes.spl be deployed to the indexers?



Answer : C


Question 4

Which of the following are examples of sources for events in the endpoint security domain dashboards?



Answer : C


Question 5

Which indexes are searched by default for CIM data models?



Answer : D


Question 6

When investigating, what is the best way to store a newly-found IOC?



Answer : C


Question 7

How is notable event urgency calculated?



Answer : D


Page:    1 / 14   
Total 99 questions