Splunk Enterprise Security Certified Admin SPLK-3001 Exam Questions

Page: 1 / 14
Total 99 questions
Question 1

What is the maximum recommended volume of indexing per day, per indexer, for a non-cloud (on-prem) ES deployment?



Answer : B


Question 2

ES needs to be installed on a search head with which of the following options?



Answer : D


Question 3

Which settings indicated that the correlation search will be executed as new events are indexed?



Answer : C


Question 4

At what point in the ES installation process should Splunk_TA_ForIndexes.spl be deployed to the indexers?



Answer : C


Question 5

What role should be assigned to a security team member who will be taking ownership of notable events in the incident review dashboard?



Answer : B


Question 6

Where are attachments to investigations stored?



Answer : A


Question 7

What does the risk framework add to an object (user, server or other type) to indicate increased risk?



Answer : D


Page:    1 / 14   
Total 99 questions