Splunk Enterprise Security Certified Admin SPLK-3001 Exam Practice Test

Page: 1 / 14
Total 99 questions
Question 1

Where are attachments to investigations stored?



Answer : A


Question 2

Glass tables can display static images and text, the results of ad-hoc searches, and which of the following objects?



Answer : C


Question 3

After installing Enterprise Security, the distributed configuration management tool can be used to create which app to configure indexers?



Answer : D


Question 4

An administrator is asked to configure an ''Nslookup'' adaptive response action, so that it appears as a selectable option in the notable event's action menu when an analyst is working in the Incident Review dashboard. What steps would the administrator take to configure this option?



Answer : D


Question 5

An administrator is provisioning one search head prior to installing ES. What are the reference minimum requirements for OS, CPU, and RAM for that machine?



Answer : C


Question 6

Which of the following is a risk of using the Auto Deployment feature of Distributed Configuration Management to distribute indexes.conf?



Answer : A


Question 7

How is it possible to navigate to the list of currently-enabled ES correlation searches?



Answer : C


Page:    1 / 14   
Total 99 questions