Splunk SPLK-3001 Splunk Enterprise Security Certified Admin Exam Practice Test

Page: 1 / 14
Total 99 questions

Question 1

What is the main purpose of the Dashboard Requirements Matrix document?



Answer : D

Question 2

What does the summariesonly=true option do for a correlation search?



Answer : A

Question 3

Which columns in the Assets lookup are used to identify an asset in an event?



Answer : C

Question 4

Which two fields combine to create the Urgency of a notable event?



Answer : A

Question 5

Which of the following actions would not reduce the number of false positives from a correlation search?



Answer : A

Question 6

Adaptive response action history is stored in which index?



Answer : A

Question 7

To observe what network services are in use in a network's activity overall, which of the following dashboards in Enterprise Security will contain the most relevant data?



Answer : B

Page:    1 / 14   
Total 99 questions