ExamGecko
Home / Splunk / SPLK-3001 / List of questions
Ask Question

Splunk SPLK-3001 Practice Test - Questions Answers

List of questions

Question 1

Report
Export
Collapse

The Add-On Builder creates Splunk Apps that start with what?

DA
DA
SA
SA
TA
TA
App-
App-
Suggested answer: C

Explanation:

Reference:

https://dev.splunk.com/enterprise/docs/developapps/enterprisesecurity/abouttheessolution/

asked 23/09/2024
Babak Sadeghpour
28 questions

Question 2

Report
Export
Collapse

Which of the following are examples of sources for events in the endpoint security domain dashboards?

REST API invocations.
REST API invocations.
Investigation final results status.
Investigation final results status.
Workstations, notebooks, and point-of-sale systems.
Workstations, notebooks, and point-of-sale systems.
Lifecycle auditing of incidents, from assignment to resolution.
Lifecycle auditing of incidents, from assignment to resolution.
Suggested answer: C

Explanation:

Reference:

https://docs.splunk.com/Documentation/ES/6.1.0/User/EndpointProtectionDomaindashboards

asked 23/09/2024
Rodrigo Serrano dos Santos
38 questions

Question 3

Report
Export
Collapse

When creating custom correlation searches, what format is used to embed field values in the title, description, and drill-down fields of a notable event?

$fieldname$
$fieldname$
“fieldname”
“fieldname”
%fieldname%
%fieldname%
_fieldname_
_fieldname_
Suggested answer: A

Explanation:

Reference: https://docs.splunk.com/Documentation/ITSI/4.4.2/Configure/Createcorrelationsearch

asked 23/09/2024
Mitesh Patel
44 questions

Question 4

Report
Export
Collapse

What feature of Enterprise Security downloads threat intelligence data from a web server?

Threat Service Manager
Threat Service Manager
Threat Download Manager
Threat Download Manager
Threat Intelligence Parser
Threat Intelligence Parser
Therat Intelligence Enforcement
Therat Intelligence Enforcement
Suggested answer: B

Explanation:

"The Threat Intelligence Framework provides a modular input (Threat Intelligence Downloads) that handles the majority of configurations typically needed for downloading intelligence files & data. To access this modular input, you simply need to create a stanza in your Inputs.conf file called “threatlist”."

asked 23/09/2024
Peter Unterasinger
42 questions

Question 5

Report
Export
Collapse

The Remote Access panel within the User Activity dashboard is not populating with the most recent hour of dat a. What data model should be checked for potential errors such as skipped searches?

Web
Web
Risk
Risk
Performance
Performance
Authentication
Authentication
Suggested answer: D

Explanation:

Reference: https://answers.splunk.com/answers/565482/how-to-resolve-skipped-scheduledsearches.html

asked 23/09/2024
Duane Joyce
33 questions

Question 6

Report
Export
Collapse

In order to include an eventtype in a data model node, what is the next step after extracting the correct fields?

Save the settings.
Save the settings.
Apply the correct tags.
Apply the correct tags.
Run the correct search.
Run the correct search.
Visit the CIM dashboard.
Visit the CIM dashboard.
Suggested answer: C

Explanation:

Reference:

https://docs.splunk.com/Documentation/CIM/4.15.0/User/UsetheCIMtonormalizeOSSECdata

asked 23/09/2024
Marcin Piotrowski
40 questions

Question 7

Report
Export
Collapse

What role should be assigned to a security team member who will be taking ownership of notable events in the incident review dashboard?

ess_user
ess_user
ess_admin
ess_admin
ess_analyst
ess_analyst
ess_reviewer
ess_reviewer
Suggested answer: B

Explanation:

Reference: https://docs.splunk.com/Documentation/ES/6.1.0/User/Triagenotableevents

asked 23/09/2024
Justin Kim
38 questions

Question 8

Report
Export
Collapse

Which column in the Asset or Identity list is combined with event security to make a notable event’s urgency?

VIP
VIP
Priority
Priority
Importance
Importance
Criticality
Criticality
Suggested answer: B

Explanation:

Reference: https://docs.splunk.com/Documentation/ES/6.1.0/User/Howurgencyisassigned

asked 23/09/2024
marco damone
41 questions

Question 9

Report
Export
Collapse

What does the risk framework add to an object (user, server or other type) to indicate increased risk?

An urgency.
An urgency.
A risk profile.
A risk profile.
An aggregation.
An aggregation.
A numeric score.
A numeric score.
Suggested answer: D

Explanation:

Reference: https://docs.splunk.com/Documentation/ES/6.1.0/User/RiskScoring

asked 23/09/2024
rayan rayanalbanna
44 questions

Question 10

Report
Export
Collapse

Which indexes are searched by default for CIM data models?

notable and default
notable and default
summary and notable
summary and notable
_internal and summary
_internal and summary
All indexes
All indexes
Suggested answer: D

Explanation:

Reference: https://answers.splunk.com/answers/600354/indexes-searched-by-cim-datamodels.html

asked 23/09/2024
Lionel Fitzgerald Gweth
44 questions
Total 99 questions
Go to page: of 10