Splunk SPLK-3001 Practice Test - Questions Answers, Page 2
List of questions
Question 11
Which setting is used in indexes.conf to specify alternate locations for accelerated storage?
Reference:
https://docs.splunk.com/Documentation/Splunk/8.0.2/Knowledge/Acceleratedatamodels
Question 12
Which of the following is a way to test for a property normalized data model?
Reference:
https://docs.splunk.com/Documentation/CIM/4.15.0/User/UsetheCIMtonormalizedataatsearchtime
Question 13
Which argument to the | tstats command restricts the search to summarized data only?
Reference:
https://docs.splunk.com/Documentation/Splunk/8.0.2/Knowledge/Acceleratedatamodels
Question 14
When investigating, what is the best way to store a newly-found IOC?
Question 15
How is it possible to navigate to the list of currently-enabled ES correlation searches?
Reference: https://docs.splunk.com/Documentation/ES/6.1.0/Admin/Listcorrelationsearches
Question 16
Which of the following is a risk of using the Auto Deployment feature of Distributed Configuration Management to distribute indexes.conf?
Reference: https://docs.splunk.com/Documentation/Splunk/8.0.2/Admin/Indexesconf
Question 17
Which of the following are data models used by ES? (Choose all that apply)
Reference:
https://dev.splunk.com/enterprise/docs/developapps/enterprisesecurity/datamodelsusedbyes/
Question 18
At what point in the ES installation process should Splunk_TA_ForIndexes.spl be deployed to the indexers?
Reference: https://docs.splunk.com/Documentation/ES/6.1.0/Install/InstallTechnologyAdd-ons
Question 19
Which correlation search feature is used to throttle the creation of notable events?
Question 20
Both βRecommended Actionsβ and βAdaptive Response Actionsβ use adaptive response. How do they differ?
Question