Splunk SPLK-3001 Practice Test - Questions Answers, Page 2

List of questions
Question 11

Which setting is used in indexes.conf to specify alternate locations for accelerated storage?
Reference:
https://docs.splunk.com/Documentation/Splunk/8.0.2/Knowledge/Acceleratedatamodels
Question 12

Which of the following is a way to test for a property normalized data model?
Reference:
https://docs.splunk.com/Documentation/CIM/4.15.0/User/UsetheCIMtonormalizedataatsearchtime
Question 13

Which argument to the | tstats command restricts the search to summarized data only?
Reference:
https://docs.splunk.com/Documentation/Splunk/8.0.2/Knowledge/Acceleratedatamodels
Question 14

When investigating, what is the best way to store a newly-found IOC?
Question 15

How is it possible to navigate to the list of currently-enabled ES correlation searches?
Reference: https://docs.splunk.com/Documentation/ES/6.1.0/Admin/Listcorrelationsearches
Question 16

Which of the following is a risk of using the Auto Deployment feature of Distributed Configuration Management to distribute indexes.conf?
Reference: https://docs.splunk.com/Documentation/Splunk/8.0.2/Admin/Indexesconf
Question 17

Which of the following are data models used by ES? (Choose all that apply)
Reference:
https://dev.splunk.com/enterprise/docs/developapps/enterprisesecurity/datamodelsusedbyes/
Question 18

At what point in the ES installation process should Splunk_TA_ForIndexes.spl be deployed to the indexers?
Reference: https://docs.splunk.com/Documentation/ES/6.1.0/Install/InstallTechnologyAdd-ons
Question 19

Which correlation search feature is used to throttle the creation of notable events?
Question 20

Both βRecommended Actionsβ and βAdaptive Response Actionsβ use adaptive response. How do they differ?
Question