Splunk SPLK-3001 Practice Test - Questions Answers, Page 4
List of questions
Question 31
Where is the Add-On Builder available from?
Question 32
Which of the following would allow an add-on to be automatically imported into Splunk Enterprise Security?
Question 33
ES apps and add-ons from $SPLUNK_HOME/etc/apps should be copied from the staging instance to what location on the cluster deployer instance?
Question 34
How is notable event urgency calculated?
Question 35
What kind of value is in the red box in this picture?
Question 36
Where is it possible to export content, such as correlation searches, from ES?
Question 37
Which of the following threat intelligence types can ES download? (Choose all that apply)
Question 38
A site has a single existing search head which hosts a mix of both CIM and non-CIM compliant applications. All of the applications are mission-critical. The customer wants to carefully control cost, but wants good ES performance. What is the best practice for installing ES?
Question 39
Enterprise Security’s dashboards primarily pull data from what type of knowledge object?
Question 40
To which of the following should the ES application be uploaded?
Question