Splunk SPLK-3001 Practice Test - Questions Answers, Page 6
List of questions
Related questions
Question 51

When ES content is exported, an app with a .spl extension is automatically created. What is the best practice when exporting and importing updates to ES content?
Explanation:
Either use new app names each time (which could be difficult to manage) or make sure you always include all content (old and new) each time you export.
Question 52

Who can delete an investigation?
Explanation:
Reference: https://docs.splunk.com/Documentation/ES/6.1.0/Admin/Manageinvestigations
Question 53

After installing Enterprise Security, the distributed configuration management tool can be used to create which app to configure indexers?
Explanation:
Reference: https://docs.splunk.com/Documentation/ES/6.1.0/Install/InstallTechnologyAdd-ons
Question 54

The Brute Force Access Behavior Detected correlation search is enabled, and is generating many false positives. Assuming the input data has already been validated. How can the correlation search be made less sensitive?
Explanation:
Reference: https://docs.splunk.com/Documentation/ES/6.1.0/User/Howurgencyisassigned
Question 55

Which of the following actions can improve overall search performance?
Question 56

Which of the following ES features would a security analyst use while investigating a network anomaly notable?
Explanation:
Reference: https://www.splunk.com/en_us/products/premium-solutions/splunk-enterprisesecurity/features.html
Question 57

Which component normalizes events?
Explanation:
Reference:
https://docs.splunk.com/Documentation/CIM/4.15.0/User/UsetheCIMtonormalizedataatsearchtime
Question 58

An administrator wants to ensure that none of the ES indexed data could be compromised through tampering. What feature would satisfy this requirement?
Explanation:
Reference: https://answers.splunk.com/answers/790783/anti-tampering-features-to-protect-splunklogs-the.html
Question 59

What is the first step when preparing to install ES?
Question 60

What is the default schedule for accelerating ES Datamodels?
Question