ExamGecko
Home / Splunk / SPLK-3001 / List of questions
Ask Question

Splunk SPLK-3001 Practice Test - Questions Answers, Page 7

List of questions

Question 61

Report
Export
Collapse

Which of the following is a Web Intelligence dashboard?

Network Center
Network Center
Endpoint Center
Endpoint Center
HTTP Category Analysis
HTTP Category Analysis
stream :http Protocol dashboard
stream :http Protocol dashboard
Suggested answer: C
asked 23/09/2024
Gilbert Mendoza
38 questions

Question 62

Report
Export
Collapse

Which of the following is an adaptive action that is configured by default for ES?

Create notable event
Create notable event
Create new correlation search
Create new correlation search
Create investigation
Create investigation
Create new asset
Create new asset
Suggested answer: A
asked 23/09/2024
mohamed mamdouh
43 questions

Question 63

Report
Export
Collapse

Which of the following are the default ports that must be configured for Splunk Enterprise Security to function?

SplunkWeb (8068), Splunk Management (8089), KV Store (8000)
SplunkWeb (8068), Splunk Management (8089), KV Store (8000)
SplunkWeb (8390), Splunk Management (8323), KV Store (8672)
SplunkWeb (8390), Splunk Management (8323), KV Store (8672)
SplunkWeb (8000), Splunk Management (8089), KV Store (8191)
SplunkWeb (8000), Splunk Management (8089), KV Store (8191)
SplunkWeb (8043), Splunk Management (8088), KV Store (8191)
SplunkWeb (8043), Splunk Management (8088), KV Store (8191)
Suggested answer: C

Explanation:

https://docs.splunk.com/Documentation/Splunk/8.1.2/Security/SecureSplunkonyournetwork

asked 23/09/2024
Udara Somachandra
49 questions

Question 64

Report
Export
Collapse

Which tool Is used to update indexers In E5?

Index Updater
Index Updater
Distributed Configuration Management
Distributed Configuration Management
indexes.conf
indexes.conf
Splunk_TA_ForIndexeres. spl
Splunk_TA_ForIndexeres. spl
Suggested answer: B
asked 23/09/2024
Stian Godoe
42 questions

Question 65

Report
Export
Collapse

Which of the following actions may be necessary before installing ES?

Redirect distributed search connections.
Redirect distributed search connections.
Purge KV Store.
Purge KV Store.
Add additional indexers.
Add additional indexers.
Add additional forwarders.
Add additional forwarders.
Suggested answer: C
asked 23/09/2024
Talal Elemam
51 questions

Question 66

Report
Export
Collapse

When using distributed configuration management to create the Splunk_TA_ForIndexers package, which three files can be included?

indexes.conf, props.conf, transforms.conf
indexes.conf, props.conf, transforms.conf
web.conf, props.conf, transforms.conf
web.conf, props.conf, transforms.conf
inputs.conf, props.conf, transforms.conf
inputs.conf, props.conf, transforms.conf
eventtypes.conf, indexes.conf, tags.conf
eventtypes.conf, indexes.conf, tags.conf
Suggested answer: A

Explanation:

Reference: https://docs.splunk.com/Documentation/ES/6.4.1/Install/InstallTechnologyAdd-ons

asked 23/09/2024
Arthur Khaha
43 questions

Question 67

Report
Export
Collapse

Which of these Is a benefit of data normalization?

Reports run faster because normalized data models can be optimized for better performance.
Reports run faster because normalized data models can be optimized for better performance.
Dashboards take longer to build.
Dashboards take longer to build.
Searches can be built no matter the specific source technology for a normalized data type.
Searches can be built no matter the specific source technology for a normalized data type.
Forwarder-based inputs are more efficient.
Forwarder-based inputs are more efficient.
Suggested answer: A
asked 23/09/2024
Jagatnata Gurusinga
38 questions

Question 68

Report
Export
Collapse

Following the Installation of ES, an admin configured Leers with the ©ss_uso r role the ability to close notable events. How would the admin restrict these users from being able to change the status of Resolved notable events to closed?

From the Status Configuration window select the Resolved status. Remove ess_user from the status transitions for the closed status.
From the Status Configuration window select the Resolved status. Remove ess_user from the status transitions for the closed status.
From the Status Configuration windows select the closed status. Remove ess_use r from the status transitions for the Resolved status.
From the Status Configuration windows select the closed status. Remove ess_use r from the status transitions for the Resolved status.
In Enterprise Security, give the ess_user role the own Notable Events permission.
In Enterprise Security, give the ess_user role the own Notable Events permission.
From Splunk Access Controls, select the ess_user role and remove the edit_notabie_events capability.
From Splunk Access Controls, select the ess_user role and remove the edit_notabie_events capability.
Suggested answer: B
asked 23/09/2024
Francisli Lilles
42 questions

Question 69

Report
Export
Collapse

What is the bar across the bottom of any ES window?

The Investigator Workbench.
The Investigator Workbench.
The Investigation Bar.
The Investigation Bar.
The Analyst Bar.
The Analyst Bar.
The Compliance Bar.
The Compliance Bar.
Suggested answer: B

Explanation:

Reference: https://docs.splunk.com/Documentation/ES/6.4.1/User/Startaninvestigation

asked 23/09/2024
David Shokrai
37 questions

Question 70

Report
Export
Collapse

Which lookup table does the Default Account Activity Detected correlation search use to flag known default accounts?

Administrative Identities
Administrative Identities
Local User Intel
Local User Intel
Identities
Identities
Privileged Accounts
Privileged Accounts
Suggested answer: C
asked 23/09/2024
Sergio da Costa
35 questions
Total 99 questions
Go to page: of 10