Splunk Enterprise Security Certified Admin - SPLK-3001 Exam Practice Test
Which framework allows Splunk ES to automatically trigger actions in external security tools?
Correct Answer: A
Vote an answer
Explanation: Only visible for PassTestking members. You can sign-up / login (it's free).
An administrator is provisioning one search head prior to installing ES.
What are the reference minimum requirements for OS, CPU, and RAM for that machine?
What are the reference minimum requirements for OS, CPU, and RAM for that machine?
Correct Answer: C
Vote an answer
Explanation: Only visible for PassTestking members. You can sign-up / login (it's free).
The option to create a Short ID for a notable event is located where?
Correct Answer: C
Vote an answer
Explanation: Only visible for PassTestking members. You can sign-up / login (it's free).
What is the primary purpose of adaptive response actions within Splunk Enterprise Security?
Correct Answer: A
Vote an answer
Explanation: Only visible for PassTestking members. You can sign-up / login (it's free).
What does the Common Information Model primarily provide within Splunk Enterprise Security?
Correct Answer: D
Vote an answer
Explanation: Only visible for PassTestking members. You can sign-up / login (it's free).
Which of the following are examples of sources for events in the endpoint security domain dashboards?
Correct Answer: B
Vote an answer
Explanation: Only visible for PassTestking members. You can sign-up / login (it's free).
Which setting is used in indexes.conf to specify alternate locations for accelerated storage?
Correct Answer: C
Vote an answer
Explanation: Only visible for PassTestking members. You can sign-up / login (it's free).
Which tool is used to update indexers in ES?
Correct Answer: C
Vote an answer
Explanation: Only visible for PassTestking members. You can sign-up / login (it's free).
Where is the Add-On Builder available from?
Correct Answer: C
Vote an answer
Explanation: Only visible for PassTestking members. You can sign-up / login (it's free).