Winter Special Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: bigdisc65

Selected SPLK-3001 Splunk Enterprise Security Certified Admin Questions Answers

Page: 2 / 7
Question 8

When using distributed configuration management to create the Splunk_TA_ForIndexers package, which three files can be included?

Options:

A.

indexes.conf, props.conf, transforms.conf

B.

web.conf, props.conf, transforms.conf

C.

inputs.conf, props.conf, transforms.conf

D.

eventtypes.conf, indexes.conf, tags.conf

Question 9

How does ES know local customer domain names so it can detect internal vs. external emails?

Options:

A.

Web and email domain names are set in General -> General Configuration.

B.

ES uses the User Activity index and applies machine learning to determine internal and external domains.

C.

The Corporate Web and Email Domain Lookups are edited during initial configuration.

D.

ES extracts local email and web domains automatically from SMTP and HTTP logs.

Question 10

The Brute Force Access Behavior Detected correlation search is enabled, and is generating many false positives. Assuming the input data has already been validated. How can the correlation search be made less sensitive?

Options:

A.

Edit the search and modify the notable event status field to make the notable events less urgent.

B.

Edit the search, look for where or xswhere statements, and after the threshold value being compared to make it less common match.

C.

Edit the search, look for where or xswhere statements, and alter the threshold value being compared to make it a more common match.

D.

Modify the urgency table for this correlation search and add a new severity level to make notable events from this search less urgent.

Question 11

Adaptive response action history is stored in which index?

Options:

A.

cim_modactions

B.

modular_history

C.

cim_adaptiveactions

D.

modular_action_history

Page: 2 / 7
Exam Code: SPLK-3001
Exam Name: Splunk Enterprise Security Certified Admin Exam
Last Update: Nov 21, 2024
Questions: 99
SPLK-3001 pdf

SPLK-3001 PDF

$28  $80
SPLK-3001 Engine

SPLK-3001 Testing Engine

$33.25  $95
SPLK-3001 PDF + Engine

SPLK-3001 PDF + Testing Engine

$45.5  $130