Summer Special 60% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: bestdeal

Free Splunk SPLK-3001 Practice Exam with Questions & Answers

Questions 1

Which data model populated the panels on the Risk Analysis dashboard?

Options:
A.

Risk

B.

Audit

C.

Domain analysis

D.

Threat intelligence

Splunk SPLK-3001 Premium Access
Questions 2

Which of the following are the default ports that must be configured for Splunk Enterprise Security to function?

Options:
A.

SplunkWeb (8068), Splunk Management (8089), KV Store (8000)

B.

SplunkWeb (8390), Splunk Management (8323), KV Store (8672)

C.

SplunkWeb (8000), Splunk Management (8089), KV Store (8191)

D.

SplunkWeb (8043), Splunk Management (8088), KV Store (8191)

Questions 3

ES needs to be installed on a search head with which of the following options?

Options:
A.

No other apps.

B.

Any other apps installed.

C.

All apps removed except for TA-*.

D.

Only default built-in and CIM-compliant apps.

Questions 4

“10.22.63.159”, “websvr4”, and “00:26:08:18: CF:1D” would be matched against what in ES?

Options:
A.

A user.

B.

A device.

C.

An asset.

D.

An identity.

Questions 5

Which of the following is a key feature of a glass table?

Options:
A.

Rigidity.

B.

Customization.

C.

Interactive investigations.

D.

Strong data for later retrieval.

Questions 6

Where is it possible to export content, such as correlation searches, from ES?

Options:
A.

Content exporter

B.

Configure -> Content Management

C.

Export content dashboard

D.

Settings Menu -> ES -> Export

Questions 7

If a username does not match the ‘identity’ column in the identities list, which column is checked next?

Options:
A.

Email.

B.

Nickname

C.

IP address.

D.

Combination of Last Name, First Name.

Questions 8

Which of the following actions would not reduce the number of false positives from a correlation search?

Options:
A.

Reducing the severity.

B.

Removing throttling fields.

C.

Increasing the throttling window.

D.

Increasing threshold sensitivity.

Questions 9

What does the Security Posture dashboard display?

Options:
A.

Active investigations and their status.

B.

A high-level overview of notable events.

C.

Current threats being tracked by the SOC.

D.

A display of the status of security tools.

Questions 10

Which of the following lookup types in Enterprise Security contains information about known hostile IP addresses?

Options:
A.

Security domains.

B.

Threat intel.

C.

Assets.

D.

Domains.