Summer Special 60% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: bestdeal

Free Splunk SPLK-3001 Practice Exam with Questions & Answers | Set: 3

Questions 21

Which two fields combine to create the Urgency of a notable event?

Options:
A.

Priority and Severity.

B.

Priority and Criticality.

C.

Criticality and Severity.

D.

Precedence and Time.

Splunk SPLK-3001 Premium Access
Questions 22

When creating custom correlation searches, what format is used to embed field values in the title, description, and drill-down fields of a notable event?

Options:
A.

$fieldname$

B.

“fieldname”

C.

%fieldname%

D.

_fieldname_

Questions 23

Which of the following steps will make the Threat Activity dashboard the default landing page in ES?

Options:
A.

From the Edit Navigation page, drag and drop the Threat Activity view to the top of the page.

B.

From the Preferences menu for the user, select Enterprise Security as the default application.

C.

From the Edit Navigation page, click the 'Set this as the default view" checkmark for Threat Activity.

D.

Edit the Threat Activity view settings and checkmark the Default View option.

Questions 24

What are the steps to add a new column to the Notable Event table in the Incident Review dashboard?

Options:
A.

Configure -> Incident Management -> Notable Event Statuses

B.

Configure -> Content Management -> Type: Correlation Search

C.

Configure -> Incident Management -> Incident Review Settings -> Event Management

D.

Configure -> Incident Management -> Incident Review Settings -> Table Attributes

Questions 25

Which of the following ES features would a security analyst use while investigating a network anomaly notable?

Options:
A.

Correlation editor.

B.

Key indicator search.

C.

Threat download dashboard.

D.

Protocol intelligence dashboard.

Questions 26

Accelerated data requires approximately how many times the daily data volume of additional storage space per year?

Options:
A.

3.4

B.

5.7

C.

1.0

D.

2.5

Questions 27

Who can delete an investigation?

Options:
A.

ess_admin users only.

B.

The investigation owner only.

C.

The investigation owner and ess-admin.

D.

The investigation owner and collaborators.

Questions 28

How is it possible to navigate to the ES graphical Navigation Bar editor?

Options:
A.

Configure -> Navigation Menu

B.

Configure -> General -> Navigation

C.

Settings -> User Interface -> Navigation -> Click on “Enterprise Security”

D.

Settings -> User Interface -> Navigation Menus -> Click on “default” next to SplunkEnterpriseSecuritySuite

Questions 29

Following the installation of ES, an admin configured users with the ess_user role the ability to close notable events.

How would the admin restrict these users from being able to change the status of Resolved notable events to Closed?

Options:
A.

In Enterprise Security, give the ess_user role the Own Notable Events permission.

B.

From the Status Configuration window select the Closed status. Remove ess_user from the status

transitions for the Resolved status.

C.

From the Status Configuration window select the Resolved status. Remove ess_user from the status transitions for the Closed status.

D.

From Splunk Access Controls, select the ess_user role and remove the edit_notable_events capability.