Splunk SPLK-3001 Splunk Enterprise Security Certified Admin Exam Practice Test

Page: 1 / 14
Total 99 questions
Question 1

Which columns in the Assets lookup are used to identify an asset in an event?



Answer : C


Question 2

Which two fields combine to create the Urgency of a notable event?



Answer : A


Question 3

A security manager has been working with the executive team en long-range security goals. A primary goal for the team Is to Improve managing user risk in the organization. Which of the following ES features can help identify users accessing inappropriate web sites?



Answer : C


Question 4

A newly built custom dashboard needs to be available to a team of security analysts In ES. How is It possible to Integrate the new dashboard?



Answer : C


Question 5

Where should an ES search head be installed?



Answer : B


Question 6

Which component normalizes events?



Answer : A


Question 7

Which of the following ES features would a security analyst use while investigating a network anomaly notable?



Answer : D


Page:    1 / 14   
Total 99 questions