Splunk SPLK-3001 Splunk Enterprise Security Certified Admin Exam Practice Test

Page: 1 / 14
Total 99 questions
Question 1

What does the summariesonly=true option do for a correlation search?



Answer : A


Question 2

Which lookup table does the Default Account Activity Detected correlation search use to flag known default accounts?



Answer : C


Question 3

What is the bar across the bottom of any ES window?



Answer : B


Question 4

Following the Installation of ES, an admin configured Leers with the ss_uso r role the ability to close notable events. How would the admin restrict these users from being able to change the status of Resolved notable events to closed?



Answer : B


Question 5

Which of these Is a benefit of data normalization?



Answer : A


Question 6

Which component normalizes events?



Answer : A


Question 7

Which of the following ES features would a security analyst use while investigating a network anomaly notable?



Answer : D


Page:    1 / 14   
Total 99 questions