Limited-Time Summer Sale 25% Discount Offer - Apply Coupon Code: Save25
Certs Blitz
See all results for ""
Home Exams
CRISC ISACA CISSP ISC2 200-301 Cisco SY0-701 CompTIA AZ-104 Microsoft AI-900 Microsoft AIGP IAPP 1Z0-1067-26 Oracle View All Exams →
Sign in Create account
SPLK-3001 EXAM PREPARATION

Prepare Smarter for the SPLK-3001 Exam

Build your exam confidence with flexible preparation resources designed around the latest SPLK-3001 exam objectives. Practice at your own pace using PDF questions, online exam simulations, or desktop practice software.

Download Exam View Entire Exam
Page: 1 / 1
Question #1 (Topic: Demo Questions)

The option to create a Short ID for a notable event is located where?

A.

The Additional Fields.

B.

The Event Details.

C.

The Contributing Events.

D.

The Description.

Correct Answer: B
Explanation:

 According to the Splunk Enterprise Security documentation, the option to create a Short ID for a notable event is located in the Event Details section of the notable event. The Event Details section shows the basic information about the notable event, such as title, description, urgency, owner, status, and others. It also provides a link to Create Short ID, which generates a 6-digit alphanumeric code that can be used to identify and share the notable event. The Short ID is appended to the URL of the Incident Review dashboard and can be used to filter the notable events by the Short ID field. See  Manually create a notable event in Splunk Enterprise Security  for more details. Therefore, the correct answer is B. The Event Details. References =  Manually create a notable event in Splunk Enterprise Security .

Question #2 (Topic: Demo Questions)

Following the Installation of ES, an admin configured Leers with the ©ss_uso r role the ability to close notable events. How would the admin restrict these users from being able to change the status of Resolved notable events to closed?

A.

From the Status Configuration window select the Resolved status. Remove ess_user from the status transitions for the closed status.

B.

From the Status Configuration windows select the closed status. Remove ess_use r from the status transitions for the Resolved status.

C.

In Enterprise Security, give the ess_user role the own Notable Events permission.

D.

From Splunk Access Controls, select the ess_user role and remove the edit_notabie_events capability.

Correct Answer: A
Explanation:

 According to the Splunk Enterprise Security documentation, the Status Configuration window allows you to customize the status values and transitions for notable events. You can define which roles can change the status of a notable event from one value to another, and which roles can view the notable events with a specific status. To restrict the users with the ess_user role from being able to change the status of Resolved notable events to closed, you need to do the following steps:

    On the Enterprise Security menu bar, select Configure > Incident Management > Status Configuration.

    In the Status Configuration window, select the Resolved status from the list of values.

    In the Status Transitions section, find the row for the closed status and click the Edit icon.

    In the Edit Status Transition dialog box, remove the ess_user role from the Roles field and click Save.

    Click Save Changes to apply the changes to the Status Configuration window.

This will prevent the users with the ess_user role from changing the status of any notable event from Resolved to closed. They will still be able to change the status of other notable events to closed, if they have the permission to do so. Therefore, the correct answer is A. From the Status Configuration window select the Resolved status. Remove ess_user from the status transitions for the closed status. References =  Customize status values and transitions for notable events .

Question #3 (Topic: Demo Questions)

What is the maximum recommended volume of indexing per day, per indexer, for a non-cloud (on-prem) ES deployment?

A.

50 GB

B.

100 GB

C.

300 GB

D.

500 MB

Correct Answer: B
Explanation:

According to the Splunk Reference Architecture document 1 , for ES, Splunk recommends sizing based on 80 to 100 GB ingest per indexer per day. This means an ES deployment with 2 TB daily ingest will require up to 20 indexers. This recommendation is for a non-cloud (on-prem) ES deployment.  For a cloud-based ES deployment, the recommended volume of indexing per day, per indexer, is 50 GB 2 . The other options, 300 GB and 500 MB, are not recommended by Splunk for ES deployments. References =

    Splunk Reference Architecture

    Performance reference for Splunk Enterprise Security

Question #4 (Topic: Demo Questions)

After data is ingested, which data management step is essential to ensure raw data can be accelerated by a Data Model and used by ES?

A.

Applying Tags.

B.

Normalization to Customer Standard.

C.

Normalization to the Splunk Common Information Model.

D.

Extracting Fields.

Correct Answer: C
Explanation:

After data is ingested, the data management step that is essential to ensure raw data can be accelerated by a data model and used by ES is normalization to the Splunk Common Information Model (CIM). The CIM is a standard and consistent way of naming and structuring the fields and tags for different types of data, such as network, web, email, authentication, and malware. The CIM allows you to use the same search queries and dashboards across different data sources, even if they have different formats or schemas. Normalizing data to the CIM involves mapping the raw data fields and tags to the CIM fields and tags using technology add-ons. Technology add-ons are Splunk apps that provide the necessary configurations and extractions for specific data sources. By normalizing data to the CIM, you can enable data model acceleration for the data models that use the CIM fields and tags. Data model acceleration is a feature that speeds up searches and reports that use data models by pre-computing and storing the results of the data model queries. Data model acceleration is required for most of the dashboards and correlation searches in Splunk Enterprise Security. References =

    Data models in the Splunk Common Information Model

    Data model acceleration

Question #5 (Topic: Demo Questions)

When investigating, what is the best way to store a newly-found IOC?

A.

Paste it into Notepad.

B.

Click the “Add IOC” button.

C.

Click the “Add Artifact” button.

D.

Add it in a text note to the investigation.

Correct Answer: C
Explanation:

When investigating an incident in Splunk Enterprise Security, the best way to store a newly-found IOC (indicator of compromise) is to click the “Add Artifact” button. This button allows you to add an artifact to the current investigation from any dashboard or search result. An artifact is a piece of machine data that indicates risk, such as an IP address, a domain name, a file hash, or a user name. By adding an artifact to the investigation, you can enrich the context of the incident, track the artifact across multiple data sources, and share the artifact with other analysts.  You can also use the artifact to create a threat intelligence indicator, which can be used to detect and alert on future threats 1 2 .  References  =  1 : Add artifacts to an investigation - Splunk Documentation.  2 : About investigations in Splunk Enterprise Security - Splunk Documentation.

Download Exam
Page: 1 / 1
Next Page