SPLK-3001 Dumps

SPLK-3001 Free Practice Test

Splunk SPLK-3001: Splunk Enterprise Security Certified Admin Exam

QUESTION 6

Which of the following threat intelligence types can ES download? (Choose all that apply)

Correct Answer: B
Reference: https://docs.splunk.com/Documentation/ES/6.1.0/Admin/Downloadthreatfeed

QUESTION 7

What kind of value is in the red box in this picture?

Correct Answer: C
Reference: https://docs.splunk.com/Documentation/Splunk/8.0.2/Data/FormateventsforHTTPEventCollector

QUESTION 8

What feature of Enterprise Security downloads threat intelligence data from a web server?

Correct Answer: B

QUESTION 9

An administrator is provisioning one search head prior to installing ES. What are the reference minimum requirements for OS, CPU, and RAM for that machine?

Correct Answer: C
Reference: https://docs.splunk.com/Documentation/Splunk/8.0.2/Capacity/Referencehardware

QUESTION 10

An administrator is asked to configure an “Nslookup” adaptive response action, so that it appears as a selectable option in the notable event’s action menu when an analyst is working in the Incident Review dashboard. What steps would the administrator take to configure this option?

Correct Answer: D