SPLK-3001 Dumps

SPLK-3001 Free Practice Test

Splunk SPLK-3001: Splunk Enterprise Security Certified Admin Exam

QUESTION 11

Who can delete an investigation?

Correct Answer: A
Reference: https://docs.splunk.com/Documentation/ES/6.1.0/Admin/Manageinvestigations

QUESTION 12

Which of the following actions can improve overall search performance?

Correct Answer: A

QUESTION 13

How is it possible to navigate to the list of currently-enabled ES correlation searches?

Correct Answer: A
Reference: https://docs.splunk.com/Documentation/ES/6.1.0/Admin/Listcorrelationsearches

QUESTION 14

“10.22.63.159”, “websvr4”, and “00:26:08:18: CF:1D” would be matched against what in ES?

Correct Answer: B

QUESTION 15

How is notable event urgency calculated?

Correct Answer: D
Reference: https://docs.splunk.com/Documentation/ES/6.1.0/User/Howurgencyisassigned