SPLK-3001 Dumps

SPLK-3001 Free Practice Test

Splunk SPLK-3001: Splunk Enterprise Security Certified Admin Exam

QUESTION 16

Which correlation search feature is used to throttle the creation of notable events?

Correct Answer: C
Reference: https://docs.splunk.com/Documentation/ES/6.1.0/Admin/Configurecorrelationsearches

QUESTION 17

What does the risk framework add to an object (user, server or other type) to indicate increased risk?

Correct Answer: C
Reference: https://docs.splunk.com/Documentation/ES/6.1.0/User/RiskScoring

QUESTION 18

Which settings indicated that the correlation search will be executed as new events are indexed?

Correct Answer: C
Reference: https://docs.splunk.com/Documentation/ES/6.1.0/Admin/Configurecorrelationsearches

QUESTION 19

When ES content is exported, an app with a .spl extension is automatically created. What is the best practice when exporting and importing updates to ES content?

Correct Answer: A

QUESTION 20

Which of the following are examples of sources for events in the endpoint security domain dashboards?

Correct Answer: D
Reference: https://docs.splunk.com/Documentation/ES/6.1.0/User/EndpointProtectionDomaindashboards