Free SPLK-3001 Exam Braindumps (page: 7)

Page 6 of 22

What does the Security Posture dashboard display?

  1. Active investigations and their status.
  2. A high-level overview of notable events.
  3. Current threats being tracked by the SO
  4. A display of the status of security tools.

Answer(s): B

Explanation:

The Security Posture dashboard is designed to provide high-level insight into the notable events across all domains of your deployment, suitable for display in a Security Operations Center (SOC). This dashboard shows all events from the past 24 hours, along with the trends over the past 24 hours, and provides real-time event information and updates.


Reference:

https://docs.splunk.com/Documentation/ES/6.1.0/User/SecurityPosturedashboard



“10.22.63.159”, “websvr4”, and “00:26:08:18: CF:1D” would be matched against what in ES?

  1. A user.
  2. A device.
  3. An asset.
  4. An identity.

Answer(s): B



How should an administrator add a new lookup through the ES app?

  1. Upload the lookup file in Settings -> Lookups -> Lookup Definitions
  2. Upload the lookup file in Settings -> Lookups -> Lookup table files
  3. Add the lookup file to /etc/apps/SplunkEnterpriseSecuritySuite/lookups
  4. Upload the lookup file using Configure -> Content Management -> Create New Content -> Managed Lookup

Answer(s): D


Reference:

https://docs.splunk.com/Documentation/ES/6.1.0/Admin/Createlookups



Glass tables can display static images and text, the results of ad-hoc searches, and which of the following objects?

  1. Lookup searches.
  2. Summarized data.
  3. Security metrics.
  4. Metrics store searches.

Answer(s): C


Reference:

https://docs.splunk.com/Documentation/ES/6.1.0/User/CreateGlassTable






Post your Comments and Discuss Splunk® SPLK-3001 exam with other Community members:

SPLK-3001 Discussions & Posts