Free SPLK-3001 Exam Braindumps (page: 8)

Page 7 of 22

Which of the following is a key feature of a glass table?

  1. Rigidity.
  2. Customization.
  3. Interactive investigations.
  4. Strong data for later retrieval.

Answer(s): B



An administrator is asked to configure an “Nslookup” adaptive response action, so that it appears as a selectable option in the notable event’s action menu when an analyst is working in the Incident Review dashboard.

What steps would the administrator take to configure this option?

  1. Configure -> Content Management -> Type: Correlation Search -> Notable -> Nslookup
  2. Configure -> Type: Correlation Search -> Notable -> Recommended Actions -> Nslookup
  3. Configure -> Content Management -> Type: Correlation Search -> Notable -> Next Steps -> Nslookup
  4. Configure -> Content Management -> Type: Correlation Search -> Notable -> Recommended Actions -> Nslookup

Answer(s): D



What are the steps to add a new column to the Notable Event table in the Incident Review dashboard?

  1. Configure -> Incident Management -> Notable Event Statuses
  2. Configure -> Content Management -> Type: Correlation Search
  3. Configure -> Incident Management -> Incident Review Settings -> Event Management
  4. Configure -> Incident Management -> Incident Review Settings -> Table Attributes

Answer(s): C


Reference:

https://docs.splunk.com/Documentation/ES/6.1.0/Admin/Customizenotables



To observe what network services are in use in a network’s activity overall, which of the following dashboards in Enterprise Security will contain the most relevant data?

  1. Intrusion Center
  2. Protocol Analysis
  3. User Intelligence
  4. Threat Intelligence

Answer(s): A


Reference:

https://docs.splunk.com/Documentation/ES/6.1.0/User/NetworkProtectionDomaindashboards






Post your Comments and Discuss Splunk® SPLK-3001 exam with other Community members:

SPLK-3001 Discussions & Posts