Exam 6: Splunk IT Service Intelligence Certified Admin

arrow
  • Select Tags
search iconSearch Question
flashcardsStudy Flashcards
  • Select Tags

When using distributed configuration management to create the Splunk_TA_ForIndexers package, which three files can be included?

Free
(Multiple Choice)
4.8/5
(42)
Correct Answer:
Verified

A

Which of the following are examples of sources for events in the endpoint security domain dashboards?

Free
(Multiple Choice)
4.8/5
(29)
Correct Answer:
Verified

D

Which column in the Asset or Identity list is combined with event security to make a notable event's urgency?

Free
(Multiple Choice)
4.8/5
(36)
Correct Answer:
Verified

B

An administrator is provisioning one search head prior to installing ES. What are the reference minimum requirements for OS, CPU, and RAM for that machine?

(Multiple Choice)
4.8/5
(39)

Which of the following steps will make the Threat Activity dashboard the default landing page in ES?

(Multiple Choice)
4.8/5
(31)

The option to create a Short ID for a notable event is located where?

(Multiple Choice)
4.8/5
(42)

How is it possible to navigate to the ES graphical Navigation Bar editor?

(Multiple Choice)
4.8/5
(36)

What does the summariesonly=true option do for a correlation search?

(Multiple Choice)
4.7/5
(28)

When ES content is exported, an app with a .spl extension is automatically created. What is the best practice when exporting and importing updates to ES content?

(Multiple Choice)
5.0/5
(42)

Which two fields combine to create the Urgency of a notable event?

(Multiple Choice)
4.8/5
(37)

Which of the following is a key feature of a glass table?

(Multiple Choice)
4.7/5
(35)

When investigating, what is the best way to store a newly-found IOC?

(Multiple Choice)
4.9/5
(39)

What does the risk framework add to an object (user, server or other type) to indicate increased risk?

(Multiple Choice)
4.9/5
(27)

The Add-On Builder creates Splunk Apps that start with what?

(Multiple Choice)
4.9/5
(40)

What is the bar across the bottom of any ES window?

(Multiple Choice)
4.9/5
(31)

Which of the following ES features would a security analyst use while investigating a network anomaly notable?

(Multiple Choice)
4.9/5
(30)

A newly built custom dashboard needs to be available to a team of security analysts in ES. How is it possible to integrate the new dashboard?

(Multiple Choice)
4.9/5
(43)

Which of the following features can the Add-on Builder configure in a new add-on?

(Multiple Choice)
4.9/5
(32)

Accelerated data requires approximately how many times the daily data volume of additional storage space per year?

(Multiple Choice)
4.8/5
(38)

After installing Enterprise Security, the distributed configuration management tool can be used to create which app to configure indexers?

(Multiple Choice)
4.9/5
(46)
Showing 1 - 20 of 72
close modal

Filters

  • Essay(0)
  • Multiple Choice(0)
  • Short Answer(0)
  • True False(0)
  • Matching(0)