Exam 6: Splunk IT Service Intelligence Certified Admin
Exam 1: Splunk Core Certified User187 Questions
Exam 2: Splunk Enterprise Certified Admin79 Questions
Exam 3: Splunk Certified Developer84 Questions
Exam 4: Splunk Enterprise Certified Architect42 Questions
Exam 5: Splunk Enterprise Security Certified Admin85 Questions
Exam 6: Splunk IT Service Intelligence Certified Admin72 Questions
Exam 7: Splunk Core Certified Consultant62 Questions
Select questions type
When using distributed configuration management to create the Splunk_TA_ForIndexers package, which three files can be included?
Free
(Multiple Choice)
4.8/5
(42)
Correct Answer:
A
Which of the following are examples of sources for events in the endpoint security domain dashboards?
Free
(Multiple Choice)
4.8/5
(29)
Correct Answer:
D
Which column in the Asset or Identity list is combined with event security to make a notable event's urgency?
Free
(Multiple Choice)
4.8/5
(36)
Correct Answer:
B
An administrator is provisioning one search head prior to installing ES. What are the reference minimum requirements for OS, CPU, and RAM for that machine?
(Multiple Choice)
4.8/5
(39)
Which of the following steps will make the Threat Activity dashboard the default landing page in ES?
(Multiple Choice)
4.8/5
(31)
The option to create a Short ID for a notable event is located where?
(Multiple Choice)
4.8/5
(42)
How is it possible to navigate to the ES graphical Navigation Bar editor?
(Multiple Choice)
4.8/5
(36)
What does the summariesonly=true option do for a correlation search?
(Multiple Choice)
4.7/5
(28)
When ES content is exported, an app with a .spl extension is automatically created. What is the best practice when exporting and importing updates to ES content?
(Multiple Choice)
5.0/5
(42)
Which two fields combine to create the Urgency of a notable event?
(Multiple Choice)
4.8/5
(37)
When investigating, what is the best way to store a newly-found IOC?
(Multiple Choice)
4.9/5
(39)
What does the risk framework add to an object (user, server or other type) to indicate increased risk?
(Multiple Choice)
4.9/5
(27)
The Add-On Builder creates Splunk Apps that start with what?
(Multiple Choice)
4.9/5
(40)
Which of the following ES features would a security analyst use while investigating a network anomaly notable?
(Multiple Choice)
4.9/5
(30)
A newly built custom dashboard needs to be available to a team of security analysts in ES. How is it possible to integrate the new dashboard?
(Multiple Choice)
4.9/5
(43)
Which of the following features can the Add-on Builder configure in a new add-on?
(Multiple Choice)
4.9/5
(32)
Accelerated data requires approximately how many times the daily data volume of additional storage space per year?
(Multiple Choice)
4.8/5
(38)
After installing Enterprise Security, the distributed configuration management tool can be used to create which app to configure indexers?
(Multiple Choice)
4.9/5
(46)
Showing 1 - 20 of 72
Filters
- Essay(0)
- Multiple Choice(0)
- Short Answer(0)
- True False(0)
- Matching(0)