Exam 6: Splunk IT Service Intelligence Certified Admin
Exam 1: Splunk Core Certified User187 Questions
Exam 2: Splunk Enterprise Certified Admin79 Questions
Exam 3: Splunk Certified Developer84 Questions
Exam 4: Splunk Enterprise Certified Architect42 Questions
Exam 5: Splunk Enterprise Security Certified Admin85 Questions
Exam 6: Splunk IT Service Intelligence Certified Admin72 Questions
Exam 7: Splunk Core Certified Consultant62 Questions
Select questions type
What role should be assigned to a security team member who will be taking ownership of notable events in the incident review dashboard?
(Multiple Choice)
4.9/5
(35)
At what point in the ES installation process should Splunk_TA_ForIndexers.spl be deployed to the indexers?
(Multiple Choice)
4.8/5
(38)
Which of the following actions can improve overall search performance?
(Multiple Choice)
4.8/5
(41)
Which of the following actions would not reduce the number of false positives from a correlation search?
(Multiple Choice)
4.7/5
(43)
Which of the following is an adaptive action that is configured by default for ES?
(Multiple Choice)
4.9/5
(34)
What feature of Enterprise Security downloads threat intelligence data from a web server?
(Multiple Choice)
4.9/5
(39)
Which setting is used in indexes.conf to specify alternate locations for accelerated storage?
(Multiple Choice)
4.7/5
(44)
How should an administrator add a new lookup through the ES app?
(Multiple Choice)
4.8/5
(34)
To observe what network services are in use in a network's activity overall, which of the following dashboards in Enterprise Security will contain the most relevant data?
(Multiple Choice)
5.0/5
(44)
Which of the following are data models used by ES? (Choose all that apply.)
(Multiple Choice)
4.9/5
(34)
What is the default schedule for accelerating ES Datamodels?
(Multiple Choice)
4.8/5
(38)
What are the steps to add a new column to the Notable Event table in the Incident Review dashboard?
(Multiple Choice)
4.9/5
(33)
When installing Enterprise Security, what should be done after installing the add-ons necessary for normalizing data?
(Multiple Choice)
4.9/5
(36)
Which settings indicated that the correlation search will be executed as new events are indexed?
(Multiple Choice)
5.0/5
(37)
Which of the following actions may be necessary before installing ES?
(Multiple Choice)
4.8/5
(33)
An administrator wants to ensure that none of the ES indexed data could be compromised through tampering. What feature would satisfy this requirement?
(Multiple Choice)
4.9/5
(37)
A set of correlation searches are enabled at a new ES installation, and results are being monitored. One of the correlation searches is generating many notable events which, when evaluated, are determined to be false positives. What is a solution for this issue?
(Multiple Choice)
4.7/5
(34)
Following the installation of ES, an admin configured users with the ess_user role the ability to close notable events. How would the admin restrict these users from being able to change the status of Resolved notable events to Closed ?
(Multiple Choice)
4.9/5
(35)
Showing 21 - 40 of 72
Filters
- Essay(0)
- Multiple Choice(0)
- Short Answer(0)
- True False(0)
- Matching(0)