Exam 6: Splunk IT Service Intelligence Certified Admin

arrow
  • Select Tags
search iconSearch Question
flashcardsStudy Flashcards
  • Select Tags

What role should be assigned to a security team member who will be taking ownership of notable events in the incident review dashboard?

(Multiple Choice)
4.9/5
(35)

At what point in the ES installation process should Splunk_TA_ForIndexers.spl be deployed to the indexers?

(Multiple Choice)
4.8/5
(38)

Which of the following actions can improve overall search performance?

(Multiple Choice)
4.8/5
(41)

Which of the following actions would not reduce the number of false positives from a correlation search?

(Multiple Choice)
4.7/5
(43)

Which of the following is an adaptive action that is configured by default for ES?

(Multiple Choice)
4.9/5
(34)

What feature of Enterprise Security downloads threat intelligence data from a web server?

(Multiple Choice)
4.9/5
(39)

Which setting is used in indexes.conf to specify alternate locations for accelerated storage?

(Multiple Choice)
4.7/5
(44)

How should an administrator add a new lookup through the ES app?

(Multiple Choice)
4.8/5
(34)

To observe what network services are in use in a network's activity overall, which of the following dashboards in Enterprise Security will contain the most relevant data?

(Multiple Choice)
5.0/5
(44)

Which of the following are data models used by ES? (Choose all that apply.)

(Multiple Choice)
4.9/5
(34)

What is the default schedule for accelerating ES Datamodels?

(Multiple Choice)
4.8/5
(38)

What are the steps to add a new column to the Notable Event table in the Incident Review dashboard?

(Multiple Choice)
4.9/5
(33)

When installing Enterprise Security, what should be done after installing the add-ons necessary for normalizing data?

(Multiple Choice)
4.9/5
(36)

Which settings indicated that the correlation search will be executed as new events are indexed?

(Multiple Choice)
5.0/5
(37)

Which indexes are searched by default for CIM data models?

(Multiple Choice)
4.7/5
(41)

Which of the following actions may be necessary before installing ES?

(Multiple Choice)
4.8/5
(33)

An administrator wants to ensure that none of the ES indexed data could be compromised through tampering. What feature would satisfy this requirement?

(Multiple Choice)
4.9/5
(37)

A set of correlation searches are enabled at a new ES installation, and results are being monitored. One of the correlation searches is generating many notable events which, when evaluated, are determined to be false positives. What is a solution for this issue?

(Multiple Choice)
4.7/5
(34)

What do threat gen searches produce?

(Multiple Choice)
4.7/5
(37)

Following the installation of ES, an admin configured users with the ess_user role the ability to close notable events. How would the admin restrict these users from being able to change the status of Resolved notable events to Closed ?

(Multiple Choice)
4.9/5
(35)
Showing 21 - 40 of 72
close modal

Filters

  • Essay(0)
  • Multiple Choice(0)
  • Short Answer(0)
  • True False(0)
  • Matching(0)