Go Back on SPLK-3001 Exam
Available in 1, 3, 6 and 12 Months Free Updates Plans
PDF: $15 $60

Test Engine: $20 $80

PDF + Engine: $25 $99

SPLK-3001 Practice Test


Page 1 out of 20 Pages

Which indexes are searched by default for CIM data models?


A.

notable and default


B.

summary and notable


C.

_internal and summary


D.

All indexes





D.
  

All indexes



Reference: https://answers.splunk.com/answers/600354/indexes-searched-by-cim-datamodels.
html

What tools does the Risk Analysis dashboard provide?


A.

High risk threats.


B.

Notable event domains displayed by risk score.


C.

A display of the highest risk assets and identities.


D.

Key indicators showing the highest probability correlation searches in the environment





C.
  

A display of the highest risk assets and identities.



Reference: https://docs.splunk.com/Documentation/ES/6.1.0/User/RiskAnalysis

Which two fields combine to create the Urgency of a notable event?


A.

Priority and Severity.


B.

Priority and Criticality.


C.

Criticality and Severity.


D.

Precedence and Time.





A.
  

Priority and Severity.



Reference: https://docs.splunk.com/Documentation/ES/6.4.1/User/Howurgencyisassigned

Where is the Add-On Builder available from?


A.

GitHub


B.

SplunkBase


C.

www.splunk.com


D.

The ES installation package





B.
  

SplunkBase



Reference:
https://docs.splunk.com/Documentation/AddonBuilder/3.0.1/UserGuide/Installation

Where are attachments to investigations stored?


A.

KV Store


B.

notable index


C.

attachments.csv lookup


D.

<splunk_home>/etc/apps/SA-Investigations/default/ui/views/attachments





A.
  

KV Store



Reference: https://docs.splunk.com/Documentation/ES/6.1.0/Admin/Manageinvestigations


Page 1 out of 20 Pages