Discount Offer
Go Back on SPLK-3001 Exam
Available in 1, 3, 6 and 12 Months Free Updates Plans
PDF: $15 $60

Test Engine: $20 $80

PDF + Engine: $25 $99



Pass exam with Dumps4free or we will provide you with three additional months of access for FREE.

SPLK-3001 Practice Test


Page 5 out of 20 Pages

Which of the following are data models used by ES? (Choose all that apply)


A.

Web


B.

Anomalies


C.

Authentication


D.

Network Traffic





A.
  

Web



C.
  

Authentication



D.
  

Network Traffic



Reference:
https://dev.splunk.com/enterprise/docs/developapps/enterprisesecurity/datamodelsusedbye
s/

ES apps and add-ons from $SPLUNK_HOME/etc/apps should be copied from the staging instance to what location on the cluster deployer instance?


A.

$SPLUNK_HOME/etc/master-apps/


B.

$SPLUNK_HOME/etc/system/local/


C.

$SPLUNK_HOME/etc/shcluster/apps


D.

$SPLUNK_HOME/var/run/searchpeers





C.
  

$SPLUNK_HOME/etc/shcluster/apps



Explanation:
The upgraded contents of the staging instance will be migrated back to the deployer and
deployed to the search head cluster members. On the staging instance, copy
$SPLUNK_HOME/etc/apps to
$SPLUNK_HOME/etc/shcluster/apps on the deployer. 1. On the deployer, remove any
deprecated apps or add-ons in $SPLUNK_HOME/etc/shcluster/apps that were removed
during the upgrade on staging. Confirm by reviewing the ES upgrade report generated on
staging, or by examining the apps moved into
$SPLUNK_HOME/etc/disabled-apps on staging

Which lookup table does the Default Account Activity Detected correlation search use to flag known default accounts?


A.

Administrative Identities


B.

Local User Intel


C.

Identities


D.

Privileged Accounts





C.
  

Identities



How is notable event urgency calculated?


A.

Asset priority and threat weight.


B.

Alert severity found by the correlation search.


C.

Asset or identity risk and severity found by the correlation search.


D.

Severity set by the correlation search and priority assigned to the associated asset or identity.





D.
  

Severity set by the correlation search and priority assigned to the associated asset or identity.



Reference: https://docs.splunk.com/Documentation/ES/6.1.0/User/Howurgencyisassigned

A customer site is experiencing poor performance. The UI response time is high and
searches take a very long time to run. Some operations time out and there are errors in the
scheduler logs, indicating too many concurrent searches are being started. 6 total
correlation searches are scheduled and they have already been tuned to weed out false
positives.
Which of the following options is most likely to help performance?


A.

Change the search heads to do local indexing of summary searches.


B.

Add heavy forwarders between the universal forwarders and indexers so inputs can be parsed before indexing.


C.

Increase memory and CPUs on the search head(s) and add additional indexers.


D.

If indexed realtime search is enabled, disable it for the notable index.





C.
  

Increase memory and CPUs on the search head(s) and add additional indexers.




Page 5 out of 20 Pages
Previous