Question No : 1
How is notable event urgency calculated?
답을 확인하기
정답: Explanation:
Reference: https://docs.splunk.com/Documentation/ES/6.1.0/User/Howurgencyisassigned
Question No : 2
If a username does not match the ‘identity’ column in the identities list, which column is checked next?
답을 확인하기
정답:
Question No : 3
Which of these Is a benefit of data normalization?
답을 확인하기
정답:
Question No : 4
To which of the following should the ES application be uploaded?
답을 확인하기
정답: Explanation:
Reference: https://docs.splunk.com/Documentation/ES/6.1.0/Install/InstallEnterpriseSecuritySHC
Question No : 5
A customer site is experiencing poor performance. The UI response time is high and searches take a very long time to run. Some operations time out and there are errors in the scheduler logs, indicating too many concurrent searches are being started. 6 total correlation searches are scheduled and they have already been tuned to weed out false positives.
Which of the following options is most likely to help performance?
답을 확인하기
정답:
Question No : 6
Which setting is used in indexes.conf to specify alternate locations for accelerated storage?
답을 확인하기
정답: Explanation:
Reference: https://docs.splunk.com/Documentation/Splunk/8.0.2/Knowledge/Acceleratedatamodels
Question No : 7
How is it possible to navigate to the ES graphical Navigation Bar editor?
답을 확인하기
정답: Explanation:
Reference: https://docs.splunk.com/Documentation/ES/6.1.0/Admin/Customizemenubar#Restore_the_default_navigation
Question No : 8
Which of the following is an adaptive action that is configured by default for ES?
답을 확인하기
정답:
Question No : 9
Where should an ES search head be installed?
답을 확인하기
정답: Explanation:
Reference: https://docs.splunk.com/Documentation/ES/6.4.1/Admin/Export
Question No : 10
Which of the following steps will make the Threat Activity dashboard the default landing page in ES?
답을 확인하기
정답:
Question No : 11
Which argument to the | tstats command restricts the search to summarized data only?
답을 확인하기
정답: Explanation:
Reference: https://docs.splunk.com/Documentation/Splunk/8.0.2/Knowledge/Acceleratedatamodels
Question No : 12
The option to create a Short ID for a notable event is located where?
답을 확인하기
정답: Explanation:
https://docs.splunk.com/Documentation/ES/6.4.1/User/Takeactiononanotableevent
Question No : 13
Glass tables can display static images and text, the results of ad-hoc searches, and which of the following objects?
답을 확인하기
정답: Explanation:
Reference: https://docs.splunk.com/Documentation/ES/6.1.0/User/CreateGlassTable
Question No : 14
What is the bar across the bottom of any ES window?
답을 확인하기
정답: Explanation:
Reference: https://docs.splunk.com/Documentation/ES/6.4.1/User/Startaninvestigation
Question No : 15
The Add-On Builder creates Splunk Apps that start with what?
답을 확인하기
정답: Explanation:
Reference: https://dev.splunk.com/enterprise/docs/developapps/enterprisesecurity/abouttheessolution/