Splunk SPLK-3001 Exam questions with
verified answers
A customer site is experiencing poor performance. The UI
response time is high and searches take a very long time
to run. Some operations time out and there are errors in
the scheduler logs, indicating too many concurrent
searches are being started. 6 total correlation searches
are scheduled and they have already been tuned to weed
out false positives.
Which of the following options is most likely to help
performance?
A. Change the search heads to do local indexing of
summary searches.
B. Incre
B
Which of the following threat intelligence types can ES
download? (Choose all that apply.)
· A. Text
· B. STIX/TAXII
,· C. VulnScanSPL
· D. SplunkEnterpriseThreatGenerator
AB
When investigating, what is the best way to store a
newly-found IOC?
A. Paste it into Notepad.
B. Click the Add IOC button.
C. Click the Add Artifact button.
D. Add it in a text note to the investigation.
C
At what point in the ES installation process should
Splunk_TA_ForIndexers.spl be deployed to the indexers?
· A. When adding apps to the deployment server.
· B. Splunk_TA_ForIndexers.spl is installed first.
· C. After installing ES on the search head(s) and running
the distributed configuration management tool.
,· D. Splunk_TA_ForIndexers.spl is only installed on indexer
cluster sites using the cluster master and the splunk
apply cluster-bundle command.
C
Where is it possible to export content, such as correlation
searches, from ES?
· A. Content exporter
· B. Configure -> Content Management
· C. Export content dashboard
· D. Settings Menu -> ES -> Export
B
Enterprise Security dashboards primarily pull data from
what type of knowledge object?
· A. Tstats
· B. KV Store
· C. Data models
· D. Dynamic lookups
C
, The Add-On Builder creates Splunk Apps that start with
what?
A. DA-
B. SA-
C. TA-
D. App-
C
When creating custom correlation searches, what format
is used to embed field values in the title, description, and
drill-down fields of a notable event?
A. $fieldname$
B. ג€fieldnameג€
C. %fieldname%
D. _fieldname_
A
verified answers
A customer site is experiencing poor performance. The UI
response time is high and searches take a very long time
to run. Some operations time out and there are errors in
the scheduler logs, indicating too many concurrent
searches are being started. 6 total correlation searches
are scheduled and they have already been tuned to weed
out false positives.
Which of the following options is most likely to help
performance?
A. Change the search heads to do local indexing of
summary searches.
B. Incre
B
Which of the following threat intelligence types can ES
download? (Choose all that apply.)
· A. Text
· B. STIX/TAXII
,· C. VulnScanSPL
· D. SplunkEnterpriseThreatGenerator
AB
When investigating, what is the best way to store a
newly-found IOC?
A. Paste it into Notepad.
B. Click the Add IOC button.
C. Click the Add Artifact button.
D. Add it in a text note to the investigation.
C
At what point in the ES installation process should
Splunk_TA_ForIndexers.spl be deployed to the indexers?
· A. When adding apps to the deployment server.
· B. Splunk_TA_ForIndexers.spl is installed first.
· C. After installing ES on the search head(s) and running
the distributed configuration management tool.
,· D. Splunk_TA_ForIndexers.spl is only installed on indexer
cluster sites using the cluster master and the splunk
apply cluster-bundle command.
C
Where is it possible to export content, such as correlation
searches, from ES?
· A. Content exporter
· B. Configure -> Content Management
· C. Export content dashboard
· D. Settings Menu -> ES -> Export
B
Enterprise Security dashboards primarily pull data from
what type of knowledge object?
· A. Tstats
· B. KV Store
· C. Data models
· D. Dynamic lookups
C
, The Add-On Builder creates Splunk Apps that start with
what?
A. DA-
B. SA-
C. TA-
D. App-
C
When creating custom correlation searches, what format
is used to embed field values in the title, description, and
drill-down fields of a notable event?
A. $fieldname$
B. ג€fieldnameג€
C. %fieldname%
D. _fieldname_
A