Practice Test 1 Flashcards
The Remote Access panel within the User Activity dashboard is not populating with the most recent hour of data.
What data model should be checked for potential errors such as skipped searches?
Authentication
In order to include an eventtype in a data model node, what is the next step after extracting the correct fields?
Run the correct search.
What role should be assigned to a security team member who will be taking ownership of notable events in the incident review dashboard?
ess_analyst
Which column in the Asset or Identity list is combined with event security to make a notable event’s urgency?
Priority
The Add-On Builder creates Splunk Apps that start with what?
TA-
Which of the following are examples of sources for events in the endpoint security domain dashboards?
Workstations, notebooks, and point-of-sale systems.
When creating custom correlation searches, what format is used to embed field values in the title, description, and drill-down fields of a notable event?
$fieldname$
What feature of Enterprise Security downloads threat intelligence data from a web server?
Threat Download Manager
What does the risk framework add to an object (user, server or other type) to indicate increased risk?
A risk score.
Which indexes are searched by default for CIM data models?
All indexes
Which setting is used in indexes.conf to specify alternate locations for accelerated storage?
tstatsHomePath
Which of the following is a way to test for a property normalized data model?
Run a | datamodel search, compare results to the CIM documentation for the datamodel.
Which argument to the | tstats command restricts the search to summarized data only?
summariesonly=t
When investigating, what is the best way to store a newly-found IOC?
Click the Add Artifact.
How is it possible to navigate to the list of currently-enabled ES correlation searches?
Configure -> Content Management -> Select Type Correlation and Status Enabled
Which of the following is a risk of using the Auto Deployment feature of Distributed Configuration Management to distribute indexes.conf?
Indexers have different settings.
Which of the following are data models used by ES? (Choose all that apply.)
Web,Authentication, and Network Traffic
At what point in the ES installation process should Splunk_TA_ForIndexers.spl be deployed to the indexers?
After installing ES on the search head(s) and running the distributed configuration management tool.
Which correlation search feature is used to throttle the creation of notable events?
Window duration.
Both Recommended Actions
and Adaptive Response Actions
use adaptive response. How do they differ?
Recommended Actions show a list of Adaptive Responses to an analyst, Adaptive Response Actions run automatically without analyst intervention.
What does the Security Posture dashboard display?
A high-level overview of notable events.
10.22.63.159
, websvr4
, and 00:26:08:18: CF:1D
would be matched against what in ES?
An asset.
How should an administrator add a new lookup through the ES app?
Upload the lookup file using Configure -> Content Management -> Create New Content -> Managed Lookup
Glass tables can display static images and text, the results of ad-hoc searches, and which of the following objects?
Security metrics.