Splunk 26-50 Flashcards
(25 cards)
How often should asset lists be updated?
A) Daily
B) Weekly
C) Monthly
D) As needed based on environment changes
D) As needed based on environment changes
Which ES feature automatically discovers assets on the network?
A) Asset Discovery
B) Network Discovery
C) Auto Asset Detection
D) Dynamic Asset Management
A) Asset Discovery
What information can be included in an identity list?
A) Only usernames
B) Only email addresses
C) Usernames, email addresses, and additional attributes
D) Only employee IDs
C) Usernames, email addresses, and additional attributes
Which priority level indicates the most critical assets?
A) Low
B) Medium
C) High
D) Critical
D) Critical
What happens when an asset is marked as “bunit” in the asset list?
A) It’s assigned to a business unit
B) It’s marked for backup
C) It’s flagged as a backup unit
D) It’s designated as a business-critical unit
A) It’s assigned to a business unit
What is the primary function of correlation searches in Splunk ES?
A) To generate reports
B) To create dashboards
C) To detect security threats and create notable events
D) To backup data
C) To detect security threats and create notable events
What is the default search window for most correlation searches?
A) 1 hour
B) 4 hours
C) 24 hours
D) 1 week
C) 24 hours
Which field determines the scheduling interval for correlation searches?
A) cron_schedule
B) search_interval
C) schedule
D) frequency
A) cron_schedule
What is the purpose of the “earliest” and “latest” time modifiers in correlation searches?
A) To limit search results
B) To define the search time window
C) To set alert thresholds
D) To configure data retention
B) To define the search time window
Which action is automatically performed when a correlation search triggers?
A) Send email notification
B) Create a notable event
C) Generate a report
D) Update asset information
B) Create a notable event
What is the recommended approach for testing new correlation searches?
A) Deploy directly to production
B) Test with historical data first
C) Run only during maintenance windows
D) Test on a subset of data sources
B) Test with historical data first
Which field in correlation searches controls the notable event severity?
A) priority
B) urgency
C) severity
D) importance
C) severity
What is the purpose of suppression in correlation searches?
A) To reduce false positives
B) To increase search performance
C) To hide sensitive data
D) To compress search results
A) To reduce false positives
Which time format is used in correlation search scheduling?
A) 24-hour format
B) Cron format
C) Unix timestamp
D) ISO 8601
B) Cron format
What happens when a correlation search is disabled?
A) It continues to run but doesn’t create notable events
B) It stops running completely
C) It runs only during off-peak hours
D) It runs but creates low-priority notable events
B) It stops running completely
What are the possible statuses for notable events?
A) New, Open, Closed
B) New, In Progress, Resolved, Closed
C) Active, Inactive, Archived
D) Pending, Investigating, Complete
B) New, In Progress, Resolved, Closed
Which dashboard is primarily used for managing notable events?
A) Security Posture
B) Incident Review
C) Asset Investigator
D) Protocol Intelligence
B) Incident Review
What is the purpose of notable event suppression?
A) To delete unwanted events
B) To temporarily hide events from view
C) To prevent creation of similar events for a specified period
D) To reduce event severity
C) To prevent creation of similar events for a specified period
Which field contains the correlation search name that created the notable event?
A) search_name
B) rule_name
C) correlation_id
D) source_search
A) search_name
What is the default owner of newly created notable events?
A) admin
B) unassigned
C) system
D) es_admin
B) unassigned
Which action allows analysts to group related notable events?
A) Merge
B) Link
C) Correlate
D) Associate
A) Merge
What information is captured when a notable event status is changed?
A) Only the new status
B) Status, timestamp, and user who made the change
C) Status and timestamp only
D) User and timestamp only
B) Status, timestamp, and user who made the change
Which field determines the urgency of a notable event?
A) severity
B) priority
C) urgency
D) importance
C) urgency
What is the purpose of notable event comments?
A) To provide investigation notes and context
B) To classify the event type
C) To set the event priority
D) To assign the event to a team
A) To provide investigation notes and context