Splunk 26-50 Flashcards

(25 cards)

1
Q

How often should asset lists be updated?

A) Daily
B) Weekly
C) Monthly
D) As needed based on environment changes

A

D) As needed based on environment changes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Which ES feature automatically discovers assets on the network?

A) Asset Discovery
B) Network Discovery
C) Auto Asset Detection
D) Dynamic Asset Management

A

A) Asset Discovery

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What information can be included in an identity list?

A) Only usernames
B) Only email addresses
C) Usernames, email addresses, and additional attributes
D) Only employee IDs

A

C) Usernames, email addresses, and additional attributes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Which priority level indicates the most critical assets?

A) Low
B) Medium
C) High
D) Critical

A

D) Critical

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What happens when an asset is marked as “bunit” in the asset list?

A) It’s assigned to a business unit
B) It’s marked for backup
C) It’s flagged as a backup unit
D) It’s designated as a business-critical unit

A

A) It’s assigned to a business unit

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is the primary function of correlation searches in Splunk ES?

A) To generate reports
B) To create dashboards
C) To detect security threats and create notable events
D) To backup data

A

C) To detect security threats and create notable events

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is the default search window for most correlation searches?

A) 1 hour
B) 4 hours
C) 24 hours
D) 1 week

A

C) 24 hours

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Which field determines the scheduling interval for correlation searches?

A) cron_schedule
B) search_interval
C) schedule
D) frequency

A

A) cron_schedule

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is the purpose of the “earliest” and “latest” time modifiers in correlation searches?

A) To limit search results
B) To define the search time window
C) To set alert thresholds
D) To configure data retention

A

B) To define the search time window

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Which action is automatically performed when a correlation search triggers?

A) Send email notification
B) Create a notable event
C) Generate a report
D) Update asset information

A

B) Create a notable event

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is the recommended approach for testing new correlation searches?

A) Deploy directly to production
B) Test with historical data first
C) Run only during maintenance windows
D) Test on a subset of data sources

A

B) Test with historical data first

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Which field in correlation searches controls the notable event severity?

A) priority
B) urgency
C) severity
D) importance

A

C) severity

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What is the purpose of suppression in correlation searches?

A) To reduce false positives
B) To increase search performance
C) To hide sensitive data
D) To compress search results

A

A) To reduce false positives

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Which time format is used in correlation search scheduling?

A) 24-hour format
B) Cron format
C) Unix timestamp
D) ISO 8601

A

B) Cron format

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What happens when a correlation search is disabled?

A) It continues to run but doesn’t create notable events
B) It stops running completely
C) It runs only during off-peak hours
D) It runs but creates low-priority notable events

A

B) It stops running completely

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What are the possible statuses for notable events?

A) New, Open, Closed
B) New, In Progress, Resolved, Closed
C) Active, Inactive, Archived
D) Pending, Investigating, Complete

A

B) New, In Progress, Resolved, Closed

17
Q

Which dashboard is primarily used for managing notable events?

A) Security Posture
B) Incident Review
C) Asset Investigator
D) Protocol Intelligence

A

B) Incident Review

18
Q

What is the purpose of notable event suppression?

A) To delete unwanted events
B) To temporarily hide events from view
C) To prevent creation of similar events for a specified period
D) To reduce event severity

A

C) To prevent creation of similar events for a specified period

19
Q

Which field contains the correlation search name that created the notable event?

A) search_name
B) rule_name
C) correlation_id
D) source_search

A

A) search_name

20
Q

What is the default owner of newly created notable events?

A) admin
B) unassigned
C) system
D) es_admin

A

B) unassigned

21
Q

Which action allows analysts to group related notable events?

A) Merge
B) Link
C) Correlate
D) Associate

22
Q

What information is captured when a notable event status is changed?

A) Only the new status
B) Status, timestamp, and user who made the change
C) Status and timestamp only
D) User and timestamp only

A

B) Status, timestamp, and user who made the change

23
Q

Which field determines the urgency of a notable event?

A) severity
B) priority
C) urgency
D) importance

24
Q

What is the purpose of notable event comments?

A) To provide investigation notes and context
B) To classify the event type
C) To set the event priority
D) To assign the event to a team

A

A) To provide investigation notes and context

25
How long are notable event status changes retained by default? A) 30 days B) 90 days C) 6 months D) Same as the notable event retention period
D) Same as the notable event retention period