Sign In
Home/Splunk/SPLK-3001/Free questions

SPLK-3001 — Free Practice Questions

10 free sample questions from a bank of 144, with the correct answers and explanations. No signup required — start practising right now.

1The Add-On Builder creates Splunk Apps that start with what?
  • DA-
  • SA-
  • TA-
  • App-
Answer: C
2Which indexes are searched by default for CIM data models?
  • notable and default
  • summary and notable
  • _internal and summary
  • All indexes
Answer: D
3What is an example of an ES asset?
  • MAC address
  • User name
  • People
  • Server
Answer: A
4Analysts have requested the ability to capture and analyze network traffic data. The administrator has researched the documentation and, based on this research, has decided to integrate the Splunk App for Stream with ES. Which dashboards will now be supported so analysts can view and analyze network Stream data?
  • Endpoint dashboards.
  • Protocol Intelligence dashboards.
  • User Intelligence dashboards.
  • Web Intelligence dashboards.
Answer: B
5Which setting is used in indexes.conf to specify alternate locations for accelerated storage?
  • thawedPath
  • tstatsHomePath
  • summaryHomePath
  • warmToColdScript
Answer: B
6Which of the following is a way to test for a property normalized data model?
  • Use Audit -> Normalization Audit and check the Errors panel.
  • Run a | datamodel search, compare results to the CIM documentation for the datamodel.
  • Run a | loadjob search, look at tag values and compare them to known tags based on the encoding.
  • Run a | datamodel search and compare the results to the list of data models in the ES normalization guide.
Answer: B
7Which argument to the | tstats command restricts the search to summarized data only?
  • summaries=t
  • summaries=all
  • summariesonly=t
  • summariesonly=all
Answer: C
8When investigating, what is the best way to store a newly-found IOC?
  • Paste it into Notepad.
  • Click the ג€Add IOCג€ button.
  • Click the ג€Add Artifactג€ button.
  • Add it in a text note to the investigation.
Answer: B
9How is it possible to navigate to the list of currently-enabled ES correlation searches?
  • Configure -> Correlation Searches -> Select Status ג€Enabledג€
  • Settings -> Searches, Reports, and Alerts -> Filter by Name of ג€Correlationג€
  • Configure -> Content Management -> Select Type ג€Correlationג€ and Status ג€Enabledג€
  • Settings -> Searches, Reports, and Alerts -> Select App of ג€SplunkEnterpriseSecuritySuiteג€ and filter by ג€-Ruleג€
Answer: C
10Which of the following is a risk of using the Auto Deployment feature of Distributed Configuration Management to distribute indexes.conf?
  • Indexers might crash.
  • Indexers might be processing.
  • Indexers might not be reachable.
  • Indexers have different settings.
Answer: D

Want the full bank of 144 questions for SPLK-3001? See all practice exams.