What does the Security Posture dashboard display?
A. A high-level overview of notable events.
B. Current threats being tracked by the SOC.
C. A display of the status of security tools.
D. Active investigations and their status.
正解:A
解説: (Pass4Test メンバーにのみ表示されます)
質問 2:
Which component normalizes events?
A. SA-CIM.
B. SA-Notable.
C. ES application.
D. Technology add-on.
正解:D
解説: (Pass4Test メンバーにのみ表示されます)
質問 3:
Analysts have requested the ability to capture and analyze network traffic data. The administrator has researched the documentation and, based on this research, has decided to integrate the Splunk App for Stream with ES.
Which dashboards will now be supported so analysts can view and analyze network Stream data?
A. Protocol Intelligence dashboards.
B. User Intelligence dashboards.
C. Web Intelligence dashboards.
D. Endpoint dashboards.
正解:A
解説: (Pass4Test メンバーにのみ表示されます)
質問 4:
What are adaptive responses triggered by?
A. By custom tech add-ons and users on the risk analysis dashboard.
B. By correlation searches and users on the threat analysis dashboard.
C. By correlation searches and custom tech add-ons.
D. By correlation searches and users on the incident review dashboard.
正解:D
解説: (Pass4Test メンバーにのみ表示されます)
質問 5:
Which feature contains scenarios that are useful during ES Implementation?
A. Correlation Searches
B. Predictive Analytics
C. Adaptive Responses
D. Use Case Library
正解:D
解説: (Pass4Test メンバーにのみ表示されます)
質問 6:
Following the installation of ES, an admin configured users with the ess_user role the ability to close notable events.
How would the admin restrict these users from being able to change the status of Resolved notable events to Closed?
A. From Splunk Access Controls, select the ess_user role and remove the edit_notable_events capability.
B. In Enterprise Security, give the ess_user role the Own Notable Events permission.
C. From the Status Configuration window select the Resolved status. Remove ess_user from the status transitions for the Closed status.
D. From the Status Configuration window select the Closed status. Remove ess_user from the status transitions for the Resolved status.
正解:D
解説: (Pass4Test メンバーにのみ表示されます)
星*香 -
SPLK-3001試験に合格しました。私はもう一度う買いたいです!