Which columns in the Assets lookup are used to identify an asset in an event?
A. src, dvc, dest
B. host, hostname, url, address
C. cidr, port, netbios, saml
D. ip, mac, dns, nt_host
正解:D
解説: (Pass4Test メンバーにのみ表示されます)
質問 2:
Which of the following actions can improve overall search performance?
A. Reduce the frequency (schedule) of lower-priority correlation searches.
B. Add notable event suppressions for correlation searches with high numbers of false positives.
C. Increase priority of all correlation searches.
D. Disable indexed real-time search.
正解:A,B
質問 3:
What role should be assigned to a security team member who will be taking ownership of notable events in the incident review dashboard?
A. ess_reviewer
B. ess_user
C. ess_admin
D. ess_analyst
正解:D
解説: (Pass4Test メンバーにのみ表示されます)
質問 4:
Which argument to the | tstats command restricts the search to summarized data only?
A. summariesonly=t
B. summaries=all
C. summaries=t
D. summariesonly=all
正解:A
解説: (Pass4Test メンバーにのみ表示されます)
質問 5:
Where are attachments to investigations stored?
A. KV Store
B. notable index
C. attachments.csv lookup
D. <splunk_home>/etc/apps/SA-Investigations/default/ui/views/attachments
正解:A
解説: (Pass4Test メンバーにのみ表示されます)
質問 6:
An administrator is asked to configure an "Nslookup" adaptive response action, so that it appears as a selectable option in the notable event's action menu when an analyst is working in the Incident Review dashboard. What steps would the administrator take to configure this option?
A. Configure -> Content Management -> Type: Correlation Search -> Notable -> Recommended Actions
-> Nslookup
B. Configure -> Content Management -> Type: Correlation Search -> Notable -> Nslookup
C. Configure -> Content Management -> Type: Correlation Search -> Notable -> Next Steps -> Nslookup
D. Configure -> Type: Correlation Search -> Notable -> Recommended Actions -> Nslookup
正解:A
解説: (Pass4Test メンバーにのみ表示されます)
外山** -
ありがとねPass4TestさんPass4Testの問題集はいつも素敵でございますね。友達にも勧めました。