Which of the following are the default ports that must be configured for Splunk Enterprise Security to function?

A. SplunkWeb (8088), Splunk Management (8089), KV Store (8000)
B. SplunkWeb (8397), Splunk Management (8877), KV Store (8350)
C. SplunkWeb (8043), Splunk Management (8088), KV Store (8191)
D. SplunkWeb (8000), Splunk Management (8089), KV Store (8191)
Correct Answer: D


Which setting is used in indexes.conf to specify alternate locations for accelerated storage?

A. thawedPath
B. tstatsHomePath
C. summaryHomePath
D. warmToColdScript
Correct Answer: B
Reference: https://docs.splunk.com/Documentation/Splunk/8.0.2/Knowledge/Acceleratedatamodels


Which of the following would allow an add-on to be automatically imported into Splunk Enterprise Security?

A. A prefix of CIM_
B. A suffix of .spl
C. A prefix of TECH_
D. A prefix of Splunk_TA_
Correct Answer: D
Reference: https://dev.splunk.com/enterprise/docs/developapps/enterprisesecurity/planintegrationes/


Adaptive response action history is stored in which index?

A. cim_modactions
B. modular_history
C. cim_adaptiveactions
D. modular_action_history
Correct Answer: A
Reference: https://docs.splunk.com/Documentation/ES/6.1.0/Install/Indexes


Which component normalizes events?

B. SA-Notable.
C. ES application.
D. Technology add-on.
Correct Answer: A
Reference: https://docs.splunk.com/Documentation/CIM/4.15.0/User/ UsetheCIMtonormalizedataatsearchtime


To which of the following should the ES application be uploaded?

A. The indexer.
B. The KV Store.
C. The search head.
D. The dedicated forwarder.
Correct Answer: C
Reference: https://docs.splunk.com/Documentation/ES/6.1.0/Install/InstallEnterpriseSecuritySHC


Which of the following is part of tuning correlation searches for a new ES installation?

A. Configuring correlation permissions.
B. Configuring correlation adaptive responses.
C. Configuring correlation notable event index.
D. Configuring correlation result storage.
Correct Answer: C


What is the bar across the bottom of any ES window?

A. The Investigator Workbench.
B. The Investigation Bar.
C. The Compliance Bar.
D. The Analyst Bar.
Correct Answer: B
Reference: https://docs.splunk.com/Documentation/ES/6.4.1/User/Startaninvestigation


Which of the following is a key feature of a glass table?

A. Rigidity.
B. Customization.
C. Interactive investigations.
D. Strong data for later retrieval.
Correct Answer: B


Which columns in the Assets lookup are used to identify an asset in an event?

A. src, DVC, dest
B. cidr, port, netbios, saml
C. IP, mac, DNS, nt_host
D. host, hostname, URL, address
Correct Answer: C
Reference: https://docs.splunk.com/Documentation/ES/6.4.1/Admin/Formatassetoridentitylist


Which of the following is an adaptive action that is configured by default for ES?

A. Create a new asset
B. Create notable event
C. Create investigation
D. Create a new correlation search
Correct Answer: D


An administrator is asked to configure a “Nslookup” adaptive response actions that appear as a selectable option in the notable event\’s action menu when an analyst is working in the Incident Review dashboard.

next, What steps would the administrator take to configure this option?

A. Configure -> Content Management -> Type: Correlation Search -> Notable -> Nslookup
B. Configure -> Type: Correlation Search -> Notable -> Recommended Actions -> Nslookup
C. Configure -> Content Management -> Type: Correlation Search -> Notable -> Next Steps -> Nslookup
D. Configure -> Content Management -> Type: Correlation Search -> Notable -> Recommended Actions > Nslookup
Correct Answer: D


Which of the following is a way to test for a properly normalized data model?

A. Use Audit -> Normalization Audit and check the Errors panel.
B. Run a | data model search, compare results to the CIM documentation for the data model.
C. Run a | load job search, look at tag values and compare them to known tags based on the encoding.
D. Run a | data model search and compare the results to the list of data models in the ES normalization guide.
Correct Answer: B
Reference: https://docs.splunk.com/Documentation/CIM/4.15.0/User/ UsetheCIMtonormalizedataatsearchtime


