Which setting is used in indexes.conf to specify alternate locations for accelerated storage?
B
Explanation:
Reference:
https://docs.splunk.com/Documentation/Splunk/8.0.2/Knowledge/Acceleratedatamodels
Which of the following is a way to test for a property normalized data model?
B
Explanation:
Reference:
https://docs.splunk.com/Documentation/CIM/4.15.0/User/UsetheCIMtonormalizedataatsearchtime
Which argument to the | tstats command restricts the search to summarized data only?
C
Explanation:
Reference:
https://docs.splunk.com/Documentation/Splunk/8.0.2/Knowledge/Acceleratedatamodels
When investigating, what is the best way to store a newly-found IOC?
C
How is it possible to navigate to the list of currently-enabled ES correlation searches?
C
Explanation:
Reference:
https://docs.splunk.com/Documentation/ES/6.1.0/Admin/Listcorrelationsearches
Which of the following is a risk of using the Auto Deployment feature of Distributed Configuration
Management to distribute indexes.conf?
A
Explanation:
Reference:
https://docs.splunk.com/Documentation/Splunk/8.0.2/Admin/Indexesconf
Which of the following are data models used by ES? (Choose all that apply)
A,C,D
Explanation:
Reference:
https://dev.splunk.com/enterprise/docs/developapps/enterprisesecurity/datamodelsusedbyes/
At what point in the ES installation process should Splunk_TA_ForIndexes.spl be deployed to the
indexers?
C
Explanation:
Reference:
https://docs.splunk.com/Documentation/ES/6.1.0/Install/InstallTechnologyAdd-ons
Which correlation search feature is used to throttle the creation of notable events?
C
Explanation:
Reference:
https://docs.splunk.com/Documentation/ES/6.1.0/Admin/Configurecorrelationsearches
Both “Recommended Actions” and “Adaptive Response Actions” use adaptive response. How do
they differ?
D
Explanation:
Reference:
https://docs.splunk.com/Documentation/ES/latest/Admin/Configureadaptiveresponse