Exam SPLK-3001 All QuestionsBrowse all questions from this exam
Question 87

Which of the following is an adaptive action that is configured by default for ES?

    Correct Answer: B

    Creating a notable event is an adaptive action that is configured by default in Splunk Enterprise Security (ES). This action is leveraged to generate notable events based on the outcomes of correlation searches, enabling security analysts to review and take necessary actions.

Discussion
_ademOption: B

Answer is B. https://docs.splunk.com/Documentation/ES/6.6.2/Admin/Configureadaptiveresponse#Included_adaptive_response_actions

jaemon22Option: B

Creating a notable event is an adaptive action that is configured by default in Splunk Enterprise Security (ES). This action is used to generate notable events based on the results of correlation searches, which can then be reviewed and acted upon by security analysts.

qtygbapjpesdayazkoOption: B

B. Create notable event

niuksasOption: B

The correct answer is B

1qaz2wsxOption: B

maybe correct answer is B

_adem

Most likely!