SPLK-3001 Exam QuestionsBrowse all questions from this exam

SPLK-3001 Exam - Question 87


Which of the following is an adaptive action that is configured by default for ES?

Show Answer
Correct Answer: BD

Creating a notable event is an adaptive action that is configured by default in Splunk Enterprise Security (ES). This action is leveraged to generate notable events based on the outcomes of correlation searches, enabling security analysts to review and take necessary actions.

Discussion

5 comments
Sign in to comment
_ademOption: B
Oct 5, 2021

Answer is B. https://docs.splunk.com/Documentation/ES/6.6.2/Admin/Configureadaptiveresponse#Included_adaptive_response_actions

1qaz2wsxOption: B
Sep 22, 2021

maybe correct answer is B

_adem
Oct 5, 2021

Most likely!

niuksasOption: B
Sep 29, 2022

The correct answer is B

qtygbapjpesdayazkoOption: B
Apr 16, 2023

B. Create notable event

jaemon22Option: B
May 28, 2024

Creating a notable event is an adaptive action that is configured by default in Splunk Enterprise Security (ES). This action is used to generate notable events based on the results of correlation searches, which can then be reviewed and acted upon by security analysts.