SPLK-3001 Exam QuestionsBrowse all questions from this exam

SPLK-3001 Exam - Question 7


What role should be assigned to a security team member who will be taking ownership of notable events in the incident review dashboard?

Show Answer
Correct Answer: BC

The appropriate role for a security team member taking ownership of notable events in the incident review dashboard is the ess_analyst. The ess_analyst role is specifically designed for individuals who will be responsible for owning and performing status changes on notable events, ensuring they can efficiently manage incident reviews. While an ess_admin also has the capability, assigning the ess_analyst role aligns better with specific responsibilities and follows best practices.

Discussion

11 comments
Sign in to comment
pock3tsOption: C
Jun 25, 2022

C is correct

niuksasOption: C
Sep 29, 2022

The correct answer is C

ImcoolOption: C
Feb 14, 2021

ess_analyst is also true, and from a best practices perspective it is better to assign this one instead of admin no ?

BMOOption: C
May 30, 2021

C is correct Admin ES - Slide 20

1qaz2wsx
Sep 23, 2021

can you share Admin ES slides?

CurryMuncherOption: B
Jun 3, 2021

B is the correct answer - https://docs.splunk.com/Documentation/ES/6.5.1/Install/ConfigureUsersRoles

CurryMuncherOption: C
Jun 3, 2021

SORRY C is the correct answer https://docs.splunk.com/Documentation/ES/6.5.1/Install/ConfigureUsersRoles I made a mistake earlier. Answer is C

guiraxOption: C
Dec 1, 2021

C is the correct ES Analyst ess_analyst Owns notable events and performs notable event status changes Administering Splunk Enterprise Security page 20

andy73Option: C
Dec 1, 2021

C is correct

brockmoon56Option: C
Dec 18, 2022

Should be C. Technically an Admin can be able to do it all, but the responsibility should lie with the ess_analyst. The admin would inherit it as a higher role.

Bittu22Option: C
Dec 21, 2022

The ability to change notable event statuses is available to the ess_analyst and ess_admin roles by default.

vasudvnOption: C
Dec 17, 2023

ess_analyst can own the notable https://docs.splunk.com/Documentation/ES/6.1.0/Install/ConfigureUsersRoles