exam questions

Exam SPLK-3001 All Questions

View all questions & answers for the SPLK-3001 exam

Exam SPLK-3001 topic 1 question 22 discussion

Actual exam question from Splunk's SPLK-3001
Question #: 22
Topic #: 1
[All SPLK-3001 Questions]

`10.22.63.159`, `websvr4`, and `00:26:08:18: CF:1D` would be matched against what in ES?

  • A. A user.
  • B. A device.
  • C. An asset.
  • D. An identity.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
prich1111
Highly Voted 3 years, 3 months ago
Answer is C
upvoted 9 times
...
daisy01
Most Recent 5 days, 7 hours ago
Selected Answer: C
there are assets and identities in ES - IP address belongs to assets
upvoted 1 times
...
8e3ad88
5 months ago
Selected Answer: C
Definitely asset.
upvoted 1 times
...
jaemon22
6 months, 4 weeks ago
It's C an asset, In Splunk Enterprise Security, an asset typically refers to IP addresses, hostnames, and MAC addresses, which are used to identify and categorize different devices and systems within the network.
upvoted 1 times
...
dohatelo
8 months, 2 weeks ago
Answer is C: Explanation: “10.22.63.159”, “websvr4”, and “00:26:08:18: CF:1D” would be matched against an asset in ES. An asset is a device on a network that can be identified by an IP address, MAC address, DNS name, or other attributes. ES uses an asset and identity system to correlate asset and identity information with events to enrich and provide context to the data1. The asset fields that ES can match include ip, mac, nt_host, dns, and others2. An identity is a user account that can be identified by a username, email address, phone number, or other attributes. An identity is not the same as an asset, although an identity can be associated with an asset1. References = Add asset and identity data to Splunk Enterprise Security Asset and identity fields in Splunk Enterprise Security
upvoted 2 times
...
qtygbapjpesdayazko
1 year, 8 months ago
Selected Answer: C
C. An asset.
upvoted 1 times
...
qtygbapjpesdayazko
1 year, 8 months ago
Selected Answer: B
Suggested Answer
upvoted 1 times
...
huu_nguyen
2 years, 2 months ago
C for sure
upvoted 1 times
...
guirax
3 years ago
Answers is C Asset field matching settings – Name - which headers/fields in a lookup table to match during the merge process – Key - like ip (key), field is used in merge process – Tag - field can be used as an asset tag – Multivalue - field can output multiple values – Multivalue Limit - number of values in a multivalue field merge Administering Splunk Enterprise Security page 276
upvoted 1 times
...
andy73
3 years ago
C is correct
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago