exam questions

Exam SPLK-3001 All Questions

View all questions & answers for the SPLK-3001 exam

Exam SPLK-3001 topic 1 question 46 discussion

Actual exam question from Splunk's SPLK-3001
Question #: 46
Topic #: 1
[All SPLK-3001 Questions]

Where are attachments to investigations stored?

  • A. KV Store
  • B. notable index
  • C. attachments.csv lookup
  • D. <splunk_home>/etc/apps/SA-Investigations/default/ui/views/attachments
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️
Reference:
https://docs.splunk.com/Documentation/ES/6.1.0/Admin/Manageinvestigations

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
andy73
Highly Voted 3 weeks, 1 day ago
A is correct. Some lookups are managed by the KV store Examples: incident review, threat intel collections
upvoted 5 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago