Splunk 7.x Fundmentals Part1 & Others Flashcards

1
Q

Machine data is always structured.

Select your answer.
True
False

A

False

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Machine data makes up for more than ___% of the data accumulated by organizations.

Select your answer.
10
90
25
50
A

90%

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Machine data is only generated by web servers.

Select your answer.
False
True

A

False

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Search requests are processed by the ___________.

Select your answer.
Forwarders
Indexers
Search Heads

A

Indexers

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

A single-instance deployment of Splunk Enterprise handles:

Select all that apply.
Indexing
Input
Searching
Parsing
A

Indexing
Searching
Parsing

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Which of these is not a main component of Splunk?

Select your answer.
Collect and index data
Compress and archive
Search and investigate
Add knowledge
A

Compress and archive

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

In most Splunk deployments, ________ serve as the primary way data is supplied for indexing.

Select your answer.
Search Heads
Forwarders
Local Files

A

Forwarders

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Which function is not a part of a single instance deployment?

Select your answer.
Searching
Indexing
Clustering
Parsing
A

Clustering

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Which apps ship with Splunk Enterprise?

Select all that apply.
Sideview Utils
DB Connect
Search & Reporting
Home App
A

Search & Reporting

Home App

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What are the three main default roles in Splunk Enterprise?

Select all that apply.
Admin
User
King
Manager
Power
A

Admin
User
Power

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

_________ define what users can do in Splunk.

Select your answer.
Tokens
Disk permissions
Roles

A

Roles

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

You can launch and manage apps from the home app.

Select your answer.
False
True

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

The password for a newly installed Splunk instance is:

Select your answer.
Your email address.
Randomly generated.
Created when you install Splunk Enterprise.
Available from the splunk.com website.
A

Created when you install Splunk Enterprise.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

This role will only see their own knowledge objects and those that have been shared with them.

Select your answer.
User
Admin
Power

A

User

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

In most production environments, _______ will be used as the source of data input.

Fill in the blank.

A

Forwarders

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

The monitor input option will allow you to continuously monitor files.

Select your answer.
True
False

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

Splunk knows where to break the event, where the time stamp is located and how to automatically create field value pairs using these.

Select your answer.
Source types
Line breaks
File names

A

Source types

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

Splunk uses ________ to categorize the type of data being indexed.

Fill in the blank.

A

source types

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

Files indexed using the the upload input option get indexed _____.

Select your answer.
Every hour
On every search
Once
Each time Splunk restarts
A

Once

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

The time stamp you see in the events is based on the time zone in your user account.

Select your answer.
True
False

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

How is the asterisk used in Splunk search?

Select your answer.
To make a nose for your clown emoticon
As a wildcard
As a place holder
To add up numbers
A

As a wildcard

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q

Events are always returned in chronological order.

Select your answer.
True
False

A

False

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
23
Q

A search job will remain active for ___ minutes after it is run.

Select your answer.
10
30
5
90
20
A

10

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
24
Q

Commands that create statistics and visualizations are called _______________ commands.

Fill in the blank.

A

transforming

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
25
Q

When zooming in on the event time line, a new search is run.

Select your answer.
False
True

A

False

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
26
Q

When a search is sent to splunk, it becomes a _____.

Select your answer.
Search job
Task for Jimmy the Splunk elf
Event
File on the host system
A

Search job

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
27
Q

What is the order of evaluation for Boolean operations in Splunk?

Drag and drop into the correct order.

AND
NOT
OR
A

NOT
OR
AND

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
28
Q

These are booleans in the Splunk Search Language.

Select all that apply.
OR
IF
AND
NOT
A

OR
AND
NOT

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
29
Q

Which following search mode toggles behavior based on the type of search being run?

Select your answer.
Fast
Verbose
Smart

A

Smart

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
30
Q

These searches will return the same results.

failed password
failed AND password

Select your answer.
False
True

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
31
Q

Wildcards cannot be used with field searches.

Select your answer.
True
False

A

False

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
32
Q

What attributes describe the circled field below?
a dest 4

Select all that apply.
It contains numerical values
It contains 4 values.
It cannot be used in a search.
It contains string values.
A

It contains 4 values.

It contains string values.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
33
Q

Field names are ________.

Select all that apply.
Always capitalized
Case insensitive
Case sensitive
Not important in Splunk
A

Case sensitive

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
34
Q

Which is not a comparison operator in Splunk?

Select your answer.
?=
=
<=
!=
>
A

?=

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
35
Q

Field values are case sensitive.

Select your answer.
False
True

A

False

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
36
Q

As a general practice, exclusion is better than inclusion in a Splunk search.

Select your answer.
True
False

A

False

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
37
Q

What is the most efficient way to filter events in Splunk?

Select your answer.
By time.
With an asterisk.
Using booleans.

A

By time.

38
Q

Having separate indexes allows:

Select all that apply.
Ability to limit access.
Multiple retention policies
Faster Searches.

A

Ability to limit access.
Multiple retention policies
Faster Searches.

39
Q

Time to search can only be set by the time range picker.

Select your answer.
True
False

A

False

40
Q

This symbol is used in the “Advanced” section of the time range picker to round down to nearest unit of specified time.

Select your answer.
&amp;
%
*
@
^
A

@

41
Q

What is missing from this search?
sourcetype=a* | rename ip as “User IP” | table User IP

Select your answer.
Quotation marks around User IP.
Search terms
A table command.
A pipe.
A

Quotation marks around User IP.

42
Q

Finish the rename command to change the name of the status field to HTTP Status.
sourcetype=a* status=404 | rename—————–

Select your answer.
as "HTTP Status"
status to "HTTP Status"
status as "HTTP Status"
status as HTTP Status
A

status as “HTTP Status”

43
Q

What command would you use to remove the status field from the returned events?
sourcetype=a* status=404 | —————– status

Select your answer.
table
fields -
fields
not
A

fields -

44
Q

Excluding fields using the Fields Command will benefit performance.

Select your answer.
True
False

A

False

45
Q

Would the ip column be removed in the results of this search? Why or why not?
sourcetype=a* | rename ip as “User” | fields - ip

Select your answer.
No, because table columns can not be removed.
Yes, because a pipe was used between search commands
No, because the name was changed.
Yes, because the negative sign was used.

A

No, because the name was changed.

46
Q

To display the most common values in a specific field, what command would you use?

Select your answer.
all
table
top
rare
A

top

47
Q

Which clause would you use to rename the count field?
sourcetype=vendor* | stats count ——- “Units Sold”

Select your answer.
rename
show
as
to
A

as

48
Q

How many results are shown by default when using a Top or Rare Command?

Fill in the blank.

A

10

49
Q

Which one of these is not a stats function?

Select your answer.
Sum
Count
Avg
List
Addtotals
A

Addtotals

50
Q

Which stats function would you use to find the average value of a field?

Fill in the blank.

A

Avg

51
Q

Charts can be based on numbers, time, or location.

Select your answer.
False
True

A

True

52
Q

The User role can not create reports.

Select your answer.
True
False

A

False

53
Q

A time range picker can be included in a report.

Select your answer.
True
False

A

True

54
Q

If a search returns this, you can view the results as a chart.

Select your answer.
Numbers
Statistical values
A list.
Time limits.
A

Statistical values

55
Q

In a dashboard, a time range picker will only work on panels that include a(n) __________ search.

Select your answer.
visualization
transforming
accelerated
inline
A

inline

56
Q

These roles can create reports:

Select all that apply.
User
Admin
Power

A

User
Admin
Power

57
Q

_____________ are reports gathered together into a single pane of glass.

Select your answer.
Dashboards
Alerts
Scheduled Reports
Panels
A

Dashboards

58
Q

Adding child data model objects is like the ______ Boolean in the Splunk search language.

Select your answer.
OR
AND
NOT

A

AND

59
Q

Pivots can be saved as dashboards panels.

Select your answer.
False
True

A

True

60
Q

Data models are made up of ___________.

Select your answer.
Dashboard panels
Pivots
Datasets
Transforming searches
A

Datasets

61
Q

Pivots cannot be saved as reports panels.

Select your answer.
True
False

A

False

62
Q

These are knowledge objects that provide the data structure for pivot.

Select your answer.
Indexes
Data models
Alerts
Reports
A

Data models

63
Q

Which role(s) can create data models?

Select all that apply.
Admin
Power
User

A

User

64
Q

When using a .csv file for Lookups, the first row in the file represents this.

Select your answer.
Field names
Input fields
Output fields
Nothing, it is ignored
A

Field names

65
Q

External data used by a Lookup can come from sources like:

Select all that apply.
None. Only internal data can be used.
Geospatial data
Scripts
CSV files
A

Geospatial data
Scripts
CSV files

66
Q

Finish this search command so that it displays data from the http_status.csv Lookup file.
| ———- http_status.csv

Select your answer.
inputlookup
lookup=*
lookup
datalookup
A

inputlookup

67
Q

A lookup is categorized as a dataset.

Select your answer.
False
True

A

True

68
Q

To keep from overwriting existing fields with your Lookup you can use the ____________ clause.

Fill in the blank.

A

OUTPUTNEW

69
Q

Real-time alerts will run the search continuously in the background.

Select your answer.
False
True

A

True

70
Q

Alerts can send an email.

Select your answer.
False
True

A

True

71
Q

Alerts can run uploaded scripts.

Select your answer.
True
False

A

True

72
Q

Alerts can be shared to all apps.

Select your answer.
True
False

A

True

73
Q

Once an alert is created, you can no longer edit its defining search.

Select your answer.
True
False

A

False

74
Q

An alert is an action triggered by a _____________.

Select your answer.
Report
Saved search
Selected field
Tag
A

Saved search

75
Q

Splunk major parts

A

search heads
indexers
forwarders

76
Q

What are the types of forwarders?

A

○ Universal Forwarder
○ Light Forwarder (deprecated)
○ Heavy Forwarder

77
Q

How to install forwarders in large environments?

A

Deployment tools like SCCM, Ansible, or Chef

78
Q

What are Splunk deployment schemes?

A
  • small/non-distributed environment combining all parts in one instance less than 100 forwarders
  • Enterprise/distributed environment: mini-indexers, search heads, 1000s of forwarders
  • clustering: data replication (availability, fidelity, recovery), redundancy
79
Q

What are the server roles?

A
Search Head, 
Indexer, 
Cluster Master,
License Master, 
Deployment Server, 
KV Store, 
SHC Deployer
80
Q

Splunk General tasks?

A
  • Creating reports
  • Creating dashboards
  • Creating alerts
  • Scheduled reports and alerts
81
Q

Splunk SOC tasks?

A
  • Centralized monitoring
  • Event log collection
  • Log correlation to identify IOCs
  • Import syslog and local registry information into Splunk
  • Create multiple compliance reports
82
Q

PaloAlto Authentication

A
  • Configuring Authentication

- Using Two-Factor Authentication to Secure the Firewall

83
Q

PaloAlto Decryption

A
  • Decrypting SSH Traffic

- Decrypting SSL Inbound Traffic

84
Q

PaloAlto application Management

A
  • Allowing Only Trusted Applications

- Denying High Risk Apps

85
Q

PaloAlto Responding to Attacks

A

Stopping Reconnaissance Attacks
Denying International Attackers
Using Dynamic Block Lists

86
Q

Cisco ASA Tasks

A

Configure IPS
Configure NAT
Implement VPN via ASA Device Manager

87
Q

pFsense tasks

A

PCAP Analysis
Analyze Network Traffic with pftop
Using syslog to identify access

88
Q

Python?

A
  • If statement, For, While loops
  • If/else
  • While loop
  • Python functions
89
Q

Powershell?

A
  • Piping
  • Scripting basics
  • Common commands
90
Q

Regex?

A
  • Queries basics
  • Building Regex:
  • Extracting Data from Windows logs
  • Extracting data from firwall logs
91
Q

SQL?

A
  • Statements: Select, Delte, Update, Insert

- Creating Views