|
所在平台: Udemy |
课程主页: https://www.udemy.com/course/splunk-enterprise-security-certified-admin-tests-splk-3001-m/
课程评论:没有评论
课程名称:Splunk Enterprise Security Certified Admin Tests-SPLK-3001 课程概述:本课程旨在减少您的练习时间,课程结束时会提供解释和参考资料,帮助您提高知识水平。这些题目在Splunk管理员面试中非常有用。Splunk Enterprise Certified Admin考试是完成Splunk认证的最后一步,考试时长为57分钟,共48道题,评估候选人在安装、配置和管理Splunk Enterprise Security方面的知识和技能。建议考生完成与管理Splunk Enterprise Security相关的讲座、实践实验和测验,以便为认证考试做好准备。重要提示:参加认证考试时,考生有3分钟的时间审查并接受Splunk认证协议,如果未在指定时间内接受,考试会被终止。 管理Splunk Enterprise Security课程主要针对管理Splunk Enterprise Security环境的管理员,包括ES事件处理和规范化、部署要求、技术附加组件、设置、风险分析设置、威胁情报和协议情报配置及自定义。 课程主题包括: 1. ES简介(5%) - ES功能与概念概述 2. 监控与调查(10%) - 安全态势、事件审查、显著事件管理和调查 3. 安全情报(5%) - 安全情报工具概述 4. 取证、玻璃表和导航控制(10%) - 取证仪表板探讨,玻璃表分析,导航和仪表板权限配置 5. ES部署(10%) - 部署拓扑识别,部署检查表,ES索引策略和数据模型 6. 安装与配置(15%) - 为安装准备Splunk环境,下载和安装ES,了解用户账号与角色,安装后的配置任务 7. 验证ES数据(10%) - 规划ES输入,配置技术附加组件 8. 自定义附加组件(5%) - 设计用于自定义数据的新附加组件,使用附加组件构建器构建新附加组件 9. 调整关联搜索(10%) - 配置关联搜索调度与敏感性,调整ES关联搜索 10. 创建关联搜索(10%) - 创建自定义关联搜索,配置自适应响应,搜索导出/导入 11. 查找功能和身份管理(5%) - 确定特定于ES的查找,理解并配置查找列表 12. 威胁情报框架(5%) - 理解并配置威胁情报,配置用户活动分析 如果您需要关于Splunk开发的任何支持,请随时与我联系。我很乐意提供帮助。
This course will cut down on your practice time. Explanation and references are provided at the end of the practice test to help you improve your knowledge. These questions will come in handy during the Splunk Admin interview. The Splunk Enterprise Certified Admin exam is final step towards the completion of the Splunk certification. This exam is a 57-minute, 48-questions assessment which evaluates a candidate's knowledge and skills in the installation, configuration, and management of Splunk Enterprise Security. It is recommended that candidates for this certification complete the lecture, hands-on labs, and quizzes that are part of the Administering Splunk Enterprise Security course, in order to be prepared for the certification exam. IMPORTANT: When you sit for your certification exam, you will have 3 minutes to review and accept the Splunk Certification Agreement. Exam sessions will be terminated if this is not accepted within the designated time-frame. The Administering Splunk Enterprise Security course focuses on Administrators who manage a Splunk Enterprise Security environment, including ES event processing and normalization, deployment requirements, technology add-ons, settings, risk analysis settings, threat intelligence and protocol intelligence configuration, and customizations. Topics Include: 1.0 ES Introduction 5%1.1 Overview of ES features and concepts2.0 Monitoring and Investigation 10%2.1 Security posture2.2 Incident review2.3 Notable events management2.4 Investigations3.0 Security Intelligence 5%3.1 Overview of security intel tools4.0 Forensics, Glass Tables, and Navigation Control 10%4.1 Explore forensics dashboards4.2 Examine glass tables4.3 Configure navigation and dashboard permissions5.0 ES Deployment 10%5.1 Identify deployment topologies5.2 Examine the deployment checklist5.3 Understand indexing strategy for ES5.4 Understand ES Data Models6.0 Installation and Configuration 15%6.1 Prepare a Splunk environment for installation6.2 Download and install ES on a search head6.3 Understand ES Splunk user accounts and roles6.4 Post-install configuration tasks7.0 Validating ES Data 10%7.1 Plan ES inputs7.2 Configure technology add-ons8.0 Custom Add-ons 5%8.1 Design a new add-on for custom data8.2 Use the Add-on Builder to build a new add-on9.0 Tuning Correlation Searches 10%9.1 Configure correlation search scheduling and sensitivity9.2 Tune ES correlation searches10.0 Creating Correlation Searches 10%10.1 Create a custom correlation search10.2 Configuring adaptive responses10.3 Search export/import11.0 Lookups and Identity Management 5%11.1 Identify ES-specific lookups11.2 Understand and configure lookup lists12.0 Threat Intelligence Framework 5%12.1 Understand and configure threat intelligence12.2 Configure user activity analysisPlease reach out to me if you need any support on Splunk Development. I am happy to help.