This professional-level exam validates skills in installing, configuring, and managing Splunk Enterprise Security. It is intended for experienced Splunk platform administrators and cybersecurity professionals working with ES event processing, normalization, risk analysis, threat intelligence, and customizations. Splunk identifies it as a legacy certification whose content is no longer actively maintained or updated to reflect product changes.
Exam Topics
- ES Introduction5%
- Monitoring and Investigation10%
- Security Intelligence5%
- Forensics, Glass Tables, and Navigation Control10%
- ES Deployment10%
- Installation and Configuration15%
- Validating ES Data10%
- Custom Add-ons5%
- Tuning Correlation Searches10%
- Creating Correlation Searches10%
- Lookups and Identity Management5%
- Threat Intelligence Framework5%
How to Use This Practice Exam
- Browse — Read each question, select your answer, and reveal the explanation.
- Exam Mode — Simulate real exam conditions with a timed session and score report.
- Learn Mode — Spaced repetition schedules questions you struggle with for long-term retention.
Last updated September 29, 2020 at 12:02 AM