Question 11

Which of the following ES features would a security analyst use while investigating a network anomaly notable?
  • Question 12

    Which of the following is a risk of using the Auto Deployment feature of Distributed Configuration Management to distribute indexes.conf?
  • Question 13

    What are the steps to add a new column to the Notable Event table in the Incident Review dashboard?
  • Question 14

    Which of the following actions may be necessary before installing ES?
  • Question 15

    Which of the following are the default ports that must be configured for Splunk Enterprise Security to function?