Question 26

What role should be assigned to a security team member who will be taking ownership of notable events in the incident review dashboard?
  • Question 27

    ES apps and add-ons from $SPLUNK_HOME/etc/apps should be copied from the staging instance to what location on the cluster deployer instance?
  • Question 28

    Which two fields combine to create the Urgency of a notable event?
  • Question 29

    When installing Enterprise Security, what should be done after installing the add-ons necessary for normalizing data?
  • Question 30

    A newly built custom dashboard needs to be available to a team of security analysts in ES.
    How is it possible to integrate the new dashboard?