Question 31
Which of the following are the default ports that must be configured for Splunk Enterprise Security to function?
Question 32
How is it possible to navigate to the list of currently-enabled ES correlation searches?
Question 33
What should be used to map a non-standard field name to a CIM field name?
Question 34
What does the risk framework add to an object (user, server or other type) to indicate increased risk?
Question 35
Where are attachments to investigations stored?
