Question 31

Which of the following are the default ports that must be configured for Splunk Enterprise Security to function?
  • Question 32

    How is it possible to navigate to the list of currently-enabled ES correlation searches?
  • Question 33

    What should be used to map a non-standard field name to a CIM field name?
  • Question 34

    What does the risk framework add to an object (user, server or other type) to indicate increased risk?
  • Question 35

    Where are attachments to investigations stored?