Question 46

A site has a single existing search head which hosts a mix of both CIM and non-CIM compliant applications. All of the applications are mission-critical. The customer wants to carefully control cost, but wants good ES performance.
What is the best practice for installing ES?
  • Question 47

    Which feature contains scenarios that are useful during ES Implementation?
  • Question 48

    An administrator is asked to configure an "Nslookup" adaptive response action, so that it appears as a selectable option in the notable event's action menu when an analyst is working in the Incident Review dashboard. What steps would the administrator take to configure this option?
  • Question 49

    To which of the following should the ES application be uploaded?
  • Question 50

    Which settings indicated that the correlation search will be executed as new events are indexed?