Question 86

What role should be assigned to a security team member who will be taking ownership of notable events in the incident review dashboard?
  • Question 87

    What feature of Enterprise Security downloads threat intelligence data from a web server?
  • Question 88

    A site has a single existing search head which hosts a mix of both CIM and non-CIM compliant applications. All of the applications are mission-critical. The customer wants to carefully control cost, but wants good ES performance. What is the best practice for installing ES?
  • Question 89

    What should be used to map a non-standard field name to a CIM field name?
  • Question 90

    Which of the following is part of tuning correlation searches for a new ES installation?