Question 1

What role should be assigned to a security team member who will be taking ownership of notable events in the incident review dashboard?
  • Question 2

    Which of the following lookup types in Enterprise Security contains information about known hostile IP addresses?
  • Question 3

    Which of the following are data models used by ES? (Choose all that apply.)
  • Question 4

    An administrator is asked to configure an "Nslookup" adaptive response action, so that it appears as a selectable option in the notable event's action menu when an analyst is working in the Incident Review dashboard. What steps would the administrator take to configure this option?
  • Question 5

    Where should an ES search head be installed?