Question 1
What role should be assigned to a security team member who will be taking ownership of notable events in the incident review dashboard?
Question 2
Which of the following lookup types in Enterprise Security contains information about known hostile IP addresses?
Question 3
Which of the following are data models used by ES? (Choose all that apply.)
Question 4
An administrator is asked to configure an "Nslookup" adaptive response action, so that it appears as a selectable option in the notable event's action menu when an analyst is working in the Incident Review dashboard. What steps would the administrator take to configure this option?
Question 5
Where should an ES search head be installed?
