Question 16

Which of the following ES features would a security analyst use while investigating a network anomaly notable?
  • Question 17

    Following the Installation of ES, an admin configured Leers with the ss_uso r role the ability to close notable events. How would the admin restrict these users from being able to change the status of Resolved notable events to closed?
  • Question 18

    At what point in the ES installation process should Splunk_TA_ForIndexes.spl be deployed to the indexers?
  • Question 19

    Which of the following ES features would a security analyst use while investigating a network anomaly notable?
  • Question 20

    What does the Security Posture dashboard display?