Following the Installation of ES, an admin configured Leers with the ss_uso r role the ability to close notable events. How would the admin restrict these users from being able to change the status of Resolved notable events to closed?
Correct Answer: A
Explanation According to the Splunk Enterprise Security documentation, the Status Configuration window allows you to customize the status values and transitions for notable events. You can define which roles can change the status of a notable event from one value to another, and which roles can view the notable events with a specific status. To restrict the users with the ess_user role from being able to change the status of Resolved notable events to closed, you need to do the following steps: On the Enterprise Security menu bar, select Configure > Incident Management > Status Configuration. In the Status Configuration window, select the Resolved status from the list of values. In the Status Transitions section, find the row for the closed status and click the Edit icon. In the Edit Status Transition dialog box, remove the ess_user role from the Roles field and click Save. Click Save Changes to apply the changes to the Status Configuration window. This will prevent the users with the ess_user role from changing the status of any notable event from Resolved to closed. They will still be able to change the status of other notable events to closed, if they have the permission to do so. Therefore, the correct answer is A. From the Status Configuration window select the Resolved status. Remove ess_user from the status transitions for the closed status. References = Customize status values and transitions for notable events.
Question 18
At what point in the ES installation process should Splunk_TA_ForIndexes.spl be deployed to the indexers?
Correct Answer: D
Question 19
Which of the following ES features would a security analyst use while investigating a network anomaly notable?
Correct Answer: B
Question 20
What does the Security Posture dashboard display?
Correct Answer: B
Explanation The Security Posture dashboard is designed to provide high-level insight into the notable events across all domains of your deployment, suitable for display in a Security Operations Center (SOC). This dashboard