Accelerated data requires approximately how many times the daily data volume of additional storage space per year?
#61
Answer: A✅ Correct❌ Incorrect
When installing Enterprise Security, what should be done after installing the add-ons necessary for normalizing data?
#62
Answer: D✅ Correct❌ Incorrect
What can be exported from ES using the Content Management page?
#63
Answer: C✅ Correct❌ Incorrect
Where should an ES search head be installed?
#64
Answer: C✅ Correct❌ Incorrect
Following the installation of ES, an admin configured users with the ess_user role the ability to close notable events.How would the admin restrict these users from being able to change the status of Resolved notable events to Closed?
#65
Answer: C✅ Correct❌ Incorrect
Which of the following actions may be necessary before installing ES?
#66
Answer: D✅ Correct❌ Incorrect
A customer site is experiencing poor performance. The UI response time is high and searches take a very long time to run. Some operations time out and there are errors in the scheduler logs, indicating too many concurrent searches are being started. 6 total correlation searches are scheduled and they have already been tuned to weed out false positives.Which of the following options is most likely to help performance?
#67
Answer: C✅ Correct❌ Incorrect
What should be used to map a non-standard field name to a CIM field name?
#68
Answer: A✅ Correct❌ Incorrect
Which of the following lookup types in Enterprise Security contains information about known hostile IP addresses?
#69
Answer: B✅ Correct❌ Incorrect
A set of correlation searches are enabled at a new ES installation, and results are being monitored. One of the correlation searches is generating many notable events which, when evaluated, are determined to be false positives.What is a solution for this issue?
#70
Answer: C✅ Correct❌ Incorrect
Which of the following steps will make the Threat Activity dashboard the default landing page in ES?
#71
Answer: B✅ Correct❌ Incorrect
When using distributed configuration management to create the Splunk_TA_ForIndexers package, which three files can be included?
#72
Answer: A✅ Correct❌ Incorrect
Which feature contains scenarios that are useful during ES implementation?
#73
Answer: B✅ Correct❌ Incorrect
Where is detailed information about identities stored?
#74
Answer: D✅ Correct❌ Incorrect
The option to create a Short ID for a notable event is located where?
#75
Answer: B✅ Correct❌ Incorrect
A newly built custom dashboard needs to be available to a team of security analysts in ES.How is it possible to integrate the new dashboard?
#76
Answer: A✅ Correct❌ Incorrect
What is the bar across the bottom of any ES window?
#77
Answer: B✅ Correct❌ Incorrect
Which two fields combine to create the Urgency of a notable event?
#78
Answer: A✅ Correct❌ Incorrect
What do threat gen searches produce?
#79
Answer: C✅ Correct❌ Incorrect
Which of the following is part of tuning correlation searches for a new ES installation?
#80
Answer: B✅ Correct❌ Incorrect
Which columns in the Assets lookup are used to identify an asset in an event?
#81
Answer: C✅ Correct❌ Incorrect
What does the summariesonly=true option do for a correlation search?
#82
Answer: A✅ Correct❌ Incorrect
Which of the following are the default ports that must be configured for Splunk Enterprise Security to function?
#83
Answer: A✅ Correct❌ Incorrect
What is the main purpose of the Dashboard Requirements Matrix document?
#84
Answer: A✅ Correct❌ Incorrect
Which of the following is a recommended pre-installation step?
#85
Answer: C✅ Correct❌ Incorrect
What are adaptive responses triggered by?
#86
Answer: A✅ Correct❌ Incorrect
Which of the following is an adaptive action that is configured by default for ES?
#87
Answer: B✅ Correct❌ Incorrect
When creating custom correlation searches, what format is used to embed field values in the title, description, and drill-down fields of a notable event?
#88
Answer: A✅ Correct❌ Incorrect
Which lookup table does the Default Account Activity Detected correlation search use to flag known default accounts?