When investigating, what is the best way to store a newly-found IOC?
Which of the following features can the Add-on Builder configure in a new add-on?
How should an administrator add a new look up through the ES app?
Which of the following steps will make the Threat Activity dashboard the default landing page in ES?
Which of the following are the default ports that must be configured for Splunk Enterprise Security to function?
Where is it possible to export content, such as correlation searches, from ES?
An administrator is asked to configure an “Nslookup” adaptive response action, so that it appears as a selectable option in the notable event’s action menu when an analyst is working in the Incident Review dashboard. What steps would the administrator take to configure this option?
Which of the following are data models used by ES? (Choose all that apply)
A security manager has been working with the executive team en long-range security goals. A primary goal for the team Is to Improve managing user risk in the organization. Which of the following ES features can help identify users accessing inappropriate web sites?
Which of the following actions can improve overall search performance?