What should be used to map a non-standard field name to a CIM field name?
A
A customer site is experiencing poor performance. The UI response time is high and searches take a
very long time to run. Some operations time out and there are errors in the scheduler logs, indicating
too many concurrent searches are being started. 6 total correlation searches are scheduled and they
have already been tuned to weed out false positives.
Which of the following options is most likely to help performance?
C
Following the installation of ES, an admin configured users with the ess_user role the ability to close
notable events.
How would the admin restrict these users from being able to change the status of Resolved notable
events to Closed?
C
What can be exported from ES using the Content Management page?
C
Explanation:
Reference:
https://docs.splunk.com/Documentation/ES/6.4.1/Admin/Export#:~:text=as%20an%20app-,Export
%20content%20from%20Splunk%20Enterprise%20Security%20as,from%20the%20Content%20Mana
gement
%20page.&text=You%20can%20export%20any%20type,%2C%20data%20models%2C%20and%20vie
ws.
Accelerated data requires approximately how many times the daily data volume of additional storage
space per year?
A
Explanation:
Reference:
https://docs.splunk.com/Documentation/ES/6.4.1/Install/Datamodels
When installing Enterprise Security, what should be done after installing the add-ons necessary for
normalizing data?
A
How is it possible to specify an alternate location for accelerated storage?
C
A security manager has been working with the executive team en long-range security goals. A
primary goal for the team Is to Improve managing user risk in the organization. Which of the
following ES features can help identify users accessing inappropriate web sites?
C
Which of the following is part of tuning correlation searches for a new ES installation?
A
What do threat gen searches produce?
D
Explanation:
https://docs.splunk.com/Documentation/ES/6.4.1/Admin/Createthreatmatchspecs
Which of the following steps will make the Threat Activity dashboard the default landing page in ES?
C
What is an example of an ES asset?
A
After managing source types and extracting fields, which key step comes next In the Add-On Builder?
D
The option to create a Short ID for a notable event is located where?
B
Explanation:
https://docs.splunk.com/Documentation/ES/6.4.1/User/Takeactiononanotableevent
Which feature contains scenarios that are useful during ES Implementation?
B
Explanation:
Reference:
https://www.splunk.com/pdfs/professional-services/2019/splunk-enterprise-security
-
implementation-success.pdf