Which correlation search feature is used to throttle the creation of notable events?
Correct Answer:
C
Reference: https://docs.splunk.com/Documentation/ES/6.1.0/Admin/Configurecorrelationsearches
What does the risk framework add to an object (user, server or other type) to indicate increased risk?
Correct Answer:
C
Reference: https://docs.splunk.com/Documentation/ES/6.1.0/User/RiskScoring
Which settings indicated that the correlation search will be executed as new events are indexed?
Correct Answer:
C
Reference: https://docs.splunk.com/Documentation/ES/6.1.0/Admin/Configurecorrelationsearches
When ES content is exported, an app with a .spl extension is automatically created. What is the best practice when exporting and importing updates to ES content?
Correct Answer:
A
Which of the following are examples of sources for events in the endpoint security domain dashboards?
Correct Answer:
D
Reference: https://docs.splunk.com/Documentation/ES/6.1.0/User/EndpointProtectionDomaindashboards