What is the maximum recommended volume of indexing per day, per indexer, for a non-cloud (on-prem) ES deployment?
Answer : B
ES needs to be installed on a search head with which of the following options?
Answer : D
Which settings indicated that the correlation search will be executed as new events are indexed?
Answer : C
At what point in the ES installation process should Splunk_TA_ForIndexes.spl be deployed to the indexers?
Answer : C
What role should be assigned to a security team member who will be taking ownership of notable events in the incident review dashboard?
Answer : B
Where are attachments to investigations stored?
Answer : A
What does the risk framework add to an object (user, server or other type) to indicate increased risk?
Answer : D