A : https://help.splunk.com/en/splunk-enterprise-security-7/install/7.2/installation/configure-data-models-for-splunk-enterprise-security
After data is ingested, which data management step is essential to ensure raw data can be
accelerated by a Data Model and used by ES?
C
How does ES know local customer domain names so it can detect internal vs. external emails?
C
What are adaptive responses triggered by?
D
What is the main purpose of the Dashboard Requirements Matrix document?
D
What does the summariesonly=true option do for a correlation search?
A
Explanation:
Reference:
https://community.splunk.com/t5/Splunk-Enterprise-Security/Why-do-correlation-
searches-in- Enterprise-Security-not-use-quot/m-p/262622
Which columns in the Assets lookup are used to identify an asset in an event?
C
Explanation:
Reference:
https://docs.splunk.com/Documentation/ES/6.4.1/Admin/Formatassetoridentitylist
Which two fields combine to create the Urgency of a notable event?
A
Explanation:
Reference:
https://docs.splunk.com/Documentation/ES/6.4.1/User/Howurgencyisassigned
Where is detailed information about identities stored?
C
A set of correlation searches are enabled at a new ES installation, and results are being monitored.
One of the correlation searches is generating many notable events which, when evaluated, are
determined to be false positives.
What is a solution for this issue?
A
Which of the following lookup types in Enterprise Security contains information about known hostile
IP addresses?
B
Explanation:
Reference:
https://docs.splunk.com/Documentation/ES/6.4.1/Admin/Manageinternallookups
What should be used to map a non-standard field name to a CIM field name?
A
A customer site is experiencing poor performance. The UI response time is high and searches take a
very long time to run. Some operations time out and there are errors in the scheduler logs, indicating
too many concurrent searches are being started. 6 total correlation searches are scheduled and they
have already been tuned to weed out false positives.
Which of the following options is most likely to help performance?
C
Following the installation of ES, an admin configured users with the ess_user role the ability to close
notable events.
How would the admin restrict these users from being able to change the status of Resolved notable
events to Closed?
C
What can be exported from ES using the Content Management page?
C
Explanation:
Reference:
https://docs.splunk.com/Documentation/ES/6.4.1/Admin/Export#:~:text=as%20an%20app-,Export
%20content%20from%20Splunk%20Enterprise%20Security%20as,from%20the%20Content%20Mana
gement
%20page.&text=You%20can%20export%20any%20type,%2C%20data%20models%2C%20and%20vie
ws.
Accelerated data requires approximately how many times the daily data volume of additional storage
space per year?
A
Explanation:
Reference:
https://docs.splunk.com/Documentation/ES/6.4.1/Install/Datamodels
A : https://help.splunk.com/en/splunk-enterprise-security-7/install/7.2/installation/configure-data-models-for-splunk-enterprise-security