After installing Enterprise Security, the distributed configuration management tool can be used to create which app to configure indexers?
Correct Answer:D
Reference: https://docs.splunk.com/Documentation/ES/6.1.0/Install/InstallTechnologyAdd-ons
Which correlation search feature is used to throttle the creation of notable events?
Correct Answer:C
Reference: https://docs.splunk.com/Documentation/ES/6.1.0/Admin/Configurecorrelationsearches
Which of the following is a way to test for a property normalized data model?
Correct Answer:B
Reference: https://docs.splunk.com/Documentation/CIM/4.15.0/User/UsetheCIMtonormalizedataatsearchtime
When investigating, what is the best way to store a newly-found IOC?
Correct Answer:B
ES needs to be installed on a search head with which of the following options?
Correct Answer:A
Reference: https://docs.splunk.com/Documentation/ES/6.1.0/Install/InstallEnterpriseSecurity