nerdexam
Splunk

SPLK-3001 · Question #76

What role should be assigned to a security team member who will be taking ownership of notable events in the incident review dashboard?

The correct answer is C. ess_analyst. https://docs.splunk.com/Documentation/ES/6.1.0/Install/ConfigureUsersRoles

Investigations and Incident Review

Question

What role should be assigned to a security team member who will be taking ownership of notable events in the incident review dashboard?

Options

  • Aess_user
  • Bess_admin
  • Cess_analyst
  • Dess_reviewer

How the community answered

(35 responses)
  • B
    3% (1)
  • C
    94% (33)
  • D
    3% (1)

Explanation

https://docs.splunk.com/Documentation/ES/6.1.0/Install/ConfigureUsersRoles

Topics

#ess_analyst#ES roles#incident review#notable events

Community Discussion

No community discussion yet for this question.

Full SPLK-3001 Practice