If a username does not match the 'identity' column in the identities list, which column is checked next?
Where are attachments to investigations stored?
Which of the following threat intelligence types can ES download? (Choose all that apply)
What role should be assigned to a security team member who will be taking ownership of notable events in the incident review dashboard?
Adaptive response action history is stored in which index?