Splunk Enterprise Security Certified Admin — Question 45

Where should an ES search head be installed?

Answer options

Correct answer: C

Explanation

The correct answer is C because an ES search head requires a fresh installation of Splunk to function properly. Options A and D suggest specific configurations that may not be suitable for a dedicated search head, while option B is too vague and does not ensure the necessary setup.