Splunk Enterprise Security Certified Admin — Question 63

How does ES know local customer domain names so it can detect internal vs. external emails?

Answer options

Correct answer: D

Explanation

The correct answer is D because the Corporate Web and Email Domain Lookups are specifically configured to help ES recognize local domains. Options A and B are incorrect as they describe different methods of handling domain names, and C is misleading because while machine learning may be involved, the initial recognition is dependent on the configuration done during setup.