Splunk Enterprise Security Certified Analyst — Question 1

When adding a new search head to a search head cluster (SHC), which of the following scenarios occurs?

Answer options

Correct answer: D

Explanation

The correct answer is D because when a new search head is added, it first connects to the deployer to obtain the latest configuration bundle. Afterward, it connects to the captain to apply any recent configuration changes. Options A, B, and C are incorrect as they do not accurately describe the correct sequence of connections and actions that occur during this process.