Splunk Enterprise Security Certified Analyst — Question 47
A customer has downloaded the Splunk App for AWS from Splunkbase and installed it in a search head cluster following the instructions using the deployer. A power user modifies a dashboard in the app on one of the search head cluster members. The app containing an updated dashboard is upgraded to the latest version by following the instructions via the deployer.
What happens?
Answer options
- A. The updated dashboard will not be deployed globally to all users, due to the conflict with the power user's modified version of the dashboard.
- B. Applying the search head cluster bundle will fail due to the conflict.
- C. The updated dashboard will be available to the power user.
- D. The updated dashboard will not be available to the power user; they will see their modified version.
Correct answer: D
Explanation
The correct answer is D because the power user's modifications take precedence over the updated version of the dashboard, resulting in the user only seeing their version. A is incorrect as the updated dashboard won't deploy globally, but it doesn't specify the user's view accurately. B is also incorrect because the bundle application will not fail; it will simply not update the user's modified dashboard. C is wrong as the user will not gain access to the updated version.