How is Splunk platform secured?
What are the additional security measures of Splunk?
What is FIPS mode?
FIPS mode (federal information processing standard – FIPS 140-2) – if enabled, Splunk automatically configures all security to comply with US federal government standards. You have to enable FIPS mode before starting Splunk for the first time.
A Splunk __ultimately determines what a user can do and cannot do (privileges)
role
Name some examples of capabilities
Name the Splunk built in roles
You can use the ___command to see capabilities of a particular role
btool
What are the two ways to create and edit a role?
* Configuration file – authorize.comf
Why create a custome role?
How do you create a custom role using conf files?
What are the four authentication mechanisms that are supported?
• native
o always on, cannot be disabled
o users can be added, edited and deleted from Splunk web
o users maintained in $SPLUNK_HOME/etc/passwd file
• External LDAP
o most common
o integrates AD
• SAML
o open standard used to assert security info via XML
• Scripted authentication – can use own authentication systems
What do you need to know before creating an LDAP strategy?
What are some features of single sign-on?
___is required for Single sign on
SAML
Why Multi factor authentication?
What are the supported multi-factor integrations?
* RSA security