Which of the following are the default ports that must be configured on Splunk to allow connections from SOAR?
Which of the following accurately describes the Files tab on the Investigate page?
A user has written a playbook that calls three other playbooks, one after the other. The user notices that the second playbook starts executing before the first one completes. What is the cause of this behavior?
Phantom supports multiple user authentication methods such as LDAP and SAML2. What other user authentication method is supported?
What does a user need to do to have a container with an event from Splunk use context-aware actions designed for notable events?
To limit the impact of custom code on the VPE, where should the custom code be placed?
Which of the following is a step when configuring event forwarding from Splunk to Phantom?
A filter block with only one condition configured which states: artifact.*.cef .sourceAddress !- , would permit which of the following data to pass forward to the next block?
Some of the playbooks on the SOAR server should only be executed by members of the admin role. How can this rule be applied?
Some of the playbooks on the Phantom server should only be executed by members of the admin role. How can this rule be applied?
When writing a custom function that uses regex to extract the domain name from a URL, a user wants to create a new artifact for the extracted domain. Which of the following Python API calls will create a new artifact?
How can a user with the username "pat" configure the Analyst Queue to only show new events that are assigned to the current user?
When the Splunk App for SOAR Export executes a Splunk search, which activities are completed?
Which is the primary system requirement that should be increased with heavy usage of the file vault?
Which of the following actions will store a compressed, secure version of an email attachment with suspected malware for future analysis?
In addition to full backups. Phantom supports what other backup type using backup?
Seventy can be set during ingestion and later changed manually. What other mechanism can change the severity or a container?