Which of the following supported approaches enables Phantom to run on a Windows server?
Seventy can be set during ingestion and later changed manually. What other mechanism can change the severity or a container?
During a second test of a playbook, a user receives an error that states: 'an empty parameters list was passed to phantom.act()." What does this indicate?
A user wants to get the playbook results for a single artifact. Which steps will accomplish the?
The SOAR server has been configured to use an external Splunk search head for search and searching on SOAR works; however, the search results don't include content that was being returned by search before configuring external search. Which of the following could be the problem?
Within the 12A2 design methodology, which of the following most accurately describes the last step?
Which of the following will show all artifacts that have the term results in a filePath CEF value?
Splunk user account(s) with which roles must be created to configure Phantom with an external Splunk Enterprise instance?
When analyzing events, a working on a case, significant items can be marked as evidence. Where can ail of a case's evidence items be viewed together?
In addition to full backups. Phantom supports what other backup type using backup?
Which of the following accurately describes the Files tab on the Investigate page?
What is enabled if the Logging option for a playbook's settings is enabled?
Which of the following roles is appropriate for a Splunk SOAR account that will only be used to execute automated tasks?
Is it possible to import external Python libraries such as the time module?
When writing a custom function that uses regex to extract the domain name from a URL, a user wants to create a new artifact for the extracted domain. Which of the following Python API calls will create a new artifact?
Which of the following are the default ports that must be configured on Splunk to allow connections from Phantom?