In addition to full backups. Phantom supports what other backup type using backup?
Regarding the Splunk SOAR Automation Broker requirements, which of the following statements is not correct?
When configuring a Splunk asset for SOAR to connect to a Splunk Cloud instance, the user discovers that they need to be able to run two different on_poll searches. How is this possible?
When writing a custom function that uses regex to extract the domain name from a URL, a user wants to create a new artifact for the extracted domain. Which of the following Python API calls will create a new artifact?
Which of the following queries would return all artifacts that contain a SHA1 file hash?
What metrics can be seen from the System Health Display? (select all that apply)
The SOAR server has been configured to use an external Splunk search head for search and searching on SOAR works; however, the search results don't include content that was being returned by search before configuring external search. Which of the following could be the problem?
Why is it good playbook design to create smaller and more focused playbooks? (select all that apply)
When configuring a Splunk asset for Phantom to connect to a SplunkC loud instance, the user discovers that they need to be able to run two different on_poll searches. How is this possible
Splunk user account(s) with which roles must be created to configure Phantom with an external Splunk Enterprise instance?
What is the primary objective of using the I2A2 playbook design methodology?
Some of the playbooks on the SOAR server should only be executed by members of the admin role. How can this rule be applied?
Which of the following will show all artifacts that have the term results in a filePath CEF value?
Which of the following are the default ports that must be configured on Splunk to allow connections from Phantom?
Which of the following views provides a holistic view of an incident - providing event metadata, Service Level Agreement status, Severity, sensitivity of an event, and other detailed event info?
Within the 12A2 design methodology, which of the following most accurately describes the last step?