A user wants to use their Splunk Cloud instance as the external Splunk instance for Phantom. What ports need to be opened on the Splunk Cloud instance to facilitate this? Assume default ports are in use.
Two action blocks, geolocate_ip 1 and file_reputation_2, are connected to a decision block. Which of the following is a correct configuration for making a decision on the action results from one of the given blocks?
How is a Django filter query performed?
How is it possible to evaluate user prompt results?
In addition to full backups. Phantom supports what other backup type using backup?
Which of the following can be configured in the ROl Settings?
What is the primary objective of using the I2A2 playbook design methodology?
Which of the following cannot be marked as evidence in a container?
Which of the following will show all artifacts that have the term results in a filePath CEF value?
Which of the following are the steps required to complete a full backup of a Splunk Phantom deployment' Assume the commands are executed from /opt/phantom/bin and that no other backups have been made.
Which of the following can be configured in the ROI Settings?
Some of the playbooks on the Phantom server should only be executed by members of the admin role. How can this rule be applied?
During a second test of a playbook, a user receives an error that states: 'an empty parameters list was passed to phantom.act()." What does this indicate?
Which of the following are examples of things commonly done with the Phantom REST APP
When analyzing events, a working on a case, significant items can be marked as evidence. Where can ail of a case's evidence items be viewed together?
Playbooks typically handle which types of data?
Seventy can be set during ingestion and later changed manually. What other mechanism can change the severity or a container?
How can parent and child playbooks pass information to each other?
Without customizing container status within Phantom, what are the three types of status for a container?
Where in SOAR can a user view the JSON data for a container?
An active playbook can be configured to operate on all containers that share which attribute?
Which of the following items cannot be modified once entered into SOAR?
On a multi-tenant Phantom server, what is the default tenant's ID?
Which app allows a user to run Splunk queries from within Phantom?
Which of the following can the format block be used for?
Phantom supports multiple user authentication methods such as LDAP and SAML2. What other user authentication method is supported?
On the Splunk search head, when configuring the app to search SOAR searchable content, what are the two requirements to complete the app setup?
How can a user with the username "pat" configure the Analyst Queue to only show new events that are assigned to the current user?
What values can be applied when creating Custom CEF field?
Which Phantom API command is used to create a custom list?
How can more than one user perform tasks in a workbook?
A user has written a playbook that calls three other playbooks, one after the other. The user notices that the second playbook starts executing before the first one completes. What is the cause of this behavior?
Which of the following accurately describes the Files tab on the Investigate page?