A user wants to use their Splunk Cloud instance as the external Splunk instance for Phantom. What ports need to be opened on the Splunk Cloud instance to facilitate this? Assume default ports are in use.
When configuring a Splunk asset for SOAR to connect to a Splunk Cloud instance, the user discovers that they need to be able to run two different on_poll searches. How is this possible?
When working with complex data paths, which operator is used to access a sub-element inside another element?
Which of the following are the default ports that must be configured on Splunk to allow connections from SOAR?
Which of the following expressions will output debug information to the debug window in the Visual Playbook Editor?
A customer wants to design a modular and reusable set of playbooks that all communicate with each other. Which of the following is a best practice for data sharing across playbooks?
Which of the following supported approaches enables Phantom to run on a Windows server?
On the Splunk search head, when configuring the app to search SOAR searchable content, what are the two requirements to complete the app setup?
Which of the following will show all artifacts that have the term results in a filePath CEF value?
Phantom supports multiple user authentication methods such as LDAP and SAML2. What other user authentication method is supported?
A user has written a playbook that calls three other playbooks, one after the other. The user notices that the second playbook starts executing before the first one completes. What is the cause of this behavior?
When analyzing events, a working on a case, significant items can be marked as evidence. Where can ail of a case's evidence items be viewed together?
An active playbook can be configured to operate on all containers that share which attribute?
Which of the following are examples of things commonly done with the Phantom REST APP
In a playbook, more than one Action block can be active at one time. What is this called?
Regarding the Splunk SOAR Automation Broker requirements, which of the following statements is not correct?
During a second test of a playbook, a user receives an error that states: 'an empty parameters list was passed to phantom.act()." What does this indicate?
A user selects the New option under Sources on the menu. What will be displayed?