Why is it good playbook design to create smaller and more focused playbooks? (select all that apply)
Without customizing container status within Phantom, what are the three types of status for a container?
Seventy can be set during ingestion and later changed manually. What other mechanism can change the severity or a container?
Regarding the Splunk SOAR Automation Broker requirements, which of the following statements is not correct?
After a successful POST to a Phantom REST endpoint to create a new object what result is returned?
Which app allows a user to send Splunk Enterprise Security notable events to Phantom?
What is enabled if the Logging option for a playbook's settings is enabled?
In a playbook, more than one Action block can be active at one time. What is this called?
Which two playbook blocks can discern which path in the playbook to take next?
Which of the following are the default ports that must be configured on Splunk to allow connections from Phantom?
During a second test of a playbook, a user receives an error that states: 'an empty parameters list was passed to phantom.act()." What does this indicate?
Which of the following accurately describes the Files tab on the Investigate page?
When writing a custom function that uses regex to extract the domain name from a URL, a user wants to create a new artifact for the extracted domain. Which of the following Python API calls will create a new artifact?
Within the 12A2 design methodology, which of the following most accurately describes the last step?
Which of the following will show all artifacts that have the term results in a filePath CEF value?
What metrics can be seen from the System Health Display? (select all that apply)
A user has written a playbook that calls three other playbooks, one after the other. The user notices that the second playbook starts executing before the first one completes. What is the cause of this behavior?
How can a user with the username "pat" configure the Analyst Queue to only show new events that are assigned to the current user?
Which of the following supported approaches enables Phantom to run on a Windows server?
A filter block with only one condition configured which states: artifact.*.cef .sourceAddress !- , would permit which of the following data to pass forward to the next block?
Which of the following are the default ports that must be configured on Splunk to allow connections from SOAR?
Splunk user account(s) with which roles must be created to configure Phantom with an external Splunk Enterprise instance?
When assigning an input parameter to an action while building a playbook, a user notices the artifact value they are looking for does not appear in the auto-populated list.
How is it possible to enter the unlisted artifact value?