When working with complex data paths, which operator is used to access a sub-element inside another element?
Within the 12A2 design methodology, which of the following most accurately describes the last step?
Regarding the Splunk SOAR Automation Broker requirements, which of the following statements is not correct?
Splunk user account(s) with which roles must be created to configure Phantom with an external Splunk Enterprise instance?
In this image, which container fields are searched for the text "Malware"?
An active playbook can be configured to operate on all containers that share which attribute?
Phantom supports multiple user authentication methods such as LDAP and SAML2. What other user authentication method is supported?
Which of the following is an advantage of using the Visual Playbook Editor?
When configuring a Splunk asset for SOAR to connect to a Splunk Cloud instance, the user discovers that they need to be able to run two different on_poll searches. How is this possible?
When analyzing events, a working on a case, significant items can be marked as evidence. Where can ail of a case's evidence items be viewed together?
Which of the following are the default ports that must be configured on Splunk to allow connections from SOAR?
A user has written a playbook that calls three other playbooks, one after the other. The user notices that the second playbook starts executing before the first one completes. What is the cause of this behavior?
What metrics can be seen from the System Health Display? (select all that apply)
To limit the impact of custom code on the VPE, where should the custom code be placed?
Some of the playbooks on the SOAR server should only be executed by members of the admin role. How can this rule be applied?
When writing a custom function that uses regex to extract the domain name from a URL, a user wants to create a new artifact for the extracted domain. Which of the following Python API calls will create a new artifact?
A user wants to use their Splunk Cloud instance as the external Splunk instance for Phantom. What ports need to be opened on the Splunk Cloud instance to facilitate this? Assume default ports are in use.