Q: 11
When analyzing events, a working on a case, significant items can be marked as evidence. Where can
ail of a case's evidence items be viewed together?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 12
A filter block with only one condition configured which states: artifact.*.cef .sourceAddress !- ,
would permit which of the following data to pass forward to the next block?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 13
Which of the following accurately describes the Files tab on the Investigate page?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 14
When is using decision blocks most useful?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 15
After a playbook has run, where are the results stored?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 16
Under Asset Ingestion Settings, how many labels must be applied when configuring an asset?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 17
Which is the primary system requirement that should be increased with heavy usage of the file
vault?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 18
Configuring Phantom search to use an external Splunk server provides which of the following
benefits?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 19
After a successful POST to a Phantom REST endpoint to create a new object what result is returned?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Question 11 of 20 · Page 2 / 2