View Mode
Q: 11
When analyzing events, a working on a case, significant items can be marked as evidence. Where can ail of a case's evidence items be viewed together?
Options
Q: 12
A filter block with only one condition configured which states: artifact.*.cef .sourceAddress !- , would permit which of the following data to pass forward to the next block?
Options
Q: 13
Which of the following accurately describes the Files tab on the Investigate page?
Options
Q: 14
When is using decision blocks most useful?
Options
Q: 15
After a playbook has run, where are the results stored?
Options
Q: 16
Under Asset Ingestion Settings, how many labels must be applied when configuring an asset?
Options
Q: 17
Which is the primary system requirement that should be increased with heavy usage of the file vault?
Options
Q: 18
Configuring Phantom search to use an external Splunk server provides which of the following benefits?
Options
Q: 19
After a successful POST to a Phantom REST endpoint to create a new object what result is returned?
Options
Q: 20
Some of the playbooks on the Phantom server should only be executed by members of the admin role. How can this rule be applied?
Options
Question 11 of 20 · Page 2 / 2

Premium Access Includes

  • Quiz Simulator
  • Exam Mode
  • Progress Tracking
  • Question Saving
  • Flash Cards
  • Drag & Drops
  • 3 Months Access
  • PDF Downloads
Get Premium Access
Scroll to Top

FLASH OFFER

Days
Hours
Minutes
Seconds

avail 10% DISCOUNT on YOUR PURCHASE