最新的Splunk Phantom Certified Admin - SPLK-2003免費考試真題
A filter block with only one condition configured which states: artifact.*.cef .sourceAddress !- , would permit which of the following data to pass forward to the next block?
正確答案: C
說明:(僅 Fast2test 成員可見)
Playbooks typically handle which types of data?
正確答案: B
Which of the following expressions will output debug information to the debug window in the Visual Playbook Editor?
正確答案: B
說明:(僅 Fast2test 成員可見)
Which of the following is a reason to create a new role in SOAR?
正確答案: B
說明:(僅 Fast2test 成員可見)
When assigning an input parameter to an action while building a playbook, a user notices the artifact value they are looking for does not appear in the auto-populated list.
How is it possible to enter the unlisted artifact value?
How is it possible to enter the unlisted artifact value?
正確答案: D
說明:(僅 Fast2test 成員可見)
Without customizing container status within Phantom, what are the three types of status for a container?
正確答案: C
說明:(僅 Fast2test 成員可見)
Which set of steps will show the most detailed information for action results on the Investigation page?
正確答案: A
During a second test of a playbook, a user receives an error that states: "an empty parameters list was passed to phantom.act()." What does this indicate?
正確答案: A
說明:(僅 Fast2test 成員可見)
How is a Django filter query performed?
正確答案: D
說明:(僅 Fast2test 成員可見)