최신 SPLK-2003 무료덤프 - Splunk Phantom Certified Admin
A new project requires event data from SOAR to be sent to an external system via REST. All events with the label notable that are in new status should be sent. Which of the following REST Django expressions will select the correct events?
정답: C
설명: (DumpTOP 회원만 볼 수 있음)
The SOAR server has been configured to use an external Splunk search head for search and searching on SOAR works; however, the search results don't include content that was being returned by search before configuring external search. Which of the following could be the problem?
정답: B
설명: (DumpTOP 회원만 볼 수 있음)
Which of the following queries would return all artifacts that contain a SHA1 file hash?
정답: C
설명: (DumpTOP 회원만 볼 수 있음)
Which of the following expressions will output debug information to the debug window in the Visual Playbook Editor?
정답: C
설명: (DumpTOP 회원만 볼 수 있음)
How can a user with the username "pat" configure the Analyst Queue to only show new events that are assigned to the current user?
정답: D
설명: (DumpTOP 회원만 볼 수 있음)
What are indicators?
정답: D
설명: (DumpTOP 회원만 볼 수 있음)
Which of the following is an advantage of using the Visual Playbook Editor?
정답: D
설명: (DumpTOP 회원만 볼 수 있음)
Which app allows a user to send Splunk Enterprise Security notable events to Phantom?
정답: A
설명: (DumpTOP 회원만 볼 수 있음)
Which of the following is true about a child playbook?
정답: B
설명: (DumpTOP 회원만 볼 수 있음)
After a successful POST to a Phantom REST endpoint to create a new object what result is returned?
정답: D
설명: (DumpTOP 회원만 볼 수 있음)