Splunk SPLK-2003 - Splunk SOAR Certified Automation Developer Exam
Which Phantom API command is used to create a custom list?
When analyzing events, a working on a case, significant items can be marked as evidence. Where can ail of a case's evidence items be viewed together?
Which of the following cannot be marked as evidence in a container?
A customer wants to design a modular and reusable set of playbooks that all communicate with each other. Which of the following is a best practice for data sharing across playbooks?
When working with complex data paths, which operator is used to access a sub-element inside another element?
Which of the following can be edited or deleted in the Investigation page?
Which Phantom VPE Nock S used to add information to custom lists?
Which of the following applies to filter blocks?
How can an individual asset action be manually started?
Which of the following accurately describes the Files tab on the Investigate page?