Question 76

What does a user need to do to have a container with an event from Splunk use context-aware actions designed for notable events?
  • Question 77

    When analyzing events, a working on a case, significant items can be marked as evidence. Where can ail of a case's evidence items be viewed together?
  • Question 78

    What is the default embedded search engine used by Phantom?
  • Question 79

    Which of the following accurately describes the Files tab on the Investigate page?
  • Question 80

    Which of the following can the format block be used for?