Question 16

When configuring a Splunk asset for Phantom to connect to a SplunkC loud instance, the user discovers that they need to be able to run two different on_poll searches. How is this possible
  • Question 17

    Which of the following is an asset ingestion setting in SOAR?
  • Question 18

    Which of the following cannot be marked as evidence in a container?
  • Question 19

    What are the differences between cases and events?
  • Question 20

    How can a child playbook access the parent playbook's action results?