Question 16
When configuring a Splunk asset for Phantom to connect to a SplunkC loud instance, the user discovers that they need to be able to run two different on_poll searches. How is this possible
Question 17
Which of the following is an asset ingestion setting in SOAR?
Question 18
Which of the following cannot be marked as evidence in a container?
Question 19
What are the differences between cases and events?
Question 20
How can a child playbook access the parent playbook's action results?
