Splunk
SPLK-2003
Q1:
Which of the following accurately describes the Files tab on the Investigate page?
○
A
A user can upload the output from a detonate action to the the files tab for further investigation.○
B
Files tab items and artifacts are the only data sources that can populate active cases.○
C
Files tab items cannot be added to investigations. Instead, add them to action blocks.○
D
Phantom memory requirements remain static, regardless of Files tab usage.
Splunk
SPLK-2003
Q2:
Is it possible to import external Python libraries such as the time module?
○
A
No.○
B
No, but this can be changed by setting the proper permissions.○
C
Yes, in the global block.○
D
Yes. from a drop down menu.
Splunk
SPLK-2003
Q3:
What is enabled if the Logging option for a playbook's settings is enabled?
○
A
More detailed logging information Is available m the Investigation page.○
B
All modifications to the playbook will be written to the audit log.○
C
More detailed information is available in the debug window.○
D
The playbook will write detailed execution information into the spawn.log.
Splunk
SPLK-2003
Q4:
What values can be applied when creating Custom CEF field?
○
A
Name○
B
Name, Data Type○
C
Name, Value○
D
Name, Data Type, Severity
Splunk
SPLK-2003
Q5:
Some of the playbooks on the Phantom server should only be executed by members of the admin role. How can this rule be applied?
○
A
Add a filter block to al restricted playbooks that Titters for runRole - 'Admin''.○
B
Add a tag with restricted access to the restricted playbooks.○
C
Make sure the Execute Playbook capability is removed from al roles except admin.○
D
Place restricted playbooks in a second source repository that has restricted access.