Which of the following are the steps required to complete a full backup of a Splunk Phantom deployment' Assume the commands are executed from /opt/phantom/bin and that no other backups have been made.
A. On the command line enter: rode sudo python ibackup.pyc --setup, then audo phenv python ibackup.pyc --backup.
B. On the command line enter: sudo phenv python ibackup.pyc --backup --backup-type full, then sudo phenv python ibackup.pyc --setup.
C. Within the UI: Select from the main menu Administration > System Health > Backup.
D. Within the UI: Select from the main menu Administration > Product Settings > Backup.
Is it possible to import external Python libraries such as the time module?
A. No.
B. No, but this can be changed by setting the proper permissions.
C. Yes, in the global block.
D. Yes. from a drop-down menu.
Some of the playbooks on the SOAR server should only be executed by members of the admin role. How can this rule be applied?
A. Make sure the Execute Playbook capability is removed from all roles except admin.
B. Place restricted playbooks in a second source repository that has restricted access.
C. Add a filter block to all restricted playbooks that filters for runRole = "Admin".
D. Add a tag with restricted access to the restricted playbooks.
How is it possible to evaluate user prompt results?
A. Set action_result.summary. status to required.
B. Set the user prompt to reinvoke if it times out.
C. Set action_result. summary. response to required.
D. Add a decision Mode
A user has written a playbook that calls three other playbooks, one after the other. The user notices that the second playbook starts executing before the first one completes. What is the cause of this behavior?
A. Incorrect Join configuration on the second playbook.
B. The first playbook is performing poorly.
C. The steep option for the second playbook is not set to a long enough interval.
D. Synchronous execution has not been configured.
Configuring SOAR search to use an external Splunk server provides which of the following benefits?
A. The ability to run more complex reports on SOAR activities.
B. The ability to ingest Splunk notable events into SOAR.
C. The ability to automate Splunk searches within SOAR.
D. The ability to display results as Splunk dashboards within SOAR.
Which of the following is a reason to create a new role in SOAR?
A. To define a set of users who have access to a special label.
B. To define a set of users who have access to a restricted app.
C. To define a set of users who have access to an event's reports.
D. To define a set of users who have access to a sensitive tag.
Which of the following expressions will output debug information to the debug window in the Visual Playbook Editor?
A. phantom.debug()
B. phantom.exception()
C. phantom.print ()
D. phantom.assert()
Some of the playbooks on the Phantom server should only be executed by members of the admin role. How can this rule be applied?
A. Add a filter block to al restricted playbooks that Titters for runRole - "Admin''.
B. Add a tag with restricted access to the restricted playbooks.
C. Make sure the Execute Playbook capability is removed from al roles except admin.
D. Place restricted playbooks in a second source repository that has restricted access.
Which of the following queries would return all artifacts that contain a SHA1 file hash?
A. https://
B. https://
C. https://
D. https://