Two action blocks, geolocate_ip_1 and file_reputation_2, are connected to a decision block.
Which of the following is a correct configuration for making a decision on the action results from one of the given blocks?
A. Select parameter set to: file_reputation_2:action_result.cef.*.response_code; evaluation option set to: in; and the Select Value set to: United States.
B. Select parameter set to: file_reputation_2:action_result.data.*.response_code; evaluation option set to: ==; and the Select Value set to: custom_list:Banned Countries.
C. Select parameter set to: geolocate_ip_1:action_result.data.*.country_iso_code; evaluation option set to: in; and the Select Value set to: custom_list:Banned Countries.
D. Select parameter set to: geolocate_ip_1:action_result.cef.*.country_iso_code; evaluation option set to: !=; and the Select Value box left empty.
正解:C
質問 2:
How is a Django filter query performed?
A. By adding parameters to the URL similar to the following:
phantom/rest/container?_filter_tags_contains="sumo".
B. phantom/rest/search/app/contains/"sumo"
C. Install the SOAR Django App first, then configure the search query in the App editor.
D. Browse to the Django Filter Query Editor in the Administration panel.
正解:A
解説: (Pass4Test メンバーにのみ表示されます)
質問 3:
Which of the following can be done with the System Health Display?
A. Reset DECIDED to reset playbook environments back to at-start conditions.
B. Create a temporary, edited version of a process and test the results.
C. View a single column of status for SOAR processes. For metrics, click Details.
D. Partially rewind processes, which is useful for debugging.
正解:C
解説: (Pass4Test メンバーにのみ表示されます)
質問 4:
What is the main purpose of using a customized workbook?
A. Workbooks apply service level agreements (SLAs) to containers and monitor completion status on the ROI dashboard.
B. Workbooks may not be customized; only default workbooks are permitted within Phantom.
C. Workbooks automatically implement a customized processing of events using Python code.
D. Workbooks guide user activity and coordination during event analysis and case operations.
正解:D
解説: (Pass4Test メンバーにのみ表示されます)
質問 5:
Which of the following is the complete list of the types of backups that are supported by Phantom?
A. Full, delta, and incremental backups.
B. Full backups.
C. Full and delta backups.
D. Full and incremental backups.
正解:D
解説: (Pass4Test メンバーにのみ表示されます)
質問 6:
Without customizing container status within Phantom, what are the three types of status for a container?
A. Low, Medium, High
B. Low, Medium, Critical
C. Mew, Open, Resolved
D. New, In Progress, Closed
正解:D
解説: (Pass4Test メンバーにのみ表示されます)
質問 7:
Which of the following are the default ports that must be configured on Splunk to allow connections from SOAR?
A. SplunkWeb (8421), SplunkD (8061), HTTP Collector (8798)
B. SplunkWeb (8089), SplunkD (8088), HTTP Collector (8000)
C. SplunkWeb (8000), SplunkD (8089), HTTP Collector (8088)
D. SplunkWeb (8088), SplunkD (8089), HTTP Collector (8000)
正解:C
解説: (Pass4Test メンバーにのみ表示されます)
質問 8:
How can a playbook run searches on a Splunk search head?
A. Using the search action of the Search app.
B. Using the run_query action from the Splunk app.
C. Using the phantom.run_query() API function.
D. Use the HTTP app's get_data action to access the SOAR .../rest/splunk/query endpoint.
正解:B
曽田** -
よく出る問題を厳選した確認問題で
実力をチェックできますから超安心で受験して受かるという