An incident field is created having the display name as Source_IP. How can the field be accessed?
Which two features can be used together to automatically execute a search on a remote SIEM for extracted IP Indicators? (Choose two.).
An analyst wants to run a script to remove usernames from an incident before the incident becomes active in XSOAR. How can this be achieved?
Where is a custom layout for an incident configured?.
Which of the following does a XSOAR Admin need to create an integration with a third party cloud application?
What aggregates data from incidents and indicators into a Cortex XSOAR report?.
What are the three ways to add/mark entries as evidence inside the Evidence Board? (Choose three.)
Which investigation element is best suited for collaboration among users?
What is an example of a generic reputation command?
Which three support types are included in the Marketplace Content Packs? (Choose three.)