Which two incident search queries are valid? (Choose two.)
Answer : A, D
What is the most effective way to correlate multiple raw events coming from a SIEM and link them together?
Answer : C
How is data transferred between playbook tasks?
Answer : A
What does Script helper contain?
Answer : A
Which two advanced attributes can be applied to incident fields when editing? (Choose two.)
Answer : A, B
Which configuration is a valid distributed database (DB) implementation?
Answer : B
An engineer notices that playbooks only start once the user clicks the 'investigate' button and he/she would like the playbook to start automatically.
How can this be implemented?
Answer : B