SPLK-2003 Exam Questions
124 real SPLK-2003 exam questions with expert-verified answers and explanations. Page 1 of 3.
- Question #1Working with the API
Which of the following are examples of things commonly done with the Phantom REST APP
Phantom REST APPcurlcontainersartifacts - Question #2Splunk SOAR Environment
Which of the following are the default ports that must be configured on Splunk to allow connections from SOAR?
port configurationSplunk integrationSplunkDHTTP Collector - Question #3Splunk SOAR Environment
On a multi-tenant Phantom server, what is the default tenant's ID?
multi-tenanttenant IDPhantom configuration - Question #4Ingesting and Handling Data
What are indicators?
indicatorsartifactscontainersCEF - Question #5Splunk SOAR Environment
Which app allows a user to send Splunk Enterprise Security notable events to Phantom?
Splunk App for Phantomnotable eventsEnterprise Securityintegration - Question #6Developing Playbooks
Some of the playbooks on the Phantom server should only be executed by members of the admin role. How can this rule be applied?
role-based accessplaybook permissionsadmin rolecapabilities - Question #7Ingesting and Handling Data
What values can be applied when creating Custom CEF field?
custom CEF fieldsCEFdata typeartifact fields - Question #8Developing Playbooks
What is enabled if the Logging option for a playbook's settings is enabled?
playbook loggingInvestigation pageplaybook settingsdebug - Question #9Developing Playbooks
Is it possible to import external Python libraries such as the time module?
Python librariesglobal blockplaybook scriptingimport - Question #10Automating Tasks
How can an individual asset action be manually started?
asset actionsInvestigation pagemanual executionaction button - Question #11Splunk SOAR Environment
What is the default embedded search engine used by Phantom?
embedded search engineSplunkPhantom configuration - Question #12Developing Playbooks
A filter block with only one condition configured which states: artifact.*.cef .sourceAddress !- , would permit which of the following data to pass forward to the next block?
filter blockCEFsourceAddressplaybook logic - Question #13Developing Playbooks
A user wants to get the playbook results for a single artifact. Which steps will accomplish the?
playbook executionartifact scopecontextual menuInvestigation page - Question #14Splunk SOAR Environment
What is the main purpose of using a customized workbook?
workbooksevent analysiscase managementuser coordination - Question #15Ingesting and Handling Data
Which of the following is a step when configuring event forwarding from Splunk to Phantom?
event forwardingSplunk integrationevent_forward.pyalert configuration - Question #16Splunk SOAR Environment
Which is the primary system requirement that should be increased with heavy usage of the file vault?
file vaultsystem requirementsstorageinfrastructure - Question #17Working with the API
Which of the following will show all artifacts that have the term results in a filePath CEF value?
REST APIartifact queryCEF filePathicontain filter - Question #18Splunk SOAR Environment
Which of the following can be configured in the ROl Settings?
ROI settingsFTEanalyst metricsconfiguration - Question #19Developing Playbooks
Which of the following expressions will output debug information to the debug window in the Visual Playbook Editor?
phantom.debug()debug outputVisual Playbook Editorplaybook scripting - Question #20Splunk SOAR Environment
Which of the following supported approaches enables Phantom to run on a Windows server?
OVAvirtual machineWindowsdeployment - Question #21Developing Playbooks
Which of the following can the format block be used for?
format blockstring generationdynamic valuesplaybook blocks - Question #22Splunk SOAR Environment
When analyzing events a working on a case, significant items can be marked as evidence. Where can ail of a case's evidence items be viewed together?
case managementevidenceInvestigation pageworkbook - Question #23Developing Playbooks
When working with complex datapaths, which operator is used to access a sub-element inside another element?
datapathsdot operatorsub-elementsdata access - Question #24Developing Playbooks
Which of the following is a best practice for use of the global block?
global blockpackage importplaybook codebest practices - Question #25Splunk SOAR Environment
In this image, which container fields are searched for the text "Malware"?
container searchevent filteringartifact searchSOAR UI - Question #26Splunk SOAR Environment
Which of the following is the complete list of the types of backups that are supported by Phantom?
backup typessystem administrationfull backupincremental backup - Question #27Developing Playbooks
How can the debug log for a playbook execution be viewed?
debug logplaybook executionInvestigation pagetroubleshooting - Question #28Ingesting and Handling Data
Which of the following describes the use of labels m Phantom?
labelscontainerplaybook triggeringautomation rules - Question #29Developing Playbooks
What is the simplest way to pass data between playbooks?
inter-playbook communicationartifactsdata passingKV Store - Question #30Splunk SOAR Environment
What do assets provide for app functionality?
assetsapp configurationcredentialsaction parameters - Question #31Working with the API
After a successful POST to a Phantom REST endpoint to create a new object what result is returned?
REST APIPOST requestobject creationAPI response - Question #32Developing Playbooks
After a playbook has run, where are the results stored?
playbook resultscontainerdata storageexecution results - Question #33Automating Tasks
Seventy can be set during ingestion and later changed manually. What other mechanism can change the severity or a container?
severitycontainer propertiesplaybooksautomation - Question #34Splunk SOAR Environment
In addition to full backups. Phantom supports what other backup type using backup?
backup typesincremental backupsystem administrationPhantom administration - Question #35Developing Playbooks
How can a child playbook access the parent playbook's action results?
child playbookparent playbookscope configurationdata sharing - Question #36Splunk SOAR Environment
How does a user determine which app actions are available?
app actionsApps menusupported actionsapp discovery - Question #37Splunk SOAR Environment
What are the differences between cases and events?
caseseventscontainerscase management - Question #38Working with the API
Which Phantom API command is used to create a custom list?
custom listPhantom APIphantom.create_listAPI commands - Question #39Automating Tasks
Configuring Phantom search to use an external Splunk server provides which of the following benefits?
Splunk integrationexternal searchsearch automationSOAR configuration - Question #40Developing Playbooks
Within the 12A2 design methodology, which of the following most accurately describes the last step?
I2A2 methodologyplaybook designoutputsdesign methodology - Question #41Splunk SOAR Environment
Which of the following are the steps required to complete a full backup of a Splunk Phantom deployment' Assume the commands are executed from /opt/phantom/bin and that no other bac...
backupibackupphenvadministration - Question #42Developing Playbooks
An active playbook can be configured to operate on all containers that share which attribute?
active playbookcontainer labelplaybook scope - Question #43Developing Playbooks
Which of the following applies to filter blocks?
filter blocksVPEdata selectionplaybook flow - Question #44Developing Playbooks
A user has written a playbook that calls three other playbooks, one after the other. The user notices that the second playbook starts executing before the first one completes. What...
synchronous executionplaybook chainingexecution orderchild playbooks - Question #45Developing Playbooks
A customer wants to design a modular and reusable set of playbooks that all communicate with each other. Which of the following is a best practice for data sharing across playbooks...
modular playbooksdata sharingartifactsbest practices - Question #46Splunk SOAR Environment
A user wants to use their Splunk Cloud instance as the external Splunk instance for Phantom. What ports need to be opened on the Splunk Cloud instance to facilitate this? Assume de...
Splunk Cloudnetwork portsexternal Splunkintegration - Question #47Splunk SOAR Environment
Which app allows a user to run Splunk queries from within Phantom?
Splunk App for Phantomintegrationapp catalog - Question #48Developing Playbooks
Which Phantom VPE Nock S used to add information to custom lists?
VPE blockscustom listsAPI blocks - Question #49Developing Playbooks
How is it possible to evaluate user prompt results?
user promptsaction_resultprompt evaluationplaybook logic - Question #50Developing Playbooks
When is using decision blocks most useful?
decision blocksplaybook flowconditional logicVPE