nerdexam
Splunk

SPLK-2003 · Question #75

Which of the following is a reason to create a new role in SOAR?

The correct answer is B. To define a set of users who have access to a restricted app.. In SOAR platforms, roles are the mechanism for controlling access to restricted apps (integrations/modules that require elevated permissions), making B correct - when an app is marked as restricted, only users assigned a role that explicitly grants access to that app can use it.

Splunk SOAR Environment

Question

Which of the following is a reason to create a new role in SOAR?

Options

  • ATo define a set of users who have access to a special label.
  • BTo define a set of users who have access to a restricted app.
  • CTo define a set of users who have access to a sensitive tag.
  • DTo define a set of users who have access to an event's reports.

How the community answered

(21 responses)
  • B
    95% (20)
  • D
    5% (1)

Explanation

In SOAR platforms, roles are the mechanism for controlling access to restricted apps (integrations/modules that require elevated permissions), making B correct - when an app is marked as restricted, only users assigned a role that explicitly grants access to that app can use it. Labels (A) and tags (C) are organizational/metadata tools used for categorizing incidents or objects; they don't require role-based access control and aren't protected by role creation. Reports on events (D) are typically governed by case or incident-level permissions, not by creating dedicated roles.

Memory tip: Think "R-R" - Roles = Restricted resources. When something in SOAR is locked down at the app/integration level, a Role is the key. Labels and tags are just sticky notes - anyone can read them.

Topics

#SOAR roles#app permissions#access control#user management

Community Discussion

No community discussion yet for this question.

Full SPLK-2003 Practice