SPLK-2003 Exam Questions
124 real SPLK-2003 exam questions with expert-verified answers and explanations. Page 2 of 3.
- Question #51Splunk SOAR Environment
Which of the following accurately describes the Files tab on the Investigate page?
Files tabinvestigate pagedetonate actioncase management - Question #52Splunk SOAR Environment
Without customizing container status within Phantom, what are the three types of status for a container?
container statuscontainer managementNew In Progress Closed - Question #53Splunk SOAR Environment
Splunk user account(s) with which roles must be created to configure Phantom with an external Splunk Enterprise instance?
user rolesSplunk integrationauthenticationsuperuser - Question #54Splunk SOAR Environment
Phantom supports multiple user authentication methods such as LDAP and SAML2. What other user authentication method is supported?
authentication methodsLDAPSAMLPIV/CAC - Question #55Developing Playbooks
During a second test of a playbook, a user receives an error that states: "an empty parameters list was passed to phantom.act()." What does this indicate?
playbook debuggingphantom.act()error handlingartifacts vs parameters - Question #56Ingesting and Handling Data
What does a user need to do to have a container with an event from Splunk use context-aware actions designed for notable events?
notable eventsCEF definitionevent_idSplunk integration - Question #57Splunk SOAR Environment
After enabling multi-tenancy, which of the Mowing is the first configuration step?
multi-tenancytenant configurationdefault tenant - Question #58Ingesting and Handling Data
When configuring a Splunk asset for Phantom to connect to a SplunkC loud instance, the user discovers that they need to be able to run two different on_poll searches. How is this p...
on_pollSplunk assetmultiple queriesdata ingestion - Question #59Splunk SOAR Environment
Which of the following can be edited or deleted in the Investigation page?
investigation pageaction resultscase managementUI - Question #60Developing Playbooks
Which visual playbook editor block is used to assemble commands and data into a valid Splunk search within a SOAR playbook?
format blockVPESplunk searchplaybook automation - Question #61Splunk SOAR Environment
Which of the following contains official SOAR documentation for the latest releases?
SOAR documentationdocs.splunk.comSOAR Serverrelease notes - Question #62Developing Playbooks
Two action blocks, geolocate_ip_1 and file_reputation_2, are connected to a decision block. Which of the following is a correct configuration for making a decision on the action re...
decision blockaction_result data pathplaybook blocksdata path syntax - Question #63Splunk SOAR Environment
Which of the following items cannot be modified once entered into SOAR?
artifact immutabilitycontainer dataSOAR data modelnotes vs artifacts - Question #64Splunk SOAR Environment
Which of the following can be done with the System Health Display?
System Health DisplaySOAR processesadministrationprocess monitoring - Question #65Developing Playbooks
Which of the following is accurate?
phantom.debug()VPE debuggerPython debuggingSOAR logging - Question #66Developing Playbooks
Playbooks typically handle which types of data?
playbook data typescontainer dataartifact CEFlist data - Question #67Splunk SOAR Environment
Which of the following are tabs of an asset configuration?
asset configurationasset tabsaccess controlapproval settings - Question #68Ingesting and Handling Data
Splunk user account(s) with which roles must be created to configure SOAR with an external Splunk Enterprise instance?
Splunk rolesphantomsearchphantomdeleteSOAR-Splunk integration - Question #69Developing Playbooks
Which of the following is a way to access lists?
listsSOAR navigationplaybook resourcescustom lists - Question #70Splunk SOAR Environment
How can the DECIDED process be restarted?
DECIDED processSystem Health pageSOAR processesprocess restart - Question #71Working with the API
Which of the following queries would return all failed playbook runs from the REST API?
REST APIplaybook_run endpointfilter query syntax_query_status - Question #72Automating Tasks
How can a playbook run searches on a Splunk search head?
Splunk apprun_query actionsearch integrationSplunk search head - Question #73Developing Playbooks
In a playbook, more than one Action block can be active at one time. What is this called?
parallel processingaction blocksconcurrent executionplaybook flow - Question #74Ingesting and Handling Data
Which Splunk search command is used to send a notable event to SOAR?
sendtophantomnotable eventsSplunk integrationevent ingestion - Question #75Splunk SOAR Environment
Which of the following is a reason to create a new role in SOAR?
SOAR rolesapp permissionsaccess controluser management - Question #76Splunk SOAR Environment
Which of the following roles is appropriate for a Splunk SOAR account that will only be used to execute automated tasks?
Automation roleservice accountSOAR rolesautomated tasks - Question #77Developing Playbooks
If two or more conditions apply to data in a filter block, which path is followed in the playbook?
filter blockmultiple conditionsparallel pathsplaybook logic - Question #78Splunk SOAR Environment
If the SOAR New status is removed and replaced by In Progress, what status is shown for containers that had the new status before the replacement?
container statusstatus replacementSOAR administrationcustom statuses - Question #79Ingesting and Handling Data
On the Splunk search head, when configuring the app to search SOAR searchable content, what are the two requirements to complete the app setup?
Splunk search headapp configurationREST APIHTTP Event Collector - Question #80Splunk SOAR Environment
What metrics can be seen from the System Health Display? (Choose all that apply.)
System Health Displaydisk usagememory usageload average - Question #81Splunk SOAR Environment
What primary integrations does Splunk SOAR provide for Role administration? (Choose all that apply.)
role administrationLDAPSAMLauthentication - Question #82Ingesting and Handling Data
Which of the following cannot be marked as evidence in a container?
evidencecontainersartifactsinvestigation - Question #83Developing Playbooks
What is the primary objective of using the I2A2 playbook design methodology?
I2A2 methodologyplaybook designmodular playbooks - Question #84Splunk SOAR Environment
Which set of steps will show the most detailed information for action results on the Investigation page?
investigation pageaction resultsrecent activity pane - Question #85Splunk SOAR Environment
What users are included in a new installation of SOAR?
default usersadmin userautomation userinstallation - Question #86Splunk SOAR Environment
In the SOAR main menu, there are sub-options below Sources. What is the purpose of these options?
main menuSourcescontainer filtersnavigation - Question #87Developing Playbooks
If no data matches any filter conditions, what is the next block run by the playbook?
filter blockplaybook flowno data matchconditions - Question #88Splunk SOAR Environment
How can more than one user perform tasks in a workbook?
workbookstask assignmentrolespermissions - Question #89Working with the API
Which of the following queries would return all artifacts that contain a SHA1 file hash?
REST APIartifact filteringCEF fieldsSHA1 - Question #90Splunk SOAR Environment
What is the default embedded search engine used by SOAR?
search enginesystem configurationSOAR settings - Question #91Automating Tasks
How can the DECIDED process be restarted?
DECIDED processautomation servicesystem health - Question #92Splunk SOAR Environment
Which of the following can be configured in the ROI Settings?
ROI settingsFTE configurationanalyst metrics - Question #93Developing Playbooks
What are the components of the I2A2 design methodology?
I2A2 methodologyinputsartifactsplaybook design - Question #94Developing Playbooks
Some of the playbooks on the SOAR server should only be executed by members of the admin role. How can this rule be applied?
playbook securityrole permissionsExecute Playbook capability - Question #95Splunk SOAR Environment
Which of the following can be edited or deleted in the Investigation page?
investigation pagecommentseditingartifact values - Question #96Developing Playbooks
Why is it good playbook design to create smaller and more focused playbooks? (select all that apply)
playbook designcode reusemodular playbooksmaintainability - Question #97Splunk SOAR Environment
What is the default log level for system health debug logs?
log levelsystem healthdebug logs - Question #98Developing Playbooks
Why does SOAR use wildcards within artifact data paths?
wildcardsartifact data pathsplaybook data access - Question #99Splunk SOAR Environment
Which of the following roles is appropriate for a Splunk SOAR account that will only be used to execute automated tasks?
automation roleuser accountsautomated tasks - Question #100Developing Playbooks
To limit the impact of custom code on the VPE, where should the custom code be placed?
custom codeVPEcustom function blockplaybook development