SPLK-2003 Exam Questions
124 real SPLK-2003 exam questions with expert-verified answers and explanations. Page 3 of 3.
- Question #101Working with the API
How is a Django filter query performed?
Django filter queryREST searchURL parametersSOAR API - Question #102Ingesting and Handling Data
Which of the following is an asset ingestion setting in SOAR?
asset ingestionpolling intervalasset configurationingestion settings - Question #103Ingesting and Handling Data
When configuring a Splunk asset for SOAR to connect to a Splunk Cloud instance, the user discovers that they need to be able to run two different on_poll searches. How is this poss...
Splunk asseton_pollasset configurationmulti-query ingestion - Question #104Developing Playbooks
What is the primary objective of using the I2A2 playbook design methodology?
I2A2 methodologyplaybook designmodular playbooksreusability - Question #105Splunk SOAR Environment
Which of the following is a reason to create a new role in SOAR?
rolesRBACapp accesspermissions - Question #106Developing Playbooks
Which two playbook blocks can discern which path in the playbook to take next?
decision blockprompt blockplaybook flowconditional logic - Question #107Automating Tasks
Configuring SOAR search to use an external Splunk server provides which of the following benefits?
external Splunk searchsearch configurationSplunk integrationautomated search - Question #108Ingesting and Handling Data
Where can the Splunk App for SOAR Export be downloaded from?
Splunk App for SOAR ExportSplunkbaseGitHubapp installation - Question #109Working with the API
When writing a custom function that uses regex to extract the domain name from a URL, a user wants to create a new artifact for the extracted domain. Which of the following Python...
Python APIphantom.create_artifactartifact creationcustom function - Question #110Developing Playbooks
In a playbook, more than one Action block can be active at one time. What is this called?
parallel processingaction blocksplaybook executionconcurrency - Question #111Ingesting and Handling Data
Under Asset Ingestion Settings, how many labels must be applied when configuring an asset?
asset ingestionlabelsasset configurationingestion settings - Question #112Splunk SOAR Environment
Which of the following can be done with the System Health Display?
System Health DisplaySOAR monitoringprocess statusadministration - Question #113Splunk SOAR Environment
What metrics can be seen from the System Health Display? (select all that apply)
System Health Displaymemory usagedisk usageload average - Question #114Ingesting and Handling Data
When the Splunk App for SOAR Export executes a Splunk search, which activities are completed?
CIMCEFdata mappingcontainer creation - Question #115Splunk SOAR Environment
The SOAR server has been configured to use an external Splunk search head for search and searching on SOAR works; however, the search results don't include content that was being r...
external searchPhantomsearch capabilitytroubleshootingSplunk integration - Question #116Developing Playbooks
Which of the following is an advantage of using the Visual Playbook Editor?
Visual Playbook Editorplaybook designmaintenanceeditor features - Question #117Developing Playbooks
A user has written a playbook that calls three other playbooks, one after the other. The user notices that the second playbook starts executing before the first one completes. What...
synchronous executionplaybook chainingexecution orderplaybook configuration - Question #118Ingesting and Handling Data
Where in SOAR can a user view the JSON data for a container?
containerJSON dataInvestigation pagedata inspection - Question #119Developing Playbooks
When assigning an input parameter to an action while building a playbook, a user notices the artifact value they are looking for does not appear in the auto-populated list. How is...
CEF datapathartifact parametersaction configurationplaybook building - Question #120Automating Tasks
Which of the following actions will store a compressed, secure version of an email attachment with suspected malware for future analysis?
Secure Storefile storagemalware handlingevidence management - Question #121Splunk SOAR Environment
Without customizing container status within SOAR, what are the three types of status for a container?
container statuscontainer managementSOAR defaults - Question #122Splunk SOAR Environment
Which of the following are the default ports that must be configured on Splunk to allow connections from SOAR?
port configurationSplunk integrationSplunkWebHEC - Question #123Splunk SOAR Environment
What users are included in a new installation of SOAR?
user managementdefault usersadmin userautomation user - Question #124Ingesting and Handling Data
A user selects the New option under Sources on the menu. What will be displayed?
data ingestionsources menuingestion wizard