Leads4pass > Splunk > Splunk SOAR Certified Automation Developer > SPLK-2003 > SPLK-2003 Online Practice Questions and Answers

SPLK-2003 Online Practice Questions and Answers

Questions 4

Under Asset Ingestion Settings, how many labels must be applied when configuring an asset?

A. Labels are not configured under Asset Ingestion Settings.

B. One.

C. One or more.

D. Zero or more.

Buy Now
Questions 5

An active playbook can be configured to operate on all containers that share which attribute?

A. Artifact

B. Label

C. Tag

D. Severity

Buy Now
Questions 6

Which of the following is a step when configuring event forwarding from Splunk to Phantom?

A. Map CIM to CEF fields.

B. Create a Splunk alert that uses the event_forward.py script to send events to Phantom.

C. Map CEF to CIM fields.

D. Create a saved search that generates the JSON for the new container on Phantom.

Buy Now
Questions 7

Without customizing container status within Phantom, what are the three types of status for a container?

A. New, In Progress, Closed

B. Low, Medium, High

C. Mew, Open, Resolved

D. Low, Medium, Critical

Buy Now
Questions 8

On a multi-tenant Phantom server, what is the default tenant's ID?

A. 0

B. Default

C. 1

D. *

Buy Now
Questions 9

Where in SOAR can a user view the JSON data for a container?

A. In the analyst queue.

B. On the Investigation page.

C. In the data ingestion display.

D. In the audit log.

Buy Now
Questions 10

A user wants to get the playbook results for a single artifact. Which steps will accomplish the?

A. Use the contextual menu from the artifact and select run playbook.

B. Use the run playbook dialog and set the scope to the artifact.

C. Create a new container including Just the artifact in question.

D. Use the contextual menu from the artifact and select the actions.

Buy Now
Questions 11

Which of the following can be configured in the ROl Settings?

A. Analyst hours per month.

B. Time lost.

C. Number of full time employees (FTEs).

D. Annual analyst salary.

Buy Now
Questions 12

How can the DECIDED process be restarted?

A. By restarting the playbook daemon.

B. On the System Health page.

C. In Administration > Server Settings.

D. By restarting the automation service.

Buy Now
Questions 13

Which of the following queries would return all artifacts that contain a SHA1 file hash?

A. https:///rest/artifact?_filter_cef_md5_insull=false

B. https:///rest/artifact?_filter_cef_Shal_contains=""

C. https:///rest/artifact?_filter_cef_shal_insull=False

D. https:///rest/artifact?_filter_shal__insull=False

Buy Now
Exam Code: SPLK-2003
Exam Name: Splunk SOAR Certified Automation Developer
Last Update: Dec 18, 2024
Questions: 96
10%OFF Coupon Code: SAVE10

PDF (Q&A)

$49.99

VCE

$55.99

PDF + VCE

$65.99