Summer Special Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: myex65

Home > Splunk > Splunk SOAR Certified Automation Developer > SPLK-2003

SPLK-2003 Splunk SOAR Certified Automation Developer Exam Question and Answers

Question # 4

Which of the following is an asset ingestion setting in SOAR?

A.

Polling Interval

B.

Tag

C.

File format

D.

Operating system

Full Access
Question # 5

Is it possible to import external Python libraries such as the time module?

A.

No.

B.

No, but this can be changed by setting the proper permissions.

C.

Yes, in the global block.

D.

Yes. from a drop-down menu.

Full Access
Question # 6

Some of the playbooks on the Phantom server should only be executed by members of the admin role. How can this rule be applied?

A.

Add a filter block to al restricted playbooks that Titters for runRole - "Admin''.

B.

Add a tag with restricted access to the restricted playbooks.

C.

Make sure the Execute Playbook capability is removed from al roles except admin.

D.

Place restricted playbooks in a second source repository that has restricted access.

Full Access
Question # 7

Splunk user account(s) with which roles must be created to configure Phantom with an external Splunk Enterprise instance?

A.

superuser, administrator

B.

phantomcreate. phantomedit

C.

phantomsearch, phantomdelete

D.

admin,user

Full Access
Question # 8

Which of the following can be done with the System Health Display?

A.

Create a temporary, edited version of a process and test the results.

B.

Partially rewind processes, which is useful for debugging.

C.

View a single column of status for SOAR processes. For metrics, click Details.

D.

Reset DECIDED to reset playbook environments back to at-start conditions.

Full Access
Question # 9

Some of the playbooks on the SOAR server should only be executed by members of the admin role. How can this rule be applied?

A.

Make sure the Execute Playbook capability is removed from all roles except admin.

B.

Place restricted playbooks in a second source repository that has restricted access.

C.

Add a filter block to all restricted playbooks that filters for runRole = "Admin".

D.

Add a tag with restricted access to the restricted playbooks.

Full Access
Question # 10

How can an individual asset action be manually started?

A.

With the > action button in the analyst queue page.

B.

By executing a playbook in the Playbooks section.

C.

With the > action button in the Investigation page.

D.

With the > asset button in the asset configuration section.

Full Access
Question # 11

What is the main purpose of using a customized workbook?

A.

Workbooks automatically implement a customized processing of events using Python code.

B.

Workbooks guide user activity and coordination during event analysis and case operations.

C.

Workbooks apply service level agreements (SLAs) to containers and monitor completion status on the ROI dashboard.

D.

Workbooks may not be customized; only default workbooks are permitted within Phantom.

Full Access
Question # 12

Which of the following are the default ports that must be configured on Splunk to allow connections from Phantom?

A.

SplunkWeb (8088), SplunkD (8089), HTTP Collector (8000)

B.

SplunkWeb (8089), SplunkD (8088), HTTP Collector (8000)

C.

SplunkWeb (8421), SplunkD (8061), HTTP Collector (8798)

D.

SplunkWeb (8000), SplunkD (8089), HTTP Collector (8088)

Full Access
Question # 13

When analyzing events, a working on a case, significant items can be marked as evidence. Where can ail of a case's evidence items be viewed together?

A.

Workbook page Evidence tab.

B.

Evidence report.

C.

Investigation page Evidence tab.

D.

At the bottom of the Investigation page widget panel.

Full Access
Question # 14

A user selects the New option under Sources on the menu. What will be displayed?

A.

A list of new assets.

B.

The New Data Ingestion wizard.

C.

A list of new data sources.

D.

A list of new events.

Full Access
Question # 15

An active playbook can be configured to operate on all containers that share which attribute?

A.

Artifact

B.

Label

C.

Tag

D.

Severity

Full Access
Question # 16

Which of the following is the complete list of the types of backups that are supported by Phantom?

A.

Full backups.

B.

Full, delta, and incremental backups.

C.

Full and incremental backups.

D.

Full and delta backups.

Full Access
Question # 17

A user has written a playbook that calls three other playbooks, one after the other. The user notices that the second playbook starts executing before the first one completes. What is the cause of this behavior?

A.

Incorrect Join configuration on the second playbook.

B.

The first playbook is performing poorly.

C.

The steep option for the second playbook is not set to a long enough interval.

D.

Synchronous execution has not been configured.

Full Access
Question # 18

When assigning an input parameter to an action while building a playbook, a user notices the artifact value they are looking for does not appear in the auto-populated list.

How is it possible to enter the unlisted artifact value?

A.

Type the CEF datapath in manually.

B.

Delete and recreate the artifact.

C.

Edit the artifact to enable the List as Parameter option for the CEF value.

D.

Edit the container to allow CEF parameters.

Full Access
Question # 19

Why is it good playbook design to create smaller and more focused playbooks? (select all that apply)

A.

Reduces amount of playbook data stored in each repo.

B.

Reduce large complex playbooks which become difficult to maintain.

C.

Encourages code reuse in a more compartmentalized form.

D.

To avoid duplication of code across multiple playbooks.

Full Access
Question # 20

What is the default log level for system health debug logs?

A.

INFO

B.

WARN

C.

ERROR

D.

DEBUG

Full Access
Question # 21

Configuring SOAR search to use an external Splunk server provides which of the following benefits?

A.

The ability to run more complex reports on SOAR activities.

B.

The ability to ingest Splunk notable events into SOAR.

C.

The ability to automate Splunk searches within SOAR.

D.

The ability to display results as Splunk dashboards within SOAR.

Full Access
Question # 22

Which of the following is a reason to create a new role in SOAR?

A.

To define a set of users who have access to a special label.

B.

To define a set of users who have access to a restricted app.

C.

To define a set of users who have access to an event's reports.

D.

To define a set of users who have access to a sensitive tag.

Full Access
Question # 23

What are the differences between cases and events?

A.

Case: potential threats.

Events: identified as a specific kind of problem and need a structured approach.

B.

Cases: only include high-level incident artifacts.

Events: only include low-level incident artifacts.

C.

Cases: contain a collection of containers.

Events: contain potential threats.

D.

Cases: incidents with a known violation and a plan for correction.

Events: occurrences in the system that may require a response.

Full Access
Question # 24

How can the DECIDED process be restarted?

A.

By restarting the playbook daemon.

B.

On the System Health page.

C.

In Administration > Server Settings.

D.

By restarting the automation service.

Full Access
Question # 25

What values can be applied when creating Custom CEF field?

A.

Name

B.

Name, Data Type

C.

Name, Value

D.

Name, Data Type, Severity

Full Access
Question # 26

Which is the primary system requirement that should be increased with heavy usage of the file vault?

A.

Amount of memory.

B.

Number of processors.

C.

Amount of storage.

D.

Bandwidth of network.

Full Access
Question # 27

Which of the following can be edited or deleted in the Investigation page?

A.

Action results

B.

Comments

C.

Approval records

D.

Artifact values

Full Access
Question # 28

What metrics can be seen from the System Health Display? (select all that apply)

A.

Playbook Usage

B.

Memory Usage

C.

Disk Usage

D.

Load Average

Full Access