SPLK-2003 Splunk SOAR Certified Automation Developer Exam Dumps

If you are looking for free SPLK-2003 dumps than here we have some sample question answers available. You can prepare from our Splunk SPLK-2003 exam questions notes and prepare exam with this practice test. Check below our updated SPLK-2003 exam dumps.

DumpsGroup are top class study material providers and our inclusive range of SPLK-2003 Real exam questions would be your key to success in Splunk Splunk SOAR Certified Automation Developer Certification Exam in just first attempt. We have an excellent material covering almost all the topics of Splunk SPLK-2003 exam. You can get this material in Splunk SPLK-2003 PDF and SPLK-2003 practice test engine formats designed similar to the Real Exam Questions. Free SPLK-2003 questions answers and free Splunk SPLK-2003 study material is available here to get an idea about the quality and accuracy of our study material.


discount banner

Sample Question 4

In a playbook, more than one Action block can be active at one time. What is this called?

A. Serial Processing
B. Parallel Processing
C. Multithreaded Processing
D. Juggle Processing


Sample Question 5

Which of the following are the default ports that must be configured on Splunk to allowconnections from SOAR?

A. SplunkWeb (8088), SplunkD (8089), HTTP Collector (8000)
B. SplunkWeb (8089), SplunkD (8088), HTTP Collector (8000)
C. SplunkWeb (8000), SplunkD (8089), HTTP Collector (8088)
D. SplunkWeb (8469), SplunkD (8702), HTTP Collector (8864)


Sample Question 6

Where can the Splunk App for SOAR Export be downloaded from?

A. GitHub and Splunkbase.
B. SOAR Community and GitHub.
C. Splunkbase and SOAR Community.
D. Splunk Answers and Splunkbase.


Sample Question 7

What does a user need to do to have a container with an event from Splunk use contextawareactions designed for notable events?

A. Include the notable event's event_id field and set the artifacts label to aplunk notableevent id.
B. Rename the event_id field from the notable event to splunkNotableEventld.
C. Include the event_id field in the search results and add a CEF definition to Phantom forevent_id, datatype splunk notable event id.
D. Add a custom field to the container named event_id and set the custom field's data typeto splunk notable event id.


Sample Question 8

Which of the following can be configured in the ROI Settings?

A. Number of full time employees (FTEs).
B. Time lost.
C. Analyst hours per month.
D. Annual analyst salary.


Sample Question 9

Which of the following supported approaches enables Phantom to run on a Windowsserver?

A. Install the Phantom RPM in a GNU Cygwin implementation.
B. Run the Phantom OVA as a cloud instance.
C. Install the Phantom RPM file in Windows Subsystem for Linux (WSL).
D. Run the Phantom OVA as a virtual machine.


Sample Question 10

Splunk user account(s) with which roles must be created to configure Phantom with anexternal Splunk Enterprise instance?

A. superuser, administrator
B. phantomcreate. phantomedit
C. phantomsearch, phantomdelete
D. admin,user


Sample Question 11

What are indicators?

A. Action result items that determine the flow of execution in a playbook.
B. Action results that may appear in multiple containers.
C. Artifact values that can appear in multiple containers.
D. Artifact values with special security significance.


Sample Question 12

A user wants to use their Splunk Cloud instance as the external Splunk instance forPhantom. What ports need to be opened on the Splunk Cloud instance to facilitate this?Assume default ports are in use.

A. TCP 8088 and TCP 8099.
B. TCP 80 and TCP 443.
C. Splunk Cloud is not supported.
D. TCP 8080 and TCP 8191.


Sample Question 13

When configuring a Splunk asset for Phantom to connect to a SplunkC loud instance, theuser discovers that they need to be able to run two different on_poll searches. How is thispossible

A. Enter the two queries in the asset as comma separated values.
B. Configure the second query in the Phantom app for Splunk.
C. Install a second Splunk app and configure the query in the second app.
D. Configure a second Splunk asset with the second query.


Sample Question 14

Which of the following are examples of things commonly done with the Phantom REST APP 

A. Use Django queries; use curl to create a container and add artifacts to it; removetemporary lists.
B. Use Django queries; use Docker to create a container and add artifacts to it; removetemporary lists.
C. Use Django queries; use curl to create a container and add artifacts to it; add actionblocks.
D. Use SQL queries; use curl to create a container and add artifacts to it; removetemporary lists.


Sample Question 15

When analyzing events, a working on a case, significant items can be marked as evidence.Where can ail of a case's evidence items be viewed together?

A. Workbook page Evidence tab.
B. Evidence report.
C. Investigation page Evidence tab.
D. At the bottom of the Investigation page widget panel.


Sample Question 16

How can more than one user perform tasks in a workbook?

A. Any user in a role with write access to the case's workbook can be assigned to tasks.
B. Add the required users to the authorized list for the container.
C. Any user with a role that has Perform Task enabled can execute tasks for workbooks.
D. The container owner can assign any authorized user to any task in a workbook.


Sample Question 17

Which of the following roles is appropriate for a Splunk SOAR account that will only beused to execute automated tasks?

A. Non-Human
B. Automation
C. Automation Engineer
D. Service Account



Exam Code: SPLK-2003
Exam Name: Splunk SOAR Certified Automation Developer Exam
Last Update: May 13, 2024
Questions: 96