SPLK-2003 Splunk SOAR Certified Automation Developer Exam Questions and Answers
Regarding the Splunk SOAR Automation Broker requirements, which of the following statements is not correct?
A user selects the New option under Sources on the menu. What will be displayed?
After enabling multi-tenancy, which of the Mowing is the first configuration step?
A user wants to use their Splunk Cloud instance as the external Splunk instance for Phantom. What ports need to be opened on the Splunk Cloud instance to facilitate this? Assume default ports are in use.
Which of the following is the best option for an analyst who wants to run a single action on an event?
A user wants to get the playbook results for a single artifact. Which steps will accomplish the?
Splunk user account(s) with which roles must be created to configure Phantom with an external Splunk Enterprise instance?
An active playbook can be configured to operate on all containers that share which attribute?
When assigning an input parameter to an action while building a playbook, a user notices the artifact value they are looking for does not appear in the auto-populated list.
How is it possible to enter the unlisted artifact value?
Which of the following queries would return all artifacts that contain a SHA1 file hash?
A filter block with only one condition configured which states: artifact.*.cef .sourceAddress !- , would permit which of the following data to pass forward to the next block?
A user has written a playbook that calls three other playbooks, one after the other. The user notices that the second playbook starts executing before the first one completes. What is the cause of this behavior?
Some of the playbooks on the Phantom server should only be executed by members of the admin role. How can this rule be applied?
Seventy can be set during ingestion and later changed manually. What other mechanism can change the severity or a container?
When configuring a Splunk asset for Phantom to connect to a SplunkC loud instance, the user discovers that they need to be able to run two different on_poll searches. How is this possible
Which of the following is a step when configuring event forwarding from Splunk to Phantom?
The SOAR server has been configured to use an external Splunk search head for search and searching on SOAR works; however, the search results don ' t include content that was being returned by search before configuring external search. Which of the following could be the problem?
Within the 12A2 design methodology, which of the following most accurately describes the last step?
