Pre-Summer Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: validbest

Pass the Splunk SOAR Certified Automation Developer SPLK-2003 Questions and answers with ValidTests

Exam SPLK-2003 All Questions
Exam SPLK-2003 Premium Access

View all detail and faqs for the SPLK-2003 exam

Viewing page 2 out of 4 pages
Viewing questions 11-20 out of questions
Questions # 11:

Which of the following views provides a holistic view of an incident - providing event metadata, Service Level Agreement status, Severity, sensitivity of an event, and other detailed event info?

Options:

A.

Executive

B.

Investigation

C.

Technical

D.

Analyst

Expert Solution
Questions # 12:

Where can the Splunk App for SOAR Export be downloaded from?

Options:

A.

GitHub and Splunkbase.

B.

SOAR Community and GitHub.

C.

Splunkbase and SOAR Community.

D.

Splunk Answers and Splunkbase.

Expert Solution
Questions # 13:

Which visual playbook editor block is used to assemble commands and data into a valid Splunk search within a SOAR playbook?

Options:

A.

An action block.

B.

A filter block.

C.

A format block.

D.

A prompt block.

Expert Solution
Questions # 14:

Some of the playbooks on the Phantom server should only be executed by members of the admin role. How can this rule be applied?

Options:

A.

Add a filter block to al restricted playbooks that Titters for runRole - "Admin''.

B.

Add a tag with restricted access to the restricted playbooks.

C.

Make sure the Execute Playbook capability is removed from al roles except admin.

D.

Place restricted playbooks in a second source repository that has restricted access.

Expert Solution
Questions # 15:

An active playbook can be configured to operate on all containers that share which attribute?

Options:

A.

Artifact

B.

Label

C.

Tag

D.

Severity

Expert Solution
Questions # 16:

What are the components of the I2A2 design methodology?

Options:

A.

Inputs, Interactions, Actions, Apps

B.

Inputs, Interactions, Actions, Artifacts

C.

Inputs, Interactions, Apps, Artifacts

D.

Inputs, Interactions, Actions, Assets

Expert Solution
Questions # 17:

Phantom supports multiple user authentication methods such as LDAP and SAML2. What other user authentication method is supported?

Options:

A.

SAML3

B.

PIV/CAC

C.

Biometrics

D.

OpenID

Expert Solution
Questions # 18:

In a playbook, more than one Action block can be active at one time. What is this called?

Options:

A.

Serial Processing

B.

Parallel Processing

C.

Multithreaded Processing

D.

Juggle Processing

Expert Solution
Questions # 19:

How can parent and child playbooks pass information to each other?

Options:

A.

The parent can pass arguments to the child when called, and the child can return values from the end block.

B.

The parent can pass arguments to the child when called, but the child can only pass values back as new artifacts in the event.

C.

The parent must create a new artifact in the event named arg_xxx, and the child must return values by creating artifacts with the naming convention return_xxx.

D.

The parent must create a new artifact in the event named return_xxx, and the child must return values by creating artifacts with the naming convention arg_xxx.

Expert Solution
Questions # 20:

After enabling multi-tenancy, which of the Mowing is the first configuration step?

Options:

A.

Select the associated tenant artifacts.

B.

Change the tenant permissions.

C.

Set default tenant base address.

D.

Configure the default tenant.

Expert Solution
Viewing page 2 out of 4 pages
Viewing questions 11-20 out of questions