Pass the Splunk Splunk SOAR Certified Automation Developer SPLK-2003 Questions and answers with CertsForce

Viewing page 1 out of 4 pages
Viewing questions 1-10 out of questions
Questions # 1:

What users are included in a new installation of SOAR?

Options:

A.

The admin and automation users are included by default.


B.

The admin, power, and user users are included by default.


C.

Only the admin user is included by default.


D.

No users are included by default.


Expert Solution
Questions # 2:

How can an individual asset action be manually started?

Options:

A.

With the > action button in the analyst queue page.


B.

By executing a playbook in the Playbooks section.


C.

With the > action button in the Investigation page.


D.

With the > asset button in the asset configuration section.


Expert Solution
Questions # 3:

What is enabled if the Logging option for a playbook's settings is enabled?

Options:

A.

More detailed logging information Is available m the Investigation page.


B.

All modifications to the playbook will be written to the audit log.


C.

More detailed information is available in the debug window.


D.

The playbook will write detailed execution information into the spawn.log.


Expert Solution
Questions # 4:

Why does SOAR use wildcards within artifact data paths?

Options:

A.

To make playbooks more specific.


B.

To make playbooks filter out nulls.


C.

To make data access in playbooks easier.


D.

To make decision execution in playbooks run faster.


Expert Solution
Questions # 5:

Which of the following can be edited or deleted in the Investigation page?

Options:

A.

Action results


B.

Comments


C.

Approval records


D.

Artifact values


Expert Solution
Questions # 6:

A filter block with only one condition configured which states: artifact.*.cef .sourceAddress !- , would permit which of the following data to pass forward to the next block?

Options:

A.

Null IP addresses


B.

Non-null IP addresses


C.

Non-null destinationAddresses


D.

Null values


Expert Solution
Questions # 7:

Under Asset Ingestion Settings, how many labels must be applied when configuring an asset?

Options:

A.

Labels are not configured under Asset Ingestion Settings.


B.

One.


C.

One or more.


D.

Zero or more.


Expert Solution
Questions # 8:

Which of the following are examples of things commonly done with the Phantom REST APP

Options:

A.

Use Django queries; use curl to create a container and add artifacts to it; remove temporary lists.


B.

Use Django queries; use Docker to create a container and add artifacts to it; remove temporary lists.


C.

Use Django queries; use curl to create a container and add artifacts to it; add action blocks.


D.

Use SQL queries; use curl to create a container and add artifacts to it; remove temporary lists.


Expert Solution
Questions # 9:

Without customizing container status within Phantom, what are the three types of status for a container?

Options:

A.

New, In Progress, Closed


B.

Low, Medium, High


C.

Mew, Open, Resolved


D.

Low, Medium, Critical


Expert Solution
Questions # 10:

In addition to full backups. Phantom supports what other backup type using backup?

Options:

A.

Snapshot


B.

Incremental


C.

Partial


D.

Differential


Expert Solution
Viewing page 1 out of 4 pages
Viewing questions 1-10 out of questions