Pass the Splunk Splunk SOAR Certified Automation Developer SPLK-2003 Questions and answers with CertsForce

Viewing page 2 out of 4 pages
Viewing questions 11-20 out of questions
Questions # 11:

Which of the following actions will store a compressed, secure version of an email attachment with suspected malware for future analysis?

Options:

A.

Copy/paste the attachment into a note.


B.

Add a link to the file in a new artifact.


C.

Use the Files tab on the Investigation page to upload the attachment.


D.

Use the Upload action of the Secure Store app to store the file in the database.


Expert Solution
Questions # 12:

Which app allows a user to send Splunk Enterprise Security notable events to Phantom?

Options:

A.

Any of the integrated Splunk/Phantom Apps


B.

Splunk App for Phantom Reporting.


C.

Splunk App for Phantom.


D.

Phantom App for Splunk.


Expert Solution
Questions # 13:

How is it possible to evaluate user prompt results?

Options:

A.

Set action_result.summary. status to required.


B.

Set the user prompt to reinvoke if it times out.


C.

Set action_result. summary. response to required.


D.

Add a decision Mode


Expert Solution
Questions # 14:

Which of the following is the complete list of the types of backups that are supported by Phantom?

Options:

A.

Full backups.


B.

Full, delta, and incremental backups.


C.

Full and incremental backups.


D.

Full and delta backups.


Expert Solution
Questions # 15:

Which of the following can the format block be used for?

Options:

A.

To generate arrays for input into other functions.


B.

To generate HTML or CSS content for output in email messages, user prompts, or comments.


C.

To generate string parameters for automated action blocks.


D.

To create text strings that merge state text with dynamic values for input or output.


Expert Solution
Questions # 16:

What metrics can be seen from the System Health Display? (select all that apply)

Options:

A.

Playbook Usage


B.

Memory Usage


C.

Disk Usage


D.

Load Average


Expert Solution
Questions # 17:

When configuring a Splunk asset for Phantom to connect to a SplunkC loud instance, the user discovers that they need to be able to run two different on_poll searches. How is this possible

Options:

A.

Enter the two queries in the asset as comma separated values.


B.

Configure the second query in the Phantom app for Splunk.


C.

Install a second Splunk app and configure the query in the second app.


D.

Configure a second Splunk asset with the second query.


Expert Solution
Questions # 18:

When working with complex data paths, which operator is used to access a sub-element inside another element?

Options:

A.

!(pipe)


B.

*(asterisk)


C.

:(colon)


D.

.(dot)


Expert Solution
Questions # 19:

Which of the following is a reason to create a new role in SOAR?

Options:

A.

To define a set of users who have access to a special label.


B.

To define a set of users who have access to a restricted app.


C.

To define a set of users who have access to an event's reports.


D.

To define a set of users who have access to a sensitive tag.


Expert Solution
Questions # 20:

Which of the following views provides a holistic view of an incident - providing event metadata, Service Level Agreement status, Severity, sensitivity of an event, and other detailed event info?

Options:

A.

Executive


B.

Investigation


C.

Technical


D.

Analyst


Expert Solution
Viewing page 2 out of 4 pages
Viewing questions 11-20 out of questions