Pass the Splunk Splunk SOAR Certified Automation Developer SPLK-2003 Questions and answers with CertsForce

Viewing page 3 out of 4 pages
Viewing questions 21-30 out of questions
Questions # 21:

An active playbook can be configured to operate on all containers that share which attribute?

Options:

A.

Artifact


B.

Label


C.

Tag


D.

Severity


Expert Solution
Questions # 22:

Which app allows a user to run Splunk queries from within Phantom?

Options:

A.

Splunk App for Phantom


B.

The Integrated Splunk/Phantom app.


C.

Phantom App for Splunk.


D.

Splunk App for Phantom Reporting.


Expert Solution
Questions # 23:

Which of the following accurately describes the Files tab on the Investigate page?

Options:

A.

A user can upload the output from a detonate action to the the files tab for further investigation.


B.

Files tab items and artifacts are the only data sources that can populate active cases.


C.

Files tab items cannot be added to investigations. Instead, add them to action blocks.


D.

Phantom memory requirements remain static, regardless of Files tab usage.


Expert Solution
Questions # 24:

When the Splunk App for SOAR Export executes a Splunk search, which activities are completed?

Options:

A.

CEF fields are mapped to CIM flelds and a container is created on the SOAR server.


B.

CIM fields are mapped to CEF fields and a container is created on the SOAR server.


C.

CEF fields are mapped to CIM and a container is created on the Splunk server.


D.

CIM fields are mapped to CEF and a container is created on the Splunk server.


Expert Solution
Questions # 25:

Which of the following can be configured in the ROl Settings?

Options:

A.

Analyst hours per month.


B.

Time lost.


C.

Number of full time employees (FTEs).


D.

Annual analyst salary.


Expert Solution
Questions # 26:

A new project requires event data from SOAR to be sent to an external system via REST. All events with the label notable that are in new status should be sent. Which of the following REST Django expressions will select the correct events?

Options:

A.

SPLK-2003 Question 26 Option 1


B.

26


C.

26


D.

26


Expert Solution
Questions # 27:

After a playbook has run, where are the results stored?

Options:

A.

Splunk Index


B.

Case


C.

Container


D.

Log file


Expert Solution
Questions # 28:

Where in SOAR can a user view the JSON data for a container?

Options:

A.

In the analyst queue.


B.

On the Investigation page.


C.

In the data ingestion display.


D.

In the audit log.


Expert Solution
Questions # 29:

In this image, which container fields are searched for the text "Malware"?

Question # 29

Options:

A.

Event Name and Artifact Names.


B.

Event Name, Notes, Comments.


C.

Event Name or ID.


Expert Solution
Questions # 30:

How can parent and child playbooks pass information to each other?

Options:

A.

The parent can pass arguments to the child when called, and the child can return values from the end block.


B.

The parent can pass arguments to the child when called, but the child can only pass values back as new artifacts in the event.


C.

The parent must create a new artifact in the event named arg_xxx, and the child must return values by creating artifacts with the naming convention return_xxx.


D.

The parent must create a new artifact in the event named return_xxx, and the child must return values by creating artifacts with the naming convention arg_xxx.


Expert Solution
Viewing page 3 out of 4 pages
Viewing questions 21-30 out of questions