Pass the Splunk Splunk SOAR Certified Automation Developer SPLK-2003 Questions and answers with CertsForce

Viewing page 4 out of 4 pages
Viewing questions 31-40 out of questions
Questions # 31:

Two action blocks, geolocate_ip 1 and file_reputation_2, are connected to a decision block. Which of the following is a correct configuration for making a decision on the action results from one of the given blocks?

Options:

A.

SPLK-2003 Question 31 Option 1


B.

31


C.

31


D.

31


Expert Solution
Questions # 32:

Configuring Phantom search to use an external Splunk server provides which of the following benefits?

Options:

A.

The ability to run more complex reports on Phantom activities.


B.

The ability to ingest Splunk notable events into Phantom.


C.

The ability to automate Splunk searches within Phantom.


D.

The ability to display results as Splunk dashboards within Phantom.


Expert Solution
Questions # 33:

Splunk user account(s) with which roles must be created to configure Phantom with an external Splunk Enterprise instance?

Options:

A.

superuser, administrator


B.

phantomcreate. phantomedit


C.

phantomsearch, phantomdelete


D.

admin,user


Expert Solution
Viewing page 4 out of 4 pages
Viewing questions 31-40 out of questions