Splunk SPLK-2003 Splunk SOAR Certified Automation Developer Exam Online Training
Splunk SPLK-2003 Online Training
The questions for SPLK-2003 were last updated at Apr 09,2025.
- Exam Code: SPLK-2003
- Exam Name: Splunk SOAR Certified Automation Developer Exam
- Certification Provider: Splunk
- Latest update: Apr 09,2025
What values can be applied when creating Custom CEF field?
- A . Name
- B . Name, Data Type
- C . Name, Value
- D . Name, Data Type, Severity
What is enabled if the Logging option for a playbook’s settings is enabled?
- A . More detailed logging information Is available m the Investigation page.
- B . All modifications to the playbook will be written to the audit log.
- C . More detailed information is available in the debug window.
- D . The playbook will write detailed execution information into the spawn.log.
Is it possible to import external Python libraries such as the time module?
- A . No.
- B . No, but this can be changed by setting the proper permissions.
- C . Yes, in the global block.
- D . Yes. from a drop-down menu.
How can an individual asset action be manually started?
- A . With the > action button in the analyst queue page.
- B . By executing a playbook in the Playbooks section.
- C . With the > action button in the Investigation page.
- D . With the > asset button in the asset configuration section.
What is the default embedded search engine used by Phantom?
- A . Embedded Splunk search engine.
- B . Embedded Phantom search engine.
- C . Embedded Elastic search engine.
- D . Embedded Django search engine.
A filter block with only one condition configured which states: artifact.*.cef .sourceAddress !- , would permit which of the following data to pass forward to the next block?
- A . Null IP addresses
- B . Non-null IP addresses
- C . Non-null destinationAddresses
- D . Null values
A user wants to get the playbook results for a single artifact.
Which steps will accomplish the?
- A . Use the contextual menu from the artifact and select run playbook.
- B . Use the run playbook dialog and set the scope to the artifact.
- C . Create a new container including Just the artifact in question.
- D . Use the contextual menu from the artifact and select the actions.
What is the main purpose of using a customized workbook?
- A . Workbooks automatically implement a customized processing of events using Python code.
- B . Workbooks guide user activity and coordination during event analysis and case operations.
- C . Workbooks apply service level agreements (SLAs) to containers and monitor completion status on the ROI dashboard.
- D . Workbooks may not be customized; only default workbooks are permitted within Phantom.
Which of the following is a step when configuring event forwarding from Splunk to Phantom?
- A . Map CIM to CEF fields.
- B . Create a Splunk alert that uses the event_forward.py script to send events to Phantom.
- C . Map CEF to CIM fields.
- D . Create a saved search that generates the JSON for the new container on Phantom.
Which is the primary system requirement that should be increased with heavy usage of the file vault?
- A . Amount of memory.
- B . Number of processors.
- C . Amount of storage.
- D . Bandwidth of network.