Exam Details

  • Exam Code
    :SPLK-2003
  • Exam Name
    :Splunk SOAR Certified Automation Developer
  • Certification
    :Splunk SOAR Certified Automation Developer
  • Vendor
    :Splunk
  • Total Questions
    :96 Q&As
  • Last Updated
    :Nov 13, 2024

Splunk Splunk SOAR Certified Automation Developer SPLK-2003 Questions & Answers

  • Question 1:

    What is the default log level for system health debug logs?

    A. INFO

    B. WARN

    C. ERROR

    D. DEBUG

  • Question 2:

    What is enabled if the Logging option for a playbook's settings is enabled?

    A. More detailed logging information Is available m the Investigation page.

    B. All modifications to the playbook will be written to the audit log.

    C. More detailed information is available in the debug window.

    D. The playbook will write detailed execution information into the spawn.log.

  • Question 3:

    How can the debug log for a playbook execution be viewed?

    A. On the Investigation page, select Debug Log from the playbook's action menu in the Recent Activity panel.

    B. Click Expand Scope m the debug window.

    C. In Administration > System Health > Playbook Run History, select the playbook execution entry, then select Log.

    D. Open the playbook in the Visual Playbook Editor, and select Debug Logs in Settings.

  • Question 4:

    What metrics can be seen from the System Health Display? (select all that apply)

    A. Playbook Usage

    B. Memory Usage

    C. Disk Usage

    D. Load Average

  • Question 5:

    Which Phantom API command is used to create a custom list?

    A. phantom.add_list()

    B. phantom.create_list()

    C. phantom.include_list()

    D. phantom.new_list()

  • Question 6:

    Which of the following is the complete list of the types of backups that are supported by Phantom?

    A. Full backups.

    B. Full, delta, and incremental backups.

    C. Full and incremental backups.

    D. Full and delta backups.

  • Question 7:

    The SOAR server has been configured to use an external Splunk search head for search and searching on SOAR works; however, the search results don't include content that was being returned by search before configuring external search. Which of the following could be the problem?

    A. The existing content indexes on the SOAR server need to be re-indexed to migrate them to Splunk.

    B. The user configured on the SOAR side with Phantomsearch capability is not enabled on Splunk.

    C. The remote Splunk search head is currently offline.

    D. Content that existed before configuring external search must be backed up on SOAR and restored on the Splunk search head.

  • Question 8:

    How can a child playbook access the parent playbook's action results?

    A. Child playbooks can access parent playbook data while the parent Is still running.

    B. By setting scope to ALL when starting the child.

    C. When configuring the playbook block in the parent, add the desired results in the Scope parameter.

    D. The parent can create an artifact with the data needed by the did.

  • Question 9:

    Why does SOAR use wildcards within artifact data paths?

    A. To make playbooks more specific.

    B. To make playbooks filter out nulls.

    C. To make data access in playbooks easier.

    D. To make decision execution in playbooks run faster.

  • Question 10:

    Which two playbook blocks can discern which path in the playbook to take next?

    A. Prompt and decision blocks.

    B. Decision and action blocks.

    C. Filter and decision blocks.

    D. Filter and prompt blocks.

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Splunk exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your SPLK-2003 exam preparations and Splunk certification application, do not hesitate to visit our Vcedump.com to find your solutions here.