Exam Details

  • Exam Code
    :SPLK-2003
  • Exam Name
    :Splunk SOAR Certified Automation Developer
  • Certification
    :Splunk Certifications
  • Vendor
    :Splunk
  • Total Questions
    :96 Q&As
  • Last Updated
    :Mar 27, 2025

Splunk Splunk Certifications SPLK-2003 Questions & Answers

  • Question 71:

    In this image, which container fields are searched for the text "Malware"?

    A. Event Name and Artifact Names.

    B. Event Name, Notes, Comments.

    C. Event Name or ID.

  • Question 72:

    What values can be applied when creating Custom CEF field?

    A. Name

    B. Name, Data Type

    C. Name, Value

    D. Name, Data Type, Severity

  • Question 73:

    Some of the playbooks on the Phantom server should only be executed by members of the admin role. How can this rule be applied?

    A. Add a filter block to al restricted playbooks that Titters for runRole - "Admin''.

    B. Add a tag with restricted access to the restricted playbooks.

    C. Make sure the Execute Playbook capability is removed from al roles except admin.

    D. Place restricted playbooks in a second source repository that has restricted access.

  • Question 74:

    Within the 12A2 design methodology, which of the following most accurately describes the last step?

    A. List of the apps used by the playbook.

    B. List of the actions of the playbook design.

    C. List of the outputs of the playbook design.

    D. List of the data needed to run the playbook.

  • Question 75:

    How can the DECIDED process be restarted?

    A. By restarting the playbook daemon.

    B. On the System Health page.

    C. In Administration > Server Settings.

    D. By restarting the automation service.

  • Question 76:

    Which of the following can be done with the System Health Display?

    A. Create a temporary, edited version of a process and test the results.

    B. Partially rewind processes, which is useful for debugging.

    C. View a single column of status for SOAR processes. For metrics, click Details.

    D. Reset DECIDED to reset playbook environments back to at-start conditions.

  • Question 77:

    When writing a custom function that uses regex to extract the domain name from a URL, a user wants to create a new artifact for the extracted domain. Which of the following Python API calls will create a new artifact?

    A. phantom.new_artifact ()

    B. phantom. update ()

    C. phantom.create_artifact ()

    D. phantom.add_artifact ()

  • Question 78:

    Which of the following queries would return all artifacts that contain a SHA1 file hash?

    A. https:///rest/artifact?_filter_cef_md5_insull=false

    B. https:///rest/artifact?_filter_cef_Shal_contains=""

    C. https:///rest/artifact?_filter_cef_shal_insull=False

    D. https:///rest/artifact?_filter_shal__insull=False

  • Question 79:

    To limit the impact of custom code on the VPE, where should the custom code be placed?

    A. A custom container or a separate KV store.

    B. A separate code repository.

    C. A custom function block.

    D. A separate container.

  • Question 80:

    What do assets provide for app functionality?

    A. Assets provide location, credentials, and other parameters needed to run actions.

    B. Assets provide hostnames, passwords, and other artifacts needed to run actions.

    C. Assets provide Python code, REST API, and other capabilities needed to run actions.

    D. Assets provide firewall, network, and data sources needed to run actions.

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Splunk exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your SPLK-2003 exam preparations and Splunk certification application, do not hesitate to visit our Vcedump.com to find your solutions here.