Exam Details

  • Exam Code
    :SPLK-2003
  • Exam Name
    :Splunk SOAR Certified Automation Developer
  • Certification
    :Splunk Certifications
  • Vendor
    :Splunk
  • Total Questions
    :96 Q&As
  • Last Updated
    :Mar 27, 2025

Splunk Splunk Certifications SPLK-2003 Questions & Answers

  • Question 81:

    What are the differences between cases and events?

    A. Case: potential threats. Events: identified as a specific kind of problem and need a structured approach.

    B. Cases: only include high-level incident artifacts. Events: only include low-level incident artifacts.

    C. Cases: contain a collection of containers. Events: contain potential threats.

    D. Cases: incidents with a known violation and a plan for correction. Events: occurrences in the system that may require a response.

  • Question 82:

    Phantom supports multiple user authentication methods such as LDAP and SAML2. What other user authentication method is supported?

    A. SAML3

    B. PIV/CAC

    C. Biometrics

    D. OpenID

  • Question 83:

    Which of the following roles is appropriate for a Splunk SOAR account that will only be used to execute automated tasks?

    A. Non-Human

    B. Automation

    C. Automation Engineer

    D. Service Account

  • Question 84:

    How can more than one user perform tasks in a workbook?

    A. Any user in a role with write access to the case's workbook can be assigned to tasks.

    B. Add the required users to the authorized list for the container.

    C. Any user with a role that has Perform Task enabled can execute tasks for workbooks.

    D. The container owner can assign any authorized user to any task in a workbook.

  • Question 85:

    When analyzing events, a working on a case, significant items can be marked as evidence. Where can ail of a case's evidence items be viewed together?

    A. Workbook page Evidence tab.

    B. Evidence report.

    C. Investigation page Evidence tab.

    D. At the bottom of the Investigation page widget panel.

  • Question 86:

    Which of the following are examples of things commonly done with the Phantom REST APP

    A. Use Django queries; use curl to create a container and add artifacts to it; remove temporary lists.

    B. Use Django queries; use Docker to create a container and add artifacts to it; remove temporary lists.

    C. Use Django queries; use curl to create a container and add artifacts to it; add action blocks.

    D. Use SQL queries; use curl to create a container and add artifacts to it; remove temporary lists.

  • Question 87:

    When configuring a Splunk asset for Phantom to connect to a SplunkC loud instance, the user discovers that they need to be able to run two different on_poll searches. How is this possible

    A. Enter the two queries in the asset as comma separated values.

    B. Configure the second query in the Phantom app for Splunk.

    C. Install a second Splunk app and configure the query in the second app.

    D. Configure a second Splunk asset with the second query.

  • Question 88:

    A user wants to use their Splunk Cloud instance as the external Splunk instance for Phantom. What ports need to be opened on the Splunk Cloud instance to facilitate this? Assume default ports are in use.

    A. TCP 8088 and TCP 8099.

    B. TCP 80 and TCP 443.

    C. Splunk Cloud is not supported.

    D. TCP 8080 and TCP 8191.

  • Question 89:

    What are indicators?

    A. Action result items that determine the flow of execution in a playbook.

    B. Action results that may appear in multiple containers.

    C. Artifact values that can appear in multiple containers.

    D. Artifact values with special security significance.

  • Question 90:

    Splunk user account(s) with which roles must be created to configure Phantom with an external Splunk Enterprise instance?

    A. superuser, administrator

    B. phantomcreate. phantomedit

    C. phantomsearch, phantomdelete

    D. admin,user

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Splunk exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your SPLK-2003 exam preparations and Splunk certification application, do not hesitate to visit our Vcedump.com to find your solutions here.