Exit demo SPLK-2003 Splunk SOAR Certified Automation Developer PDF format · free preview

Splunk SPLK-2003 - Questions & Answers

Free preview · every answer includes a full explanation

Product page: https://prepkeys.com/splk-2003.html

Question 1
Single choice

What is the default log level for system health debug logs?

A.

INFO

B.

WARN

C.

ERROR

D.

DEBUG

Question 2
Single choice

What is enabled if the Logging option for a playbook's settings is enabled?

A.

More detailed logging information Is available m the Investigation page.

B.

All modifications to the playbook will be written to the audit log.

C.

More detailed information is available in the debug window.

D.

The playbook will write detailed execution information into the spawn.log.

Question 3
Single choice

How can the debug log for a playbook execution be viewed?

A.

On the Investigation page, select Debug Log from the playbook's action menu in the Recent Activity panel.

B.

Click Expand Scope m the debug window.

C.

In Administration > System Health > Playbook Run History, select the playbook execution entry, then
select Log.

D.

Open the playbook in the Visual Playbook Editor, and select Debug Logs in Settings.

Question 4
Multiple choice

What metrics can be seen from the System Health Display? (select all that apply)

A.

Playbook Usage

B.

Memory Usage

C.

Disk Usage

D.

Load Average

Question 5
Single choice

Which Phantom API command is used to create a custom list?

A.

phantom.add_list()

B.

phantom.create_list()

C.

phantom.include_list()

D.

phantom.new_list()

Question 6
Single choice

Which of the following is the complete list of the types of backups that are supported by Phantom?

A.

Full backups.

B.

Full, delta, and incremental backups.

C.

Full and incremental backups.

D.

Full and delta backups.

Question 7
Single choice

The SOAR server has been configured to use an external Splunk search head for search and searching
on SOAR works; however, the search results don't include content that was being returned by search before configuring external search.

Which of the following could be the problem?

A.

The existing content indexes on the SOAR server need to be re-indexed to migrate them to Splunk.

B.

The user configured on the SOAR side with Phantomsearch capability is not enabled on Splunk.

C.

The remote Splunk search head is currently offline.

D.

Content that existed before configuring external search must be backed up on SOAR and restored on the Splunk search head.

Question 8
Single choice

How can a child playbook access the parent playbook's action results?

A.

Child playbooks can access parent playbook data while the parent Is still running.

B.

By setting scope to ALL when starting the child.

C.

When configuring the playbook block in the parent, add the desired results in the Scope parameter.

D.

The parent can create an artifact with the data needed by the did.

Question 9
Single choice

Why does SOAR use wildcards within artifact data paths?

A.

To make playbooks more specific.

B.

To make playbooks filter out nulls.

C.

To make data access in playbooks easier.

D.

To make decision execution in playbooks run faster.

Question 10
Single choice

Which two playbook blocks can discern which path in the playbook to take next?

A.

Prompt and decision blocks.

B.

Decision and action blocks.

C.

Filter and decision blocks.

D.

Filter and prompt blocks.

Showing 10 of 96 questions · Unlock the full set