Complete list of current Q & A>> Download Splunk SOAR Certified Automation Developer (SPLK-2003) – Quiz 1 / 15 When configuring a Splunk asset for Phantom to connect to a SplunkC loud instance, the user discovers that they need to be able to run two different on_poll searches. How is this possible A. Enter the two queries in the asset as comma separated values. B. Configure the second query in the Phantom app for Splunk. C. Install a second Splunk app and configure the query in the second app. D. Configure a second Splunk asset with the second query. 2 / 15 What does a user need to do to have a container with an event from Splunk use context-aware actions designed for notable events? A. Include the notable event's event_id field and set the artifacts label to aplunk notable event id. B. Rename the event_id field from the notable event to splunkNotableEventld. C. Include the event_id field in the search results and add a CEF definition to Phantom for event_id, datatype splunk notable event id. D. Add a custom field to the container named event_id and set the custom field's data type to splunk notable event id. 3 / 15 Without customizing container status within Phantom, what are the three types of status for a container? A. New, In Progress, Closed B. Low, Medium, High C. New, Open, Resolved D. Low, Medium, Critical 4 / 15 Which of the following are examples of things commonly done with the Phantom REST APP A. Use Django queries; use curl to create a container and add artifacts to it; remove temporary lists. B. Use Django queries; use Docker to create a container and add artifacts to it; remove temporary lists. C. Use Django queries; use curl to create a container and add artifacts to it; add action blocks. Use SQL queries; use curl to create a container and add artifacts to it; remove temporary lists. 5 / 15 A user has written a playbook that calls three other playbooks, one after the other. The user notices that the second playbook starts executing before the first one completes. What is the cause of this behavior? A. Incorrect Join configuration on the second playbook. B. The first playbook is performing poorly. C. The steep option for the second playbook is not set to a long enough interval. E. Synchronous execution has not been configured. 6 / 15 An active playbook can be configured to operate on all containers that share which attribute? A. Artifact B. Label C. Tag D. Severity 7 / 15 Configuring Phantom search to use an external Splunk server provides which of the following benefits? A. The ability to run more complex reports on Phantom activities. B. The ability to ingest Splunk notable events into Phantom. C. The ability to automate Splunk searches within Phantom. D. The ability to display results as Splunk dashboards within Phantom. 8 / 15 Which Phantom API command is used to create a custom list? A. phantom.add_list() B. phantom.create_list() C. phantom.include_list() D. phantom.new_list() 9 / 15 In addition to full backups. Phantom supports what other backup type using backup? A. Snapshot B. Incremental C. Partial D. Differential 10 / 15 What is the simplest way to pass data between playbooks? A. Action results B. File system C. Artifacts D. KV Store 11 / 15 Which of the following is a step when configuring event forwarding from Splunk to Phantom? A. Map CIM to CEF fields. B. Create a Splunk alert that uses the event_forward.py script to send events to Phantom. C. Map CEF to CIM fields. D. Create a saved search that generates the JSON for the new container on Phantom. 12 / 15 A user wants to get the playbook results for a single artifact. Which steps will accomplish the? A. Use the contextual menu from the artifact and select run playbook. B. Use the run playbook dialog and set the scope to the artifact. C. Create a new container including Just the artifact in question. D. Use the contextual menu from the artifact and select the actions. 13 / 15 What is enabled if the Logging option for a playbook’s settings is enabled? A. More detailed logging information Is available m the Investigation page. B. All modifications to the playbook will be written to the audit log. C. More detailed information is available in the debug window. D. The playbook will write detailed execution information into the spawn.log. 14 / 15 What are indicators? A. Action result items that determine the flow of execution in a playbook B. Action results that may appear in multiple containers. C. Artifact values that can appear in multiple containers. D. Artifact values with special security significance. 15 / 15 Which of the following accurately describes the Files tab on the Investigate page? A. A user can upload the output from a detonate action to the the files tab for further investigation. B. Files tab items and artifacts are the only data sources that can populate active cases. C. Files tab items cannot be added to investigations. Instead, add them to action blocks. D. Phantom memory requirements remain static, regardless of Files tab usage. Your score is 0% Restart quiz Send feedback