Winter Special Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: bigdisc65

Free SPLK-2003 Splunk Updates

Page: 3 / 8
Question 12

How can more than one user perform tasks in a workbook?

Options:

A.

Any user in a role with write access to the case's workbook can be assigned to tasks.

B.

Add the required users to the authorized list for the container.

C.

Any user with a role that has Perform Task enabled can execute tasks for workbooks.

D.

The container owner can assign any authorized user to any task in a workbook.

Question 13

Which visual playbook editor block is used to assemble commands and data into a valid Splunk search within a SOAR playbook?

Options:

A.

An action block.

B.

A filter block.

C.

A format block.

D.

A prompt block.

Question 14

Which of the following is the best option for an analyst who wants to run a single action on an event?

Options:

A.

Open the event and run this single action from the Investigation View.

B.

Create a playbook with a single action then use the Playbook Debugger on the event ID.

C.

Create a playbook with the action and run it from the Investigation View.

D.

Open a playbook with a single action, mark it active, and then use the Playbook Debugger on the event ID.

Question 15

On the Splunk search head, when configuring the app to search SOAR searchable content, what are the two requirements to complete the app setup?

Options:

A.

User accounts and universal forwarder.

B.

User accounts and an HTTP Event Collector token.

C.

User accounts and REST API.

D.

User accounts and syslog.

Page: 3 / 8
Exam Code: SPLK-2003
Exam Name: Splunk SOAR Certified Automation Developer Exam
Last Update: Nov 21, 2024
Questions: 110
SPLK-2003 pdf

SPLK-2003 PDF

$28  $80
SPLK-2003 Engine

SPLK-2003 Testing Engine

$33.25  $95
SPLK-2003 PDF + Engine

SPLK-2003 PDF + Testing Engine

$45.5  $130