Splunk Phantom Certified Admin - SPLK-2003 Exam Practice Test
Which of the following will show all artifacts that have the term results in a filePath CEF value?
Correct Answer: A
Vote an answer
Explanation: Only visible for Fast2test members. You can sign-up / login (it's free).
Two action blocks, geolocate_ip_1 and file_reputation_2, are connected to a decision block.
Which of the following is a correct configuration for making a decision on the action results from one of the given blocks?
Which of the following is a correct configuration for making a decision on the action results from one of the given blocks?
Correct Answer: C
Vote an answer
Why does SOAR use wildcards within artifact data paths?
Correct Answer: B
Vote an answer
Explanation: Only visible for Fast2test members. You can sign-up / login (it's free).
Which of the following is a reason to create a new role in SOAR?
Correct Answer: A
Vote an answer
Explanation: Only visible for Fast2test members. You can sign-up / login (it's free).
Where can the Splunk App for SOAR Export be downloaded from?
Correct Answer: C
Vote an answer
Explanation: Only visible for Fast2test members. You can sign-up / login (it's free).
Configuring SOAR search to use an external Splunk server provides which of the following benefits?
Correct Answer: D
Vote an answer
Explanation: Only visible for Fast2test members. You can sign-up / login (it's free).
Which of the following queries would return all failed playbook runs from the REST API?
Correct Answer: D
Vote an answer