A user wants to use their Splunk Cloud instance as the external Splunk instance for Phantom. What ports need to be opened on the Splunk Cloud instance to facilitate this? Assume default ports are in use.
Which of the following is a step when configuring event forwarding from Splunk to Phantom?
Which of the following will show all artifacts that have the term results in a filePath CEF value?
A filter block with only one condition configured which states: artifact.*.cef .sourceAddress !- , would permit which of the following data to pass forward to the next block?
Seventy can be set during ingestion and later changed manually. What other mechanism can change the severity or a container?
Without customizing container status within Phantom, what are the three types of status for a container?
Phantom supports multiple user authentication methods such as LDAP and SAML2. What other user authentication method is supported?
To limit the impact of custom code on the VPE, where should the custom code be placed?
When writing a custom function that uses regex to extract the domain name from a URL, a user wants to create a new artifact for the extracted domain. Which of the following Python API calls will create a new artifact?
A user wants to get the playbook results for a single artifact. Which steps will accomplish the?
Regarding the Splunk SOAR Automation Broker requirements, which of the following statements is not correct?
Under Asset Ingestion Settings, how many labels must be applied when configuring an asset?
Configuring SOAR search to use an external Splunk server provides which of the following benefits?
Which of the following views provides a holistic view of an incident - providing event metadata, Service Level Agreement status, Severity, sensitivity of an event, and other detailed event info?
A customer wants to design a modular and reusable set of playbooks that all communicate with each other. Which of the following is a best practice for data sharing across playbooks?
When the Splunk App for SOAR Export executes a Splunk search, which activities are completed?
In addition to full backups. Phantom supports what other backup type using backup?
When configuring a Splunk asset for Phantom to connect to a SplunkC loud instance, the user discovers that they need to be able to run two different on_poll searches. How is this possible
Splunk SOAR Certified Automation Developer | SPLK-2003 Questions Answers | SPLK-2003 Test Prep | Splunk SOAR Certified Automation Developer Exam Questions PDF | SPLK-2003 Online Exam | SPLK-2003 Practice Test | SPLK-2003 PDF | SPLK-2003 Test Questions | SPLK-2003 Study Material | SPLK-2003 Exam Preparation | SPLK-2003 Valid Dumps | SPLK-2003 Real Questions | Splunk SOAR Certified Automation Developer SPLK-2003 Exam Questions