Splunk SPLK-2003 Practice Test - Questions Answers, Page 10
List of questions
What users are included in a new installation of SOAR?
The admin and automation users are included by default.
The admin, power, and user users are included by default.
Only the admin user is included by default.
No users are included by default.
A user selects the New option under Sources on the menu. What will be displayed?
A list of new assets.
The New Data Ingestion wizard.
A list of new data sources.
A list of new events.
Under Asset Ingestion Settings, how many labels must be applied when configuring an asset?
Labels are not configured under Asset Ingestion Settings.
One.
One or more.
Zero or more.
Which of the following can be done with the System Health Display?
Create a temporary, edited version of a process and test the results.
Partially rewind processes, which is useful for debugging.
View a single column of status for SOAR processes. For metrics, click Details.
Reset DECIDED to reset playbook environments back to at-start conditions.
What metrics can be seen from the System Health Display? (select all that apply)
Playbook Usage
Memory Usage
Disk Usage
Load Average
When the Splunk App for SOAR Export executes a Splunk search, which activities are completed?
CEF fields are mapped to CIM flelds and a container is created on the SOAR server.
CIM fields are mapped to CEF fields and a container is created on the SOAR server.
CEF fields are mapped to CIM and a container is created on the Splunk server.
CIM fields are mapped to CEF and a container is created on the Splunk server.
Question