Splunk SPLK-2003 Practice Test - Questions Answers, Page 11

List of questions
Question 101

Which of the following are tabs of an asset configuration?
Question 102

Which visual playbook editor block is used to assemble commands and data into a valid Splunk search within a SOAR playbook?
Question 103

Two action blocks, geolocate_ip 1 and file_reputation_2, are connected to a decision block. Which of the following is a correct configuration for making a decision on the action results from one of the given blocks?
Question 104

Playbooks typically handle which types of data?
Question 105

A new project requires event data from SOAR to be sent to an external system via REST. All events with the label notable that are in new status should be sent. Which of the following REST Django expressions will select the correct events?
Question 106

Which of the following is true about a child playbook?
Question 107

Regarding the Splunk SOAR Automation Broker requirements, which of the following statements is not correct?
Question 108

How can a user with the username 'pat' configure the Analyst Queue to only show new events that are assigned to the current user?
Question 109

Which of the following cannot be marked as evidence in a container?
Question 110

How can parent and child playbooks pass information to each other?
Question