Splunk SPLK-2003 Practice Test - Questions Answers, Page 11
List of questions
Question 101
Which of the following are tabs of an asset configuration?
Question 102
Which visual playbook editor block is used to assemble commands and data into a valid Splunk search within a SOAR playbook?
Question 103
Two action blocks, geolocate_ip 1 and file_reputation_2, are connected to a decision block. Which of the following is a correct configuration for making a decision on the action results from one of the given blocks?
Question 104
Playbooks typically handle which types of data?
Question 105
A new project requires event data from SOAR to be sent to an external system via REST. All events with the label notable that are in new status should be sent. Which of the following REST Django expressions will select the correct events?
Question 106
Which of the following is true about a child playbook?
Question 107
Regarding the Splunk SOAR Automation Broker requirements, which of the following statements is not correct?
Question 108
How can a user with the username 'pat' configure the Analyst Queue to only show new events that are assigned to the current user?
Question 109
Which of the following cannot be marked as evidence in a container?
Question 110
How can parent and child playbooks pass information to each other?
        
 
                                            
Question