Splunk SPLK-2003 Practice Test - Questions Answers, Page 7

List of questions
Question 61

Why does SOAR use wildcards within artifact data paths?
Question 62

Which of the following queries would return all artifacts that contain a SHA1 file hash?
Question 63

What is the default embedded search engine used by SOAR?
Question 64

How can the DECIDED process be restarted?
Question 65

Which of the following can be configured in the ROI Settings?
Question 66

What are the components of the I2A2 design methodology?
Question 67

Some of the playbooks on the SOAR server should only be executed by members of the admin role. How can this rule be applied?
Question 68

Which of the following can be edited or deleted in the Investigation page?
Question 69

Which of the following roles is appropriate for a Splunk SOAR account that will only be used to execute automated tasks?
Question 70

To limit the impact of custom code on the VPE, where should the custom code be placed?
Question