Summer Special 60% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: bestdeal

Free Splunk SPLK-2003 Practice Exam with Questions & Answers | Set: 2

Questions 11

Which of the following can be configured in the ROl Settings?

Options:
A.

Analyst hours per month.

B.

Time lost.

C.

Number of full time employees (FTEs).

D.

Annual analyst salary.

Splunk SPLK-2003 Premium Access
Questions 12

A new project requires event data from SOAR to be sent to an external system via REST. All events with the label notable that are in new status should be sent. Which of the following REST Django expressions will select the correct events?

Options:
A.

SPLK-2003 Question 12 Option 1

B.

12

C.

12

D.

12

Questions 13

When the Splunk App for SOAR Export executes a Splunk search, which activities are completed?

Options:
A.

CEF fields are mapped to CIM flelds and a container is created on the SOAR server.

B.

CIM fields are mapped to CEF fields and a container is created on the SOAR server.

C.

CEF fields are mapped to CIM and a container is created on the Splunk server.

D.

CIM fields are mapped to CEF and a container is created on the Splunk server.

Questions 14

Which of the following will show all artifacts that have the term results in a filePath CEF value?

Options:
A.

.../rest/artifact?_filter_cef_filePath_icontain=''results''

B.

...rest/artifacts/filePath=''%results%''

C.

.../result/artifacts/cef/filePath= '%results%''

D.

.../result/artifact?_query_cef_filepath_icontains=''results

Questions 15

When working with complex data paths, which operator is used to access a sub-element inside another element?

Options:
A.

!(pipe)

B.

*(asterisk)

C.

:(colon)

D.

.(dot)

Questions 16

After a successful POST to a Phantom REST endpoint to create a new object what result is returned?

Options:
A.

The new object ID.

B.

The new object name.

C.

The full CEF name.

D.

The PostGres UUID.

Questions 17

Which is the primary system requirement that should be increased with heavy usage of the file vault?

Options:
A.

Amount of memory.

B.

Number of processors.

C.

Amount of storage.

D.

Bandwidth of network.

Questions 18

How can an individual asset action be manually started?

Options:
A.

With the > action button in the analyst queue page.

B.

By executing a playbook in the Playbooks section.

C.

With the > action button in the Investigation page.

D.

With the > asset button in the asset configuration section.

Questions 19

Which two playbook blocks can discern which path in the playbook to take next?

Options:
A.

Prompt and decision blocks.

B.

Decision and action blocks.

C.

Filter and decision blocks.

D.

Filter and prompt blocks.

Questions 20

Which of the following is the best option for an analyst who wants to run a single action on an event?

Options:
A.

Open the event and run this single action from the Investigation View.

B.

Create a playbook with a single action then use the Playbook Debugger on the event ID.

C.

Create a playbook with the action and run it from the Investigation View.

D.

Open a playbook with a single action, mark it active, and then use the Playbook Debugger on the event ID.