Summer Special 60% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: bestdeal

Free Splunk SPLK-2003 Practice Exam with Questions & Answers | Set: 3

Questions 21

What values can be applied when creating Custom CEF field?

Options:
A.

Name

B.

Name, Data Type

C.

Name, Value

D.

Name, Data Type, Severity

Splunk SPLK-2003 Premium Access
Questions 22

Splunk user account(s) with which roles must be created to configure Phantom with an external Splunk Enterprise instance?

Options:
A.

superuser, administrator

B.

phantomcreate. phantomedit

C.

phantomsearch, phantomdelete

D.

admin,user

Questions 23

On a multi-tenant Phantom server, what is the default tenant's ID?

Options:
A.

0

B.

Default

C.

1

D.

*

Questions 24

After a playbook has run, where are the results stored?

Options:
A.

Splunk Index

B.

Case

C.

Container

D.

Log file

Questions 25

Which of the following are tabs of an asset configuration?

Options:
A.

Asset Name, Asset IP, Asset URL, Asset Nickname

B.

Tags, Asset Name, Asset Date, Asset Order

C.

App Name, App Order, App Expiry, App Version

D.

Asset Info, Asset Settings, Approval Settings, Access Control

Questions 26

How is a Django filter query performed?

Options:
A.

By adding parameters to the URL similar to the following: phantom/rest/container?_filter_tags_contains="sumo".

B.

phantom/rest/search/app/contains/"sumo"

C.

Browse to the Django Filter Query Editor in the Administration panel.

D.

Install the SOAR Django App first, then configure the search query in the App editor.

Questions 27

Which of the following supported approaches enables Phantom to run on a Windows server?

Options:
A.

Install the Phantom RPM in a GNU Cygwin implementation.

B.

Run the Phantom OVA as a cloud instance.

C.

Install the Phantom RPM file in Windows Subsystem for Linux (WSL).

D.

Run the Phantom OVA as a virtual machine.

Questions 28

Which of the following can be edited or deleted in the Investigation page?

Options:
A.

Action results

B.

Comments

C.

Approval records

D.

Artifact values

Questions 29

How does a user determine which app actions are available?

Options:
A.

Add an action block to a playbook canvas area.

B.

Search the Apps category in the global search field.

C.

From the Apps menu, click the supported actions dropdown for each app.

D.

In the visual playbook editor, click Active and click the Available App Actions dropdown.

Questions 30

Which app allows a user to send Splunk Enterprise Security notable events to Phantom?

Options:
A.

Any of the integrated Splunk/Phantom Apps

B.

Splunk App for Phantom Reporting.

C.

Splunk App for Phantom.

D.

Phantom App for Splunk.