SPLK-2003 SOAR Certified Automation Developer Practice Questions
Prepare for SPLK-2003 with more than an answer.
- Exam fee
- $130 USD
- Level
- Professional
- Valid for
- Not specified
Domains covered on the exam 18
- Deployment, Installation, and Initial Configuration10%
- User Management5%
- Apps, Assets, and Playbooks15%
- Analyst Queue5%
- The Investigation Page10%
- Case Management and Workbooks5%
- Customizations5%
- Reports and Health Monitoring5%
- Introduction to Playbooks5%
- Visual Playbook Editor10%
- Logic, Filters, and User Interaction5%
- Formatted Output and Data Access5%
- Parent and Child Playbooks5%
- Custom Lists and Data Routing5%
- Configuring External Splunk Search5%
- Integrating SOAR into Splunk10%
- Custom Coding5%
- REST API5%
- 1
An organization wants to add a custom field named 'business_impact' to all containers to track the potential financial impact of an incident. This field should be available for all event types. How can an administrator implement this?
Show answer details
Correct answer: C
Splunk SOAR provides a specific UI section for adding global custom fields to core objects like containers and artifacts. This is the correct and supported method to add a new field that will be present on all containers.
- 2
True or False: The
phantom.error()call within a custom function will immediately halt the execution of the entire playbook.Show answer details
Correct answer: B
phantom.error()terminates the custom function and marks the function block as failed. However, it does not halt the entire playbook. The playbook will proceed down the 'fail' path from the custom function block, allowing for graceful error handling within the playbook logic. - 3
Case Study:
A security team at a large e-commerce company has a Splunk SOAR playbook that orchestrates the response to potential server compromises. The playbook first gathers forensic data, then quarantines the server, and finally creates a ticket in a third-party IT service management (ITSM) system via a REST API call. The final step of creating the ticket is failing intermittently.
Upon investigation, the developer finds that the API call to the ITSM system is successful when tested manually but fails within the playbook. The action results for the failed API call show a
400 Bad Requesterror. The developer suspects the JSON payload being sent to the ITSM API is malformed. The JSON payload is constructed dynamically using a Format block, which combines data gathered earlier in the playbook.Which troubleshooting step is the most direct and effective way to diagnose the problem with the JSON payload?
Show answer details
Correct answer: B
The Playbook Debugger is the ideal tool for this scenario. It allows the developer to pause execution, inspect the data at each step (including the fully rendered output of the Format block), and see the precise parameters passed to the failing action. This will reveal any malformed JSON, such as missing quotes, incorrect data types, or syntax errors.
- 4
A developer passes a list of dictionaries from a parent playbook to a child playbook. How does the child playbook access the data passed from the parent?
Show answer details
Correct answer: B
Data passed from a parent playbook is treated as an input to the child playbook. This data is accessible via datapaths originating from the 'Playbook Inputs' section of the child playbook's Start block.
- 5
A developer needs to query a custom list named
allowlist_ipsfrom a playbook and check if a specific IP address192.168.1.100exists in theip_addresscolumn. Which REST API URI with a Django query filter would accomplish this?Show answer details
Correct answer: C
The correct REST API endpoint for accessing the rows of a custom list is
/rest/custom_lists/{list_name}/rows. The data is then filtered using the_filter_parameter with the column name and the value to be matched, which is the standard Django query syntax used by the SOAR API. - 6
A SOAR developer is creating a playbook that needs to process a list of file hashes. For each hash, a child playbook is invoked to perform reputation analysis. The parent playbook must wait for all child playbooks to complete before aggregating the results. Which configuration in the parent playbook's 'Playbook' block is essential to achieve this requirement?
Show answer details
Correct answer: B
Checking the 'synchronous' checkbox ensures that the parent playbook pauses its execution and waits for the child playbook to complete before proceeding. This is critical for scenarios where the parent playbook depends on the output or completion of the child.
- 7
A custom function in a Splunk SOAR playbook is designed to parse a complex, nested JSON object from an API response. The developer needs to extract a specific value located at
results[0].indicators.domains[2].name. Which is the most robust datapath to access this value?Show answer details
Correct answer: D
The correct datapath syntax uses bracket notation
[index]to access elements in a list (array) and dot notation.keyto access values in a dictionary (object). The other options use incorrect separators or wildcards that do not target the specific element. - 8
A developer needs to write a custom function that enriches multiple artifacts and then adds a single, consolidated note to the container. Which TWO of the following
phantomlibrary calls are essential for this task? (Select TWO)Show answer details
Correct answer: A, C
phantom.act() is used to execute an action from within the custom function, which is necessary for the enrichment part of the task.
phantom.add_note() is used to programmatically add a note to the current container, which is required for the second part of the task.
- 9
True or False: When a playbook uses a 'Manual Task' block, the entire playbook execution pauses and enters a 'pending' state until a user manually marks the task as complete.
Show answer details
Correct answer: A
The 'Manual Task' block is designed specifically to halt playbook automation and assign a task to a user or role. The playbook will not proceed past this block until the task is manually completed in the SOAR UI.
- 10
A financial institution is using Splunk SOAR to automate responses to phishing alerts originating from Splunk Enterprise Security (ES). They need to ensure that when a notable event from ES creates a container in SOAR, the original notable event's urgency is mapped to the SOAR container's severity. Where is this mapping configured?
Show answer details
Correct answer: C
The mapping of fields like urgency, sensitivity, and status from a Splunk ES notable event to a SOAR container's severity, sensitivity, and status is configured within the Splunk App for SOAR Export (formerly Phantom App for Splunk) on the Splunk search head where ES is installed.
