Splunk SPLK-2003 Practice Exams
Last updated on Oct 07,2026- Exam Code: SPLK-2003
- Exam Name: Splunk SOAR Certified Automation Developer Exam
- Certification Provider: Splunk
- Latest update: Oct 07,2026
Which of the following is true about a child playbook?
- A . The child playbook does not have access to the parent playbook’s container or action result data.
- B . The child playbook does not have access to the parent playbook’s container, but to the parent’s action result data.
- C . The child playbook has access to the parent playbook’s container and the parent’s action result data.
- D . The child playbook has access to the parent playbook’s container, but not to the parent’s action result data.
C
Explanation:
In Splunk SOAR, a child playbook can access both the container data and the action result data from the parent playbook. This capability allows child playbooks to continue processing data or actions that were initiated by the parent playbook, ensuring smooth data flow and facilitating complex workflows across multiple playbooks. When a parent playbook calls a child playbook, the container (which holds the event and artifact data) and action results (which hold the outputs of previously executed actions) are passed to the child playbook.
This access enables more flexible and powerful automation by allowing the child playbook to build upon the work done by the parent.
Reference: Splunk SOAR Playbook Documentation.
Splunk SOAR Playbook Development Best Practices.
Which of the following accurately describes the Files tab on the Investigate page?
- A . A user can upload the output from a detonate action to the the files tab for further investigation.
- B . Files tab items and artifacts are the only data sources that can populate active cases.
- C . Files tab items cannot be added to investigations. Instead, add them to action blocks.
- D . Phantom memory requirements remain static, regardless of Files tab usage.
A
Explanation:
The Files tab on the Investigate page allows the user to upload, download, and view files related to an investigation. A user can upload the output from a detonate action to the Files tab for further investigation, such as analyzing the file metadata, content, or hash. Files tab items and artifacts are not the only data sources that can populate active cases, as cases can also include events, tasks, notes, and comments. Files tab items can be added to investigations by using the add file action block or the Add File button on the Files tab. Phantom memory requirements may increase depending on the Files tab usage, as files are stored in the Phantom database.
The Files tab on the Investigate page in Splunk Phantom is an area where users can manage and analyze files related to an investigation. Users can upload files, such as outputs from a ‘detonate file’ action which analyzes potentially malicious files in a sandbox environment. The files tab allows users to store and further investigate these outputs, which can include reports, logs, or any other file types that have been generated or are relevant to the investigation. The Files tab is an integral part of the investigation process, providing easy access to file data for analysis and correlation with other incident data.
Under Asset Ingestion Settings, how many labels must be applied when configuring an asset?
- A . Labels are not configured under Asset Ingestion Settings.
- B . One.
- C . One or more.
- D . Zero or more.
D
Explanation:
Under Asset Ingestion Settings in Splunk SOAR, when configuring an asset, the number of labels that must be applied can be zero or more. Labels are optional and are used to categorize data and control access. They are not a requirement under Asset Ingestion Settings, but they can be used to enhance organization and filtering if chosen.
Where can the Splunk App for SOAR Export be downloaded from?
- A . GitHub and Splunkbase.
- B . SOAR Community and GitHub.
- C . Splunkbase and SOAR Community.
- D . Splunk Answers and Splunkbase.
A
Explanation:
The Splunk App for SOAR Export can be downloaded from both GitHub and Splunkbase. Splunkbase is the official source for Splunk apps, where users can find, try, and download apps that enhance and extend the capabilities of Splunk, including the Splunk App for SOAR Export1. GitHub is also a common platform for sharing and collaborating on code, including Splunk apps and integrations. It is important to ensure that you are downloading from the official repository or author to avoid any security risks.
Reference: Splunkbase, the official source for downloading the Splunk App for SOAR Export
Which of the following are the default ports that must be configured on Splunk to allow connections from Phantom?
- A . SplunkWeb (8088), SplunkD (8089), HTTP Collector (8000)
- B . SplunkWeb (8089), SplunkD (8088), HTTP Collector (8000)
- C . SplunkWeb (8421), SplunkD (8061), HTTP Collector (8798)
- D . SplunkWeb (8000), SplunkD (8089), HTTP Collector (8088)
D
Explanation:
The correct answer is D because the default ports that must be configured on Splunk to allow connections from Phantom are SplunkWeb (8000), SplunkD (8089), and HTTP Collector (8088). SplunkWeb is the port used to access the Splunk web interface. SplunkD is the port used to communicate with the Splunk server. HTTP Collector is the port used to send data to Splunk using the HTTP Event Collector (HEC). These ports must be configured on Splunk and Phantom to enable the integration between the two products. See Splunk SOAR Documentation for more details.
To allow connections from Splunk Phantom to Splunk, certain default ports need to be open and properly configured. The default ports include SplunkWeb (8000) for web access, SplunkD (8089) for Splunk’s management port, and the HTTP Event Collector (HEC) on port 8088, which is used for ingesting data into Splunk. These ports are essential for the communication between Splunk Phantom and Splunk, facilitating data exchange, search capabilities, and the integration of various functionalities between the two platforms.
Which of the following is an advantage of using the Visual Playbook Editor?
- A . Eliminates any need to use Python code.
- B . The Visual Playbook Editor is the only way to generate user prompts.
- C . Supports Python or Javascript.
- D . Easier playbook maintenance.
D
Explanation:
Visual Playbook Editor is a feature of Splunk SOAR that allows you to create, edit, and implement automated playbooks using visual building blocks and execution flow lanes, without having to write code. The Visual Playbook Editor automatically generates the code for you, which you can view and edit in the Code Editor if needed. The Visual Playbook Editor also supports Python and Javascript as scripting languages for custom code blocks. One of the advantages of using the Visual Playbook Editor is that it makes playbook maintenance easier, as you can quickly modify, test, and debug your playbooks using the graphical interface. Therefore, option D is the correct answer, as it states an advantage of using the Visual Playbook Editor.
Option A is incorrect, because using the Visual Playbook Editor does not eliminate the need to use Python code, but rather simplifies the process of creating and editing code. You can still add custom Python code to your playbooks using the custom function block or the Code Editor.
Option B is incorrect, because the Visual Playbook Editor is not the only way to generate user prompts, but rather one of the ways. You can also generate user prompts using the classic playbook editor or the Code Editor.
Option C is incorrect, because supporting Python or Javascript is not an advantage of using the Visual Playbook Editor, but rather a feature of Splunk SOAR in general. You can use Python or Javascript in any of the playbook editors, not just the Visual Playbook Editor.
Without customizing container status within SOAR, what are the three types of status for a container?
- A . New, Open, Resolved
- B . Low, Medium, High
- C . New, In Progress, Closed
- D . Low, Medium, Critical
C
Explanation:
In Splunk SOAR, without any customization, the three default statuses for a container are New, In Progress, and Closed. These statuses are designed to reflect the lifecycle of an incident or event within the platform, from its initial detection and logging (New), through the investigation and response stages (In Progress), to its final resolution and closure (Closed). These statuses help in organizing and prioritizing incidents, tracking their progress, and ensuring a structured workflow. Options A, B, and D do not accurately represent the default container statuses within SOAR, making option C the correct answer.
containers are the top-level data structure that SOAR playbook APIs operate on. Containers can have different statuses that indicate their state and progress in the SOAR workflow.
Without customizing container status within SOAR, the three types of status for a container are:
• New: The container has been created but not yet assigned or investigated.
• In Progress: The container has been assigned and is being investigated or automated.
• Closed: The container has been resolved or dismissed and no further action is required.
Therefore, option C is the correct answer, as it lists the three types of status for a container without customizing container status within SOAR.
Option A is incorrect, because Resolved is not a type of status for a container without customizing container status within SOAR, but rather a custom status that can be defined by an administrator.
Option B is incorrect, because Low, Medium, and High are not types of status for a container, but rather types of severity that indicate the urgency or impact of a container.
Option D is incorrect, for the same reason as option B.
Splunk user account(s) with which roles must be created to configure Phantom with an external
Splunk Enterprise instance?
- A . superuser, administrator
- B . phantomcreate. phantomedit
- C . phantomsearch, phantomdelete
- D . admin,user
A
Explanation:
When configuring Splunk Phantom to integrate with an external Splunk Enterprise instance, it is typically required to have user accounts with sufficient privileges to access data and perform necessary actions. The roles of "superuser" and "administrator" in Splunk provide the broad set of permissions needed for such integration, enabling comprehensive access to data, management capabilities, and the execution of searches or actions that Phantom may require as part of its automated playbooks or investigations.
After enabling multi-tenancy, which of the Mowing is the first configuration step?
- A . Select the associated tenant artifacts.
- B . Change the tenant permissions.
- C . Set default tenant base address.
- D . Configure the default tenant.
D
Explanation:
Upon enabling multi-tenancy in Splunk SOAR, the first step in configuration typically involves setting up the default tenant. This foundational step is critical as it establishes the primary operating environment under which subsequent tenants can be created and managed. The default tenant serves as the template for permissions, settings, and configurations that might be inherited or customized by additional tenants. Proper configuration of the default tenant ensures a stable and consistent framework for multi-tenancy operations, allowing for segregated environments within the same SOAR instance, each tailored to specific operational needs or organizational units.
How does a user determine which app actions are available?
- A . Add an action block to a playbook canvas area.
- B . Search the Apps category in the global search field.
- C . From the Apps menu, click the supported actions dropdown for each app.
- D . In the visual playbook editor, click Active and click the Available App Actions dropdown.
C
Explanation:
In Splunk SOAR, a user can determine which app actions are available by navigating to the Apps menu. From there, the user can click on the supported actions dropdown for each app to view the actions that can be performed by that app. This dropdown menu provides a list of all the actions that the app is capable of executing, allowing the user to understand the functionality provided by the app and how it can be utilized within playbooks11.
Reference: Add and configure apps and assets to provide actions in Splunk SOAR (Cloud) – Splunk Documentation