Splunk SPLK-2003 Practice Exams
Last updated on Oct 07,2026- Exam Code: SPLK-2003
- Exam Name: Splunk SOAR Certified Automation Developer Exam
- Certification Provider: Splunk
- Latest update: Oct 07,2026
Which of the following actions will store a compressed, secure version of an email attachment with suspected malware for future analysis?
- A . Copy/paste the attachment into a note.
- B . Add a link to the file in a new artifact.
- C . Use the Files tab on the Investigation page to upload the attachment.
- D . Use the Upload action of the Secure Store app to store the file in the database.
D
Explanation:
To securely store a compressed version of an email attachment suspected of containing malware for future analysis, the most effective approach within Splunk SOAR is to use the Upload action of the Secure Store app. This app is specifically designed to handle sensitive or potentially dangerous files by securely storing them within the SOAR database, allowing for controlled access and analysis at a later time. This method ensures that the file is not only safely contained but also available for future forensic or investigative purposes without risking exposure to the malware. Options A, B, and C do not provide the same level of security and functionality for handling suspected malware files, making option D the most appropriate choice.
Secure Store app is a SOAR app that allows you to store files securely in the SOAR database. The Secure Store app provides two actions: Upload and Download. The Upload action takes a file as an input and stores it in the SOAR database in a compressed and encrypted format. The Download action takes a file ID as an input and retrieves the file from the SOAR database and decrypts it. The Secure Store app can be used to store files that contain sensitive or malicious data, such as email attachments with suspected malware, for future analysis. Therefore, option D is the correct answer, as it states the action that will store a compressed, secure version of an email attachment with suspected malware for future analysis.
Option A is incorrect, because copying and pasting the attachment into a note will not store the file securely, but rather expose the file content to anyone who can view the note.
Option B is incorrect, because adding a link to the file in a new artifact will not store the file securely, but rather create a reference to the file location, which may not be accessible or reliable.
Option C is incorrect, because using the Files tab on the Investigation page to upload the attachment will not store the file securely, but rather store the file in the SOAR file system, which may not be encrypted or compressed.
Which of the following are tabs of an asset configuration?
- A . Asset Name, Asset IP, Asset URL, Asset Nickname
- B . Tags, Asset Name, Asset Date, Asset Order
- C . App Name, App Order, App Expiry, App Version
- D . Asset Info, Asset Settings, Approval Settings, Access Control
D
Explanation:
In Splunk SOAR, the asset configuration consists of several key tabs that are essential for setting up
and managing an asset. These tabs include:
Asset Info: Contains general information about the asset, such as its name and description.
Asset Settings: This tab allows for configuring specific settings related to the asset, including any connections or integrations.
Approval Settings: This section manages settings related to the approval process for actions that require explicit authorization.
Access Control: This tab helps control user access to the asset, specifying permissions and roles.
These four tabs are essential for configuring an asset in SOAR, making sure the asset works as expected and that the right people have access to it.
Reference: Splunk SOAR Documentation: Asset Configuration.
Splunk SOAR Best Practices: Asset Management and Configuration.
How can a child playbook access the parent playbook’s action results?
- A . Child playbooks can access parent playbook data while the parent Is still running.
- B . By setting scope to ALL when starting the child.
- C . When configuring the playbook block in the parent, add the desired results in the Scope parameter.
- D . The parent can create an artifact with the data needed by the did.
C
Explanation:
In Splunk Phantom, child playbooks can access the action results of a parent playbook through the use of the Scope parameter. When a parent playbook calls a child playbook, it can pass certain data along by setting the Scope parameter to include the desired action results. This parameter is configured within the playbook block that initiates the child playbook. By specifying the appropriate scope, the parent playbook effectively determines what data the child playbook will have access to, allowing for a more modular and organized flow of information between playbooks.
Which of the following is the best option for an analyst who wants to run a single action on an event?
- A . Open the event and run this single action from the Investigation View.
- B . Create a playbook with a single action then use the Playbook Debugger on the event ID.
- C . Create a playbook with the action and run it from the Investigation View.
- D . Open a playbook with a single action, mark it active, and then use the Playbook Debugger on the event ID.
A
Explanation:
The best option for an analyst who wants to run a single action on an event is to open the event and run the action directly from the Investigation View. The Investigation View allows users to interact with events directly, and provides the ability to execute specific actions without the need for playbook development or debugging. This is the most straightforward and efficient way to execute a single action on an event, without the overhead of creating or editing playbooks.
While creating a playbook and using the Playbook Debugger are viable options, they introduce unnecessary complexity for running just one action. The goal is to allow the analyst to act quickly and efficiently within the Investigation View.
Reference: Splunk SOAR Documentation: Investigation View Overview.
Splunk SOAR Best Practices for Running Actions on Events.
Playbooks typically handle which types of data?
- A . Container data, Artifact CEF data, Result data. Threat data
- B . Container CEF data, Artifact data, Result data, List data
- C . Container data, Artifact CEF data, Result data, List data
- D . Container data, Artifact data, Result data, Threat data
C
Explanation:
Playbooks in Splunk SOAR are designed to handle various types of data to automate responses to security incidents.
The correct types of data handled by playbooks include:
Container Data: Containers are used to group related data for an incident or event. Playbooks can access this information to perform actions and make decisions.
Artifact CEF Data: Artifacts hold detailed information about the event or incident, including CEF (Common Event Format) data. Playbooks often process this CEF data for various actions.
Result Data: This refers to the data generated from actions executed by the playbook, such as results from API calls, integrations, or automated responses.
List Data: Lists in Splunk SOAR are collections of reusable data (such as IP blocklists, whitelists, etc.) that playbooks can access to check values or make decisions based on external lists.
The inclusion of List data instead of Threat data distinguishes this option from others, as lists are
more directly used by playbooks during execution, whereas threat data is a broader category that is often processed but not always directly handled by playbooks.
Reference: Splunk SOAR Documentation: Playbook Data Handling.
Splunk SOAR Best Practices: Automating with Playbooks.
Why is it good playbook design to create smaller and more focused playbooks? (select all that apply)
- A . Reduces amount of playbook data stored in each repo.
- B . Reduce large complex playbooks which become difficult to maintain.
- C . Encourages code reuse in a more compartmentalized form.
- D . To avoid duplication of code across multiple playbooks.
BCD
Explanation:
Creating smaller and more focused playbooks in Splunk SOAR is considered good design practice for several reasons:
• B: It reduces complexity, making playbooks easier to maintain. Large, complex playbooks can become unwieldy and difficult to troubleshoot or update.
• C: Encourages code reuse, as smaller playbooks can be designed to handle specific tasks that can be reused across different scenarios.
• D: Avoids duplication of code, as common functionalities can be centralized within specific playbooks, rather than having the same code replicated across multiple playbooks.
This approach has several benefits, such as:
• Reducing large complex playbooks which become difficult to maintain. Smaller playbooks are easier to read, debug, and update1.
• Encouraging code reuse in a more compartmentalized form. Smaller playbooks can be used as building blocks for multiple scenarios, reducing the need to write duplicate code12.
• Improving performance and scalability. Smaller playbooks can run faster and consume less resources than larger playbooks2.
The other options are not valid reasons for creating smaller and more focused playbooks. Reducing the amount of playbook data stored in each repo is not a significant benefit, as the playbook data is not very large compared to other types of data in Splunk SOAR. Avoiding duplication of code across multiple playbooks is a consequence of code reuse, not a separate goal.
When configuring a Splunk asset for Phantom to connect to a SplunkC loud instance, the user discovers that they need to be able to run two different on_poll searches.
How is this possible
- A . Enter the two queries in the asset as comma separated values.
- B . Configure the second query in the Phantom app for Splunk.
- C . Install a second Splunk app and configure the query in the second app.
- D . Configure a second Splunk asset with the second query.
D
Explanation:
In scenarios where there’s a need to run different on_poll searches for a Splunk Cloud instance from Splunk SOAR, configuring a second Splunk asset for the additional query is a practical solution. Splunk SOAR’s architecture allows for multiple assets of the same type to be configured with distinct settings. By setting up a second Splunk asset specifically for the second on_poll search query, users can maintain separate configurations and ensure that each query is executed in its intended context without interference. This approach provides flexibility in managing different data collection or monitoring needs within the same SOAR environment.
How can an individual asset action be manually started?
- A . With the > action button in the analyst queue page.
- B . By executing a playbook in the Playbooks section.
- C . With the > action button in the Investigation page.
- D . With the > asset button in the asset configuration section.
C
Explanation:
An individual asset action can be manually started with the > action button in the Investigation page. This allows the user to select an asset and an action to perform on it. The other options are not valid ways to start an asset action manually. See Performing asset actions for more information. Individual asset actions in Splunk SOAR can be manually initiated from the Investigation page of a container.
The "> action" button on this page allows users to execute specific actions associated with assets directly, enabling on-the-fly operations on artifacts or indicators within a container. This feature is particularly useful for ad-hoc analysis and actions, allowing analysts to respond to or investigate specific aspects of an incident without the need for a full playbook.
What metrics can be seen from the System Health Display? (select all that apply)
- A . Playbook Usage
- B . Memory Usage
- C . Disk Usage
- D . Load Average
BCD
Explanation:
System Health Display is a dashboard that shows the status and performance of the SOAR processes and components, such as the automation service, the playbook daemon, the DECIDED process, and the REST API.
Some of the metrics that can be seen from the System Health Display are:
• Memory Usage: The percentage of memory used by the system and the processes.
• Disk Usage: The percentage of disk space used by the system and the processes.
• Load Average: The average number of processes in the run queue or waiting for disk I/O over a period of time.
Therefore, options B, C, and D are the correct answers, as they are the metrics that can be seen from the System Health Display.
Option A is incorrect, because Playbook Usage is not a metric that can be seen from the System Health Display, but rather a metric that can be seen from the Playbook Usage dashboard, which shows the number of playbooks and actions run over a period of time.
1: Web search results from search_web(query="Splunk SOAR Automation Developer System Health Display")
The System Health Display in Splunk SOAR provides several metrics to help monitor and manage the health of the system. These typically include:
• B: Memory Usage – This metric shows the amount of memory being used by the SOAR platform, which is important for ensuring that the system does not exceed available resources.
• C: Disk Usage – This metric indicates the amount of storage space being utilized, which is crucial for maintaining adequate storage resources and for planning capacity.
• D: Load Average – This metric provides an indication of the overall load on the system over a period of time, which helps in understanding the system’s performance and in identifying potential bottlenecks or issues.
Playbook Usage is generally not a metric displayed on the System Health page; instead, it’s more related to the usage analytics of playbooks rather than system health metrics.
Which Phantom API command is used to create a custom list?
- A . phantom.add_list()
- B . phantom.create_list()
- C . phantom.include_list()
- D . phantom.new_list()
B
Explanation:
The Phantom API command to create a custom list is phantom.create_list(). This command takes a list name and an optional description as parameters and returns a list ID if successful. The other commands are not valid Phantom API commands. phantom.add_list() is a Python function that can be used in custom code blocks to add data to an existing list. To create a custom list in Splunk Phantom, the appropriate API command used is phantom.create_list(). This function allows for the creation of a new list that can be used to store data such as IP addresses, file hashes, or any other information that you want to track or reference across multiple playbooks or within different parts of the Phantom platform. The custom list is a flexible data structure that can be leveraged for various use cases within Phantom, including data enrichment, persistent storage of information, and cross-playbook data sharing.