Splunk SPLK-2003 Practice Exams
Last updated on Oct 07,2026- Exam Code: SPLK-2003
- Exam Name: Splunk SOAR Certified Automation Developer Exam
- Certification Provider: Splunk
- Latest update: Oct 07,2026
Which of the following is a step when configuring event forwarding from Splunk to Phantom?
- A . Map CIM to CEF fields.
- B . Create a Splunk alert that uses the event_forward.py script to send events to Phantom.
- C . Map CEF to CIM fields.
- D . Create a saved search that generates the JSON for the new container on Phantom.
B
Explanation:
A step when configuring event forwarding from Splunk to Phantom is to create a Splunk alert that uses the event_forward.py script to send events to Phantom. This script will convert the Splunk events to CEF format and send them to Phantom as containers. The other options are not valid steps for event forwarding. See Forwarding events from Splunk to Phantom for more details.
Configuring event forwarding from Splunk to Phantom typically involves creating a Splunk alert that leverages a script (like event_forward.py) to automatically send triggered event data to Phantom. This setup enables Splunk to act as a detection mechanism that, upon identifying notable events based on predefined criteria, forwards these events to Phantom for further orchestration, automation, and response actions. This integration streamlines the process of incident management by connecting Splunk’s powerful data analysis capabilities with Phantom’s orchestration and automation framework.
Some of the playbooks on the SOAR server should only be executed by members of the admin role.
How can this rule be applied?
- A . Make sure the Execute Playbook capability is removed from all roles except admin.
- B . Place restricted playbooks in a second source repository that has restricted access.
- C . Add a filter block to all restricted playbooks that filters for runRole = "Admin".
- D . Add a tag with restricted access to the restricted playbooks.
A
Explanation:
To restrict playbook execution to members of the admin role within Splunk SOAR, the ‘Execute Playbook’ capability must be managed appropriately. This is done by ensuring that this capability is removed from all other roles except the admin role. Role-based access control (RBAC) in Splunk SOAR allows for granular permissions, which means you can configure which roles have the ability to execute playbooks, and by restricting this capability, you can control which users are able to initiate playbook runs.
Some of the playbooks on the Phantom server should only be executed by members of the admin role.
How can this rule be applied?
- A . Add a filter block to al restricted playbooks that Titters for runRole – "Admin”.
- B . Add a tag with restricted access to the restricted playbooks.
- C . Make sure the Execute Playbook capability is removed from al roles except admin.
- D . Place restricted playbooks in a second source repository that has restricted access.
C
Explanation:
The correct answer is C because the best way to restrict the execution of playbooks to members of the admin role is to make sure the Execute Playbook capability is removed from all roles except admin. The Execute Playbook capability is a permission that allows a user to run any playbook on any container. By default, all roles have this capability, but it can be removed or added in the Phantom UI by going to Administration > User Management > Roles. Removing this capability from all roles except admin will ensure that only admin users can execute playbooks. See Splunk SOAR Documentation for more details. To ensure that only members of the admin role can execute specific playbooks on the Phantom server, the most effective approach is to manage role-based access controls (RBAC) directly. By configuring the system to remove the "Execute Playbook" capability from all roles except for the admin role, you can enforce this rule. This method leverages Phantom’s built-in RBAC mechanisms to restrict playbook execution privileges. It is a straightforward and secure way to ensure that only users with the necessary administrative privileges can initiate the execution of sensitive or critical playbooks, thus maintaining operational security and control.
In a playbook, more than one Action block can be active at one time.
What is this called?
- A . Serial Processing
- B . Parallel Processing
- C . Multithreaded Processing
- D . Juggle Processing
B
Explanation:
In Splunk SOAR, when a playbook is designed such that more than one Action block is active at the same time, it is referred to as ‘Parallel Processing’. This allows for multiple actions to be executed concurrently, which can significantly speed up the execution of a playbook as it does not have to wait for one action to complete before starting another. Parallel processing enables more efficient use of resources and time, particularly in complex playbooks that perform numerous actions.
On the Splunk search head, when configuring the app to search SOAR searchable content, what are the two requirements to complete the app setup?
- A . User accounts and universal forwarder.
- B . User accounts and an HTTP Event Collector token.
- C . User accounts and REST API.
- D . User accounts and syslog.
B
Explanation:
When configuring the Splunk app on the search head to search SOAR (Splunk’s Security Orchestration, Automation, and Response) searchable content, two key components are required:
User Accounts: The user accounts are necessary to authenticate and authorize users who are accessing SOAR data through the Splunk app. These accounts manage permissions and access levels to ensure the proper users can search and interact with the data coming from SOAR.
HTTP Event Collector (HEC) Token: The HEC token is crucial because it allows the Splunk app to receive data from Splunk SOAR. SOAR sends events and other data to the Splunk platform via HEC. This token is used for secure communication and authentication between Splunk and SOAR. The token must be configured in the Splunk app to allow it to collect and search SOAR data seamlessly.
Other options like syslog, REST API, or a universal forwarder are commonly used methods for ingesting data into Splunk but are not specific requirements for setting up the Splunk app to search SOAR content. The HTTP Event Collector is the primary method for this setup, along with the correct user accounts.
Reference: Splunk Documentation on HTTP Event Collector and SOAR Integration.
Splunk SOAR App Setup Guide for Splunk Search Head Configuration.
When writing a custom function that uses regex to extract the domain name from a URL, a user wants to create a new artifact for the extracted domain.
Which of the following Python API calls will create a new artifact?
- A . phantom.new_artifact ()
- B . phantom. update ()
- C . phantom.create_artifact ()
- D . phantom.add_artifact ()
C
Explanation:
In the Splunk SOAR platform, when writing a custom function in Python to handle data such as extracting a domain name from a URL, you can create a new artifact using the Python API call phantom.create_artifact(). This function allows you to specify the details of the new artifact, such as the type, CEF (Common Event Format) data, container it belongs to, and other relevant information necessary to create an artifact within the system.
Is it possible to import external Python libraries such as the time module?
- A . No.
- B . No, but this can be changed by setting the proper permissions.
- C . Yes, in the global block.
- D . Yes. from a drop-down menu.
C
Explanation:
In Splunk SOAR, it is possible to import external Python libraries, such as the time module, within the scope of a playbook’s global code block. The global block allows users to define custom Python code, including imports of standard Python libraries that are included in the Phantom platform’s Python environment. This capability enables the extension of playbooks’ functionality with additional Python logic, making playbooks more powerful and versatile in their operations.
Why does SOAR use wildcards within artifact data paths?
- A . To make playbooks more specific.
- B . To make playbooks filter out nulls.
- C . To make data access in playbooks easier.
- D . To make decision execution in playbooks run faster.
C
Explanation:
Wildcards are used within artifact data paths in Splunk SOAR playbooks to simplify the process of accessing data. They allow playbooks to reference dynamic or variable data structures without needing to specify exact paths, which can vary between artifacts. This flexibility makes it easier to write playbooks that work across different events and scenarios, without hard-coding data paths.
SOAR uses wildcards within artifact data paths to make data access in playbooks easier. A data path is a way of specifying the location of a piece of data within an artifact.
For example, rtifact.cef.sourceAddress is a data path that refers to the source address field of the artifact. A wildcard is a special character that can match any value or subfield within a data path. For example, artifact.*.cef.sourceAddress is a data path that uses a wildcard to match any field name before the cef subfield. This allows the playbook to access the source address data regardless of the field name, which can vary depending on the app or source that generated the artifact. Therefore, option C is the correct answer, as it explains why SOAR uses wildcards within artifact data paths.
Option A is incorrect, because wildcards do not make playbooks more specific, but more flexible and adaptable.
Option B is incorrect, because wildcards do not make playbooks filter out nulls, but match any value or subfield.
Option D is incorrect, because wildcards do not make decision execution in playbooks run faster, but make data access in playbooks easier.
1: Understanding datapaths in Administer Splunk SOAR (Cloud)
What are the components of the I2A2 design methodology?
- A . Inputs, Interactions, Actions, Apps
- B . Inputs, Interactions, Actions, Artifacts
- C . Inputs, Interactions, Apps, Artifacts
- D . Inputs, Interactions, Actions, Assets
B
Explanation:
I2A2 design methodology is a framework for designing playbooks that consists of four components:
• Inputs: The data that is required for the playbook to run, such as artifacts, parameters, or custom fields.
• Interactions: The blocks that allow the playbook to communicate with users or other systems, such as prompts, comments, or emails.
• Actions: The blocks that execute the core logic of the playbook, such as app actions, filters, decisions, or utilities.
• Artifacts: The data that is generated or modified by the playbook, such as new artifacts, container fields, or notes.
The I2A2 design methodology helps you to plan, structure, and test your playbooks in a modular and efficient way. Therefore, option B is the correct answer, as it lists the correct components of the I2A2 design methodology.
Option A is incorrect, because apps are not a component of the I2A2 design methodology, but a source of actions that can be used in the playbook.
Option C is incorrect, for the same reason as option A.
Option D is incorrect, because assets are not a component of the I2A2 design methodology, but a configuration of app credentials that can be used in the playbook.
1: Use a playbook design methodology in Administer Splunk SOAR (Cloud)
The I2A2 design methodology is an approach used in Splunk SOAR to structure and design playbooks. The acronym stands for Inputs, Interactions, Actions, and Artifacts. This methodology guides the creation of playbooks by focusing on these four key components, ensuring that all necessary aspects of an automated response are considered and effectively implemented within the platform.
Configuring SOAR search to use an external Splunk server provides which of the following benefits?
- A . The ability to run more complex reports on SOAR activities.
- B . The ability to ingest Splunk notable events into SOAR.
- C . The ability to automate Splunk searches within SOAR.
- D . The ability to display results as Splunk dashboards within SOAR.
C
Explanation:
Configuring SOAR search to use an external Splunk server allows for the automation of Splunk searches within SOAR. This integration enables Splunk SOAR to leverage the powerful search capabilities of an external Splunk Cloud Platform or Enterprise instance, thereby enhancing the ability to search for Splunk SOAR data using Splunk’s search language (SPL). It also facilitates the use of universal forwarders to send SOAR data to your Splunk deployment12. While the other options may be benefits of using Splunk in general, the specific advantage of configuring SOAR search with an external Splunk server is the automation of searches, which can streamline the process of querying and analyzing SOAR data within the Splunk environment12.
Reference: Splunk SOAR documentation on configuring search in Splunk SOAR1.
Splunk SOAR documentation on understanding the remote-search service in Splunk App for SOAR2