SPLK-2003 Sample Questions & Answers
Configuring apps, assets and playbooks carries the most weight, next to working the queue analysts use plus the investigation page, the drag-and-drop playbook editor, parent and child playbooks, custom coding, integrating SOAR with Splunk itself, and the REST API.
Launch the full SPLK-2003 simulator →Showing 10 of 20 free samples.
- Question 1Advanced
Modular Playbook Development · Design modular solutions with interacting playbooks
Case Study:
A managed security service provider (MSSP) uses a single Splunk SOAR instance to serve multiple tenants. They have developed a standardized 'Threat Intel Enrichment' playbook that is used by all tenants. Recently, a new premium tenant requires a slightly different enrichment process that involves an additional, proprietary threat intelligence source. The MSSP wants to avoid duplicating the entire playbook for one minor change.
The current playbook structure is a single, monolithic playbook. The MSSP wants to re-architect the solution to be more modular and maintainable. They need to create a solution where the core enrichment logic is shared, but the premium tenant's workflow includes the extra step. All tenants should use the same initial trigger.
Which approach best meets the MSSP's requirements for modularity and minimal duplication?
Show answer & explanation
Correct answer: D
This approach is the most modular and scalable. It encapsulates the shared logic in a reusable child playbook ('Core Enrichment'). The parent playbook acts as a controller, handling the conditional logic to invoke the specialized 'Premium Enrichment' playbook only when necessary. This avoids duplicating the core logic and makes future modifications easier.
- Question 2Intermediate
Custom Lists and Data Routing · Access lists from playbooks
A developer is building a playbook that queries a custom list containing network CIDR ranges and their corresponding business units. The playbook receives an IP address as an artifact and must find the correct business unit. The custom list is named
business_unit_cidrs. Which block is best suited to perform this lookup directly within the visual playbook editor?Show answer & explanation
Correct answer: C
The Utility block provides a built-in 'cidr lookup' operation specifically for this use case. It allows the developer to provide an IP address and a custom list name, and it will automatically find the matching CIDR range and return the corresponding row from the list.
- Question 3Advanced
Using REST · Use Django queries to search for data in SOAR
A SOAR administrator is tasked with retrieving all containers with a 'High' severity that were created in the last 7 days using the REST API. Which Django-style filter query should be used with the
/rest/containerendpoint?Show answer & explanation
Correct answer: C
This query correctly filters by the severity name and uses the
__gte(greater than or equal to) operator with a relative time stringnow-7d/d. Filtering onseverity__nameis necessary becauseseverityis a foreign key. Combining filters requires using separate_filter_parameters for each condition. - Question 4Intermediate
Logic, Filters, and User Interaction · Describe the use of different join options
A developer notices that a playbook designed to block an IP address fails intermittently. The playbook uses two parallel action blocks to add the IP to two different firewalls. The playbook then proceeds to a single 'add note' block. The developer suspects a race condition. The following diagram shows the playbook flow. What is the most effective way to ensure both firewall blocks complete before the note is added?
graph TD A[Start] --> B{Get IP Artifact}; B --> C[Block IP on FW1]; B --> D[Block IP on FW2]; C --> E[Add Note]; D --> E;Show answer & explanation
Correct answer: B
A 'Join' block is specifically designed to solve this problem. It synchronizes multiple parallel execution paths in a playbook, ensuring that all incoming paths have completed their execution before allowing the playbook to proceed to the next block. This eliminates the race condition.
- Question 5Intermediate
Custom Coding · Use custom function blocks
When should a developer choose to use a Custom Function block over a series of native Visual Playbook Editor (VPE) blocks?
Show answer & explanation
Correct answer: B
Custom Functions are ideal for tasks that require the power and flexibility of Python, such as iterating over large datasets, complex transformations, interacting with APIs that don't have a dedicated SOAR app, or implementing algorithms that are cumbersome to build with visual blocks.
- Question 6Beginner
Formatted Output and Data Access · Use Format blocks to structure data
A playbook is designed to generate a summary report and add it as a note to the container. The report needs to include a list of malicious indicators found during the investigation, formatted as a markdown bulleted list. Which block is used to construct this formatted string?
Show answer & explanation
Correct answer: C
The 'Format' block is specifically designed to create structured text strings by combining static text with dynamic values from datapaths. It is the ideal tool for building reports, notes, or email bodies with markdown or HTML formatting.
- Question 7Beginner
Apps, Assets, and Playbooks · Manage playbooks
A developer needs to create a playbook that only runs on containers that have the 'Phishing' label AND have a severity of 'High' or 'Critical'. Which block is used to define these starting conditions for the playbook?
Show answer & explanation
Correct answer: B
The conditions under which an active playbook will automatically run are defined in the playbook's Settings tab. Here, you can specify labels, severity levels, and other container properties that must be met for the playbook to be triggered.
- Question 8Intermediate
Configuring External Splunk Search · Describe the benefits of externalizing search to Splunk
What is the primary purpose of externalizing the Splunk SOAR search to a remote Splunk instance?
Show answer & explanation
Correct answer: B
The main benefit of externalizing search is performance. The SOAR instance can focus on its primary role of orchestration and automation, while the powerful and scalable Splunk platform handles searching, reporting, and long-term data storage and analysis.
- Question 9Beginner
Visual Playbook Editor · Execute actions from a playbook
A playbook needs to send an email to a distribution list. The body of the email should contain the container name and its severity. The correct way to pass these values to the 'send email' action is through the
____parameter.Show answer & explanation
Correct answer: B
The 'send email' action typically has a 'body' parameter where the main content of the email is specified. Datapaths to the container name and severity would be included here.
- Question 10IntermediateSelect 2
Case Management and Workbooks · Use workbooks
Which of the following are valid use cases for a workbook in Splunk SOAR? (Select TWO)
Show answer & explanation
Correct answers: B, D
Workbooks are designed to enforce consistent, process-oriented investigations by providing a checklist of phases and tasks for analysts to follow.
Workbooks serve as structured templates, ensuring that all necessary steps in an incident response process are considered and completed.
Ready for the real thing?
The full SPLK-2003 simulator has every exam-style question, timed mode, and instant scoring.