Splunk Test Blueprint Soar Automation Developer
Splunk Test Blueprint Soar Automation Developer
The Splunk SOAR Certified Automation Developer exam is the final step towards
completion of the Splunk SOAR Certified Automation Developer certification
track—formerly referred to as Splunk Phantom Certified Admin.
Exam Content
The following topics are general guidelines for the content likely to be included on the
exam; however, other related topics may also appear on any specific delivery of the
exam. In order to better reflect the contents of the exam and for clarity purposes, the
guidelines below may change at any time without notice.
1
3.0 Apps, Assets, and Playbooks 5%
3.1 Configure apps
3.2 Configure assets
3.3 Configure data ingestion assets
3.4 Configure labels and SLAs
3.5 Manage playbooks
7.0 Customizations 5%
7.1 Customize severity levels
7.2 Customize CEF fields
7.3 Customize status values
7.4 Customize workbooks
7.5 Add global custom fields to containers
2
8.0 System Maintenance 5%
8.1 Run reports
8.2 Use system health displays
8.3 Examine health logs
3
13.0 Modular Playbook Development 5%
13.1 Design modular solutions with interacting playbooks
13.2 Invoke child playbooks from a parent
13.3 Exchange data between playbooks
4
18.0 Using REST 5%
18.1 Describe the capabilities of SOAR REST API
18.2 Use Django queries to search for data in SOAR
18.3 Use SOAR REST from other systems to access SOAR data
Exam Preparation
Candidates may reference the Splunk How-To YouTube Channel, Splunk Docs, and
draw from their own Splunk experience.
The following is a suggested and non-exhaustive list of training from the SOAR
Certified Automation Developer Learning Path that may cover topics listed in the
above blueprint:
❏ Administering SOAR*
*The 9-hour legacy course, Administering SOAR, also presented the topics covered in
this exam. The 9-hour legacy course is now broken down into two shorter courses:
Administering SOAR and Investigating Splunk Incidents with SOAR.