Splunk SOAR Certified Automation Developer Exam Guide
The Splunk SOAR Certified Automation Developer exam validates professional-level ability to configure a SOAR server, integrate it with Splunk, and plan, build, and debug playbooks. It is most relevant to practitioners who design or maintain SOAR automation and related administration tasks. This guide helps you decide whether your current experience matches the legacy exam, which blueprint areas need deliberate practice, and how to schedule preparation without relying on unauthorized question memorization.
What the certification validates
This certification assesses a combination of SOAR administration and automation-development skills rather than playbook construction in isolation. The official track describes abilities involving SOAR-server installation and configuration, Splunk integration, and the planning, design, creation, and debugging of playbooks. Review the official track at https://www.splunk.com/en_us/pdfs/training/splunk-soar-certified-automation-developer-track.pdf.
The certification was formerly referred to as Splunk Phantom Certified Admin. That older name matters when searching for training references or internal experience records, but the current certification title and current official blueprint should control your preparation decisions.
Splunk describes the exam as professional-level. That designation is a useful signal about the expected breadth: a candidate should connect configuration choices, operational workflows, app actions, and playbook behavior instead of studying isolated interface labels.
The practical capability behind the title
A useful interpretation of the credential is that you should be able to reason through a SOAR implementation from its foundation to its automation logic. That includes understanding how deployment and initial configuration relate to users, apps, assets, and playbooks, then diagnosing why an automation flow does not produce the intended result.
The exam page presents the certification as demonstrating complex SOAR solution capabilities and growing knowledge of installing and configuring a SOAR server and integrating it with the Splunk platform. Treat that description as a scope statement, not as a promise that every question will describe a complete implementation.
Who should consider this exam
The strongest fit is a candidate whose work or laboratory practice includes SOAR administration, app and asset configuration, playbook design, or troubleshooting. Candidates coming from a Splunk integration role may need to strengthen SOAR-specific administration, while candidates with automation experience may need more practice with server, user, app, and asset topics.
There is no prerequisite certification or prerequisite course according to Splunk’s certification track document: https://www.splunk.com/en_us/pdfs/training/splunk-soar-certified-automation-developer-track.pdf. That removes a formal entry barrier, but it does not remove the need to learn the product areas named in the blueprint.
Use a capability check before paying for an attempt. Can you explain the purpose of the main configuration objects in the blueprint, follow a playbook’s data flow, interpret an action result, and identify a sensible debugging step? If several answers are uncertain, study first rather than treating the absence of prerequisites as evidence that the exam will be introductory.
When the legacy designation changes your decision
Splunk lists Splunk SOAR Certified Automation Developer as a legacy certification on its certification page: https://www.splunk.com/en_us/training/certification-track/splunk-soar-certified-automation-developer.html. The blueprint also states that legacy exam content will no longer be actively maintained or updated to reflect product changes or releases.
Before scheduling, confirm that this legacy credential still serves your employer, role plan, or skills record. If your objective is a current certification pathway rather than a specific historical credential, compare the available options through Splunk’s certification overview and learning-path pages. Do not assume that a legacy exam represents the newest product behavior.
If you proceed, use the official blueprint as the controlling scope document and verify scheduling information on the official exam page. Avoid study material that presents an unverified product version as the definitive target.
What the blueprint expects you to study
The blueprint groups the work into administration, operations, and automation topics. It covers deployment, installation, initial configuration, user management, apps, assets, and playbooks; it also covers analyst-queue use, investigation-page operations, case management, workbooks, customizations, and system maintenance. Read the blueprint before selecting courses or practice exercises: https://www.splunk.com/en_us/pdfs/training/splunk-test-blueprint-soar-automation-developer.pdf.
The blueprint includes automation best practices, playbook capabilities, available app actions, and the I2A2 design methodology. These subjects call for design reasoning. Memorizing a list of action names is less useful than being able to choose an appropriate action, understand its inputs and outputs, and place it in a controlled workflow.
A second cluster focuses on visual playbook editing, decision and filter blocks, join options, user interaction during execution, format blocks, and action-result structure. Prepare to trace a flow from input through branching, joining, formatting, and result handling. Your notes should show relationships between these elements rather than treating each as an unrelated feature.
Administration and platform foundation
Start with deployment, installation, and initial configuration because later automation depends on a correctly understood environment. Then cover user management, apps, assets, and playbooks. For each topic, write a short explanation of its purpose, the type of configuration it controls, and the symptoms you would investigate when an automation cannot use it as intended.
The blueprint’s inclusion of system maintenance means your study should not stop once a playbook appears to run. Include operational review questions: what configuration is involved, what object is being used, what dependency might be missing, and where would you inspect the result? These are preparation prompts, not claims about exact exam wording.
Use official learning resources and the available Splunk learning-path information to identify suitable study material: https://www.splunk.com/en_us/training/learning-paths-certifications.html. Map every resource to a blueprint topic before spending time on it.
Analyst workflow and investigation work
The blueprint covers analyst-queue use, investigation-page operations, case management, workbooks, customizations, and system maintenance. Study these as connected operational tasks. A sound exercise should begin with an analyst-facing investigation, move through case or workbook handling, and finish with a review of what the automation changed or returned.
Do not study administration and analyst operations as completely separate subjects. A configuration choice can affect what an analyst can use, while an analyst workflow can expose a problem in an app, asset, action, or playbook. Build a matrix with the workflow area in one column and the relevant configuration or automation dependency in another.
For each area, practice explaining the operator’s objective before naming a screen or option. This reduces dependence on interface memory and helps you reason when wording describes a task rather than displaying a familiar label.
Automation design and debugging
The automation portion requires more than knowing how to place blocks on a canvas. Review automation best practices, playbook capabilities, available app actions, I2A2 design methodology, visual editing, decision and filter blocks, join options, user interaction, format blocks, and action-result structure.
A productive exercise is to design a small response flow on paper first. Identify the input, the intended action, the data required by that action, the possible result, the decision point, and the final output. Then inspect where a filter, decision, join, format step, or user interaction belongs. Finally, list what you would check if the flow stopped or returned an unexpected value.
Keep a separate debugging log. For every failed exercise, record the assumed input, the actual result, the block where your assumption became invalid, and the correction. This trains diagnosis rather than passive recognition.
How to turn the blueprint into a study plan
Study in dependency order: establish the platform foundation, learn the analyst workflow, then design and debug automation that uses those concepts. This sequence is a practical recommendation, not an official required course order. It prevents you from trying to memorize playbook behavior without understanding the objects and operational context around it.
Begin by downloading the official blueprint and converting each listed topic into a checklist. Mark each item as explain, perform, troubleshoot, or review. “Explain” means you can describe its purpose; “perform” means you can complete a task in an authorized environment; “troubleshoot” means you can reason from a symptom to a likely inspection point.
Use the official certification study resources as a source-selection aid: https://www.splunk.com/en_us/resources/splunk-certification-exam-study-guide.html. Where a third-party explanation conflicts with the official blueprint or current official exam information, pause and verify rather than combining both descriptions into an uncertain rule.
A four-stage preparation sequence
Stage one is scope and terminology. Read the blueprint, list every named domain or capability, and identify unfamiliar terms such as I2A2, action-result structure, join options, and workbook operations. At this stage, do not attempt to memorize interface sequences. Your goal is a stable map of the exam.
Stage two is environment and operations. Work through deployment, installation, initial configuration, user management, apps, assets, analyst-queue use, investigation-page operations, case management, workbooks, customizations, and system maintenance. For each topic, produce a task explanation and a troubleshooting question.
Stage three is automation construction. Create or review playbook flows using visual editing, decision and filter blocks, join options, format blocks, user interaction, and action-result handling. Make the data movement visible in your notes. Ask what enters each step, what leaves it, and what condition changes the path.
Stage four is timed consolidation. Revisit only the topics where your explanations remain vague or your practical steps are inconsistent. Use short, mixed-topic review sessions so that you must switch between administration, analyst operations, and automation reasoning.
A study-notes format that exposes gaps
Use one page or digital record for each blueprint item. Give it four fields: purpose, related objects or workflow, failure signal, and verification step. For a playbook topic, add input, output, branch condition, and join behavior. For an administration topic, add the configuration dependency and the user-facing consequence.
This structure makes weak knowledge visible. A note that contains only a definition is not ready for practical review. A note that gives a sequence without explaining why the sequence works is also fragile. Rewrite both until you can explain the decision in plain language.
Keep official facts separate from your recommendations. For example, the blueprint’s listed coverage is official; choosing to practice one connected workflow before isolated features is your study method. That distinction prevents your revision notes from turning advice into an invented exam requirement.
How to practise without relying on exam dumps
Use authorized product practice, official documentation, blueprint-led recall, and your own troubleshooting exercises. Do not use leaked questions or dumps as a substitute for understanding. They cannot establish that your knowledge matches the official scope, and memorization does not guarantee a passing result.
Create scenario prompts without reproducing live exam content. Examples include tracing why a playbook receives the wrong data type, deciding where a filter belongs, explaining how a join affects downstream execution, or identifying which configuration area deserves inspection when an app action cannot complete. These prompts test transferable reasoning rather than recalled wording.
After each exercise, explain both the correct path and one plausible incorrect path. The second explanation is valuable because it reveals whether you understand the boundary between similar blocks, workflow stages, or configuration objects.
If you lack access to a practice environment, use diagrams and written walkthroughs carefully. Label assumptions, distinguish documented behavior from your proposed design, and avoid treating a hypothetical flow as proof of product behavior. Seek an authorized lab, course, or product documentation when the distinction matters.
A repeatable playbook drill
Choose one practical objective, identify its input, select the required app action, and sketch the result handling before opening the visual editor. Add a decision or filter only when the workflow needs a condition. Add a join when separate paths must converge, and use a format step when downstream processing requires a deliberate representation of the data.
Then test your explanation at each transition. What does the next block need? What does the previous block actually provide? What happens when the action returns an empty, unexpected, or unsuccessful result? Where would a user interaction be appropriate, and what should happen after it? These questions align directly with the blueprint’s named automation capabilities without claiming to reproduce exam questions.
Finish by writing a debugging sequence. Start with the observed symptom, check the relevant input or result, inspect the block or dependency, and verify the corrected flow. The value of the drill comes from the reasoning record, not from how quickly you draw the playbook.
A safer way to use practice questions
Practice questions are useful only when they are traceable to the blueprint and followed by an explanation. For every answer, identify the tested skill, why the selected option fits, why the alternatives do not, and what evidence would settle the issue in a real authorized environment.
Be cautious with question banks that claim to contain exact current exam items, especially for a legacy certification whose content is not actively maintained or updated for product changes or releases. Treat unsupported claims about question counts, scoring, or guaranteed success as warning signs unless the official source confirms them.
A strong review session ends with an action: revise a note, repeat a lab task, consult an official source, or mark the topic as ready. Do not count exposure to answer choices as mastery.
What the exam logistics confirm
Splunk states that the exam is delivered by Pearson VUE and that its format is multiple choice. The official exam page lists a 60-minute exam length, while the blueprint specifies 45 questions and explains that the 60-minute total exam time includes three minutes to review the exam agreement. Confirm current scheduling instructions on the official page before booking: https://www.splunk.com/en_us/training/certification-track/splunk-soar-certified-automation-developer.html.
The listed price is $130 USD per exam attempt, also shown on the official exam page. Because scheduling terms and commercial details can change, treat the official page as the final authority at the point of purchase rather than relying on an old article or training listing.
The exam page identifies this as a legacy certification. That status should be part of your scheduling decision, not an afterthought. Verify that the credential is still the one your organization or professional objective requires before committing an attempt.
How to use the time responsibly
The blueprint gives you 60 minutes total, including three minutes to review the exam agreement, and specifies 45 questions. That leaves a constrained working period, so practise reading for the tested task first: identify whether the prompt is about configuration, workflow operation, playbook design, or troubleshooting before considering the answer choices.
Do not turn the official timing information into a promise about how quickly you should answer every question. Use it to build a personal pacing plan. During practice, record where you spend time, flag questions that require a second pass, and reserve a final review period for marked items if the delivery interface permits it.
The format is multiple choice, but multiple-choice preparation still requires explanation. If you cannot justify an answer without seeing the options, revisit the underlying concept. Options can make recognition feel stronger than it is.
Scheduling and purchase checks
Before scheduling, verify the exam title, legacy status, delivery provider, listed price, exam length, and current appointment instructions on the official Splunk page. Check your account and any employer or training arrangements separately; the supplied sources do not establish that a particular discount, voucher, delivery language, or appointment method applies to you.
Do not infer a prerequisite from recommended learning material. Splunk’s track document states that there is no prerequisite certification or prerequisite course. You may still choose training because it closes a skill gap, but that is a preparation decision rather than a formal eligibility condition.
If the official page and an older study document disagree, note the conflict and seek clarification through Splunk’s current certification information before paying. This is especially important for a legacy exam.
A practical roadmap from baseline to booking
A workable roadmap has five checkpoints: scope, foundation, workflow, automation, and readiness. Move forward when you can demonstrate the checkpoint rather than when a calendar says the week is complete. This flexible approach is especially appropriate when your background is uneven across administration and playbook development.
At the scope checkpoint, annotate the official blueprint. At the foundation checkpoint, explain deployment, installation, initial configuration, user management, apps, assets, and playbooks. At the workflow checkpoint, connect analyst-queue use, investigation-page operations, case management, workbooks, customizations, and system maintenance.
At the automation checkpoint, design and troubleshoot flows involving the named blocks, user interaction, app actions, I2A2 methodology, and action-result structure. At the readiness checkpoint, complete mixed-topic recall under the official time information and review every uncertainty. Only then decide whether to schedule.
Checkpoint one: establish scope
Download the official blueprint, record its 45-question specification and 60-minute total time, and list every covered capability. Mark terms you cannot define. Confirm the certification’s legacy designation and read the official exam page so your preparation target is not based on an outdated title or unofficial description.
Your output should be a one-page scope map, not a pile of links. Include the official source beside each important claim and a separate column for your own study action. This makes it easier to discard material that is interesting but outside the published coverage.
Checkpoint two: build the foundation
Study deployment, installation, initial configuration, user management, apps, assets, and playbooks in a connected sequence. Write a short implementation story: what must be established, what is configured, what can be used by an analyst, and what automation depends on it.
Test yourself without notes. If you can name a feature but cannot explain its role in the overall SOAR setup, the topic is not ready. Return to the official learning-path and training resources rather than filling the gap with an unsupported assumption.
Checkpoint three: rehearse operations
Work through analyst-queue use, investigation-page operations, case management, workbooks, customizations, and system maintenance. For each, describe the operator’s goal, the information being handled, and the point at which an administrative or automation dependency could affect the result.
Mix operational prompts instead of studying them in the same published order every time. The purpose is to practise selecting the relevant concept from a task description, not to remember a fixed sequence of headings.
Checkpoint four: design and debug
Build small playbook diagrams that include an input, an app action, a result, a condition, and an output. Add joins, format blocks, or user interaction only when the design calls for them. Explain the I2A2 design methodology as part of your design reasoning, and connect each step to an automation best practice.
Debug deliberately. Change one assumption at a time, identify the first point where the data or control flow differs from the intended design, and record the verification step. This is more valuable than repeatedly rebuilding a flow without documenting the cause of failure.
Checkpoint five: make the booking decision
Schedule only after you can explain the blueprint topics, complete representative practice in an authorized setting or carefully documented simulation, and manage the official time constraint without sacrificing reasoning. Confirm that the legacy credential remains relevant to your objective and recheck the live official exam page for appointment details.
If readiness is mixed, postpone rather than using the exam attempt as a diagnostic purchase. Focus the next study block on the weakest checkpoint. A candidate who is strong at playbook design but weak at installation and configuration should not spend the final sessions polishing diagrams while ignoring the foundation.
Common preparation mistakes
The most damaging mistakes are scope errors: studying only playbook blocks, treating the former Phantom name as a separate exam, ignoring the legacy notice, and relying on answer memorization. Correct these by returning to the blueprint, separating official facts from personal study methods, and testing whether you can explain a complete SOAR workflow.
Another mistake is confusing familiarity with evidence. Recognizing a block or app name does not show that you understand inputs, outputs, conditions, joins, or debugging. Require yourself to produce an explanation, a diagram, or a troubleshooting path before marking a topic complete.
Do not assume that an official time or price found in an old copy remains current indefinitely. The supplied official sources support the stated figures, but the current exam page should be checked when you schedule.
Mistake: preparing for automation alone
The certification track includes server installation and configuration, Splunk integration, and playbook planning, design, creation, and debugging. A playbook-only plan leaves gaps in deployment, users, apps, assets, analyst workflows, and maintenance. Pair every automation exercise with a question about the configuration or operational context that makes it usable.
Mistake: memorizing labels without data flow
Visual editing, decision and filter blocks, join options, format blocks, user interaction, and action-result structure are easier to retain when you trace data and control flow. Draw what each step receives and returns. If you cannot state what the next step needs, you have memorized terminology rather than learned the design problem.
Mistake: ignoring source freshness
Splunk states that the legacy exam content will no longer be actively maintained or updated to reflect product changes or releases. Do not silently merge newer product documentation into a historical exam target. Check the blueprint and official certification page, flag version-sensitive uncertainty, and seek current official clarification when the distinction affects your booking decision.
How to use official resources efficiently
Start with the exam page for status, format, provider, listed price, and timing. Use the blueprint for scope and question-count information. Use the certification track document for the former name, capability description, and prerequisite statement. Use Splunk’s learning-path and study-guide pages to locate training direction, and use Splunk Lantern for SOAR assistance and help routes.
Do not open every resource without a question. Assign each source a job, record the answer, and link it to a blueprint item. This keeps research focused and reduces the risk of copying navigation text or unrelated product material into your notes.
Source roles at a glance
The official exam page is the scheduling reference: https://www.splunk.com/en_us/training/certification-track/splunk-soar-certified-automation-developer.html. The official blueprint is the content reference: https://www.splunk.com/en_us/pdfs/training/splunk-test-blueprint-soar-automation-developer.pdf. The official track document supplies historical naming, capability context, and the absence of formal prerequisites: https://www.splunk.com/en_us/pdfs/training/splunk-soar-certified-automation-developer-track.pdf.
Splunk’s certification overview can help you compare certification information: https://www.splunk.com/en_us/training/certification.html. The learning-path page is available at https://www.splunk.com/en_us/training/learning-paths-certifications.html, and the study-guide resource is at https://www.splunk.com/en_us/resources/splunk-certification-exam-study-guide.html.
For SOAR assistance, consult Splunk Lantern: https://lantern.splunk.com/Get_Started_with_Splunk_Software/Getting_help_with_SOAR. The Lantern source notes that most customers have OnDemand Services included as part of their license purchase, but those services expire at the end of each quarter. Treat that as a support-planning detail and confirm what applies to your license rather than assuming access.
A research log that prevents confusion
Create three labels in your notes: official exam fact, official product or support information, and personal recommendation. Put the 45-question specification, 60-minute total time, three-minute agreement review, multiple-choice format, Pearson VUE delivery, listed $130 USD price, legacy status, and no-prerequisite statement in the first label only when linked to their supporting official source.
Put decisions such as “study administration before playbook debugging” in the recommendation label. Put environment help, OnDemand Services information, and Lantern guidance in the support or product-information label. This simple separation makes your final review more reliable and prevents advice from being mistaken for an exam rule.
What to do in the final review
The final review should expose unresolved reasoning gaps, not introduce a new collection of facts. Revisit your blueprint checklist, explain one connected workflow aloud or in writing, inspect a playbook design for data-flow errors, and review the logistics on the official exam page before the appointment.
Use the official timing information for one mixed-topic session. Mark questions or prompts that consume disproportionate time, then study the concept behind the delay. Do not sacrifice all review time to a single difficult topic; note it, continue, and return after covering the remaining scope.
Check practical readiness in four directions: administration, analyst operations, automation design, and debugging. If one direction is materially weaker, change the booking decision or study allocation rather than hoping the multiple-choice format will conceal the gap.
A final readiness checklist
You should be able to describe the purpose of deployment, installation, initial configuration, user management, apps, assets, and playbooks. You should also be able to connect analyst-queue use, investigation-page operations, case management, workbooks, customizations, and system maintenance to the work of operating SOAR.
You should be able to explain automation best practices, available app actions, I2A2 design methodology, visual playbook editing, decision and filter blocks, join options, user interaction during execution, format blocks, and action-result structure. The test is whether you can apply each idea to a design or troubleshooting situation, not whether you can recite the list.
Finally, verify the official facts that affect your decision: the certification is legacy, the exam is multiple choice and delivered by Pearson VUE, the official page lists 60 minutes and $130 USD per exam attempt, and the blueprint specifies 45 questions with three minutes of the total time reserved to review the exam agreement. Recheck the official page before scheduling.
Your next action
Download the official blueprint, compare its topics with your current SOAR work, and mark the first three gaps you can address through authorized practice or official learning resources. Then verify the legacy status and current scheduling information before deciding whether this exam remains the right credential for your objective.
If the scope matches your role, follow the roadmap in dependency order and keep a source-linked study log. If it does not, do not force a booking simply because there is no formal prerequisite. A clear decision to pursue a different current certification or build more product experience is more useful than an attempt based on incomplete preparation.
Return to the official Splunk pages for changes, scheduling, and support information. Use this guide to organize decisions; use the official sources to confirm facts.
Conclusion
The exam rewards connected understanding of SOAR administration, analyst operations, and playbook automation. Prepare from the official blueprint, practise explaining and debugging flows, and treat the legacy designation as a scheduling consideration. Once your weakest blueprint areas are addressed and the current official logistics are confirmed, make a deliberate booking decision rather than relying on dumps or unsupported promises.
Related exams
- SPLK-1004 exam — Splunk Core Certified Advanced Power User Exam
- SPLK-1005 exam — Splunk Cloud Certified Admin
- SPLK-4001 exam — Splunk O11y Cloud Certified Metrics User Exam