ExamGecko
Home / Splunk / SPLK-2003 / List of questions
Ask Question

Splunk SPLK-2003 Practice Test - Questions Answers, Page 6

Add to Whishlist

List of questions

Question 51

Report Export Collapse

A user wants to use their Splunk Cloud instance as the external Splunk instance for Phantom. What ports need to be opened on the Splunk Cloud instance to facilitate this? Assume default ports are in use.

TCP 8088 and TCP 8099.
TCP 8088 and TCP 8099.
TCP 80 and TCP 443.
TCP 80 and TCP 443.
Splunk Cloud is not supported.
Splunk Cloud is not supported.
TCP 8080 and TCP 8191.
TCP 8080 and TCP 8191.
Suggested answer: B
Explanation:

To integrate Splunk Phantom with a Splunk Cloud instance, network communication overcertain ports is necessary. The default ports for web traffic are TCP 80 for HTTP and TCP 443 forHTTPS. Since Splunk Cloud instances are accessed over the internet, ensuring that these portsare open is essential for Phantom to communicate with Splunk Cloud for various operations,such as running searches, sending data, and receiving results. It is important to note that TCP8088 is typically used by Splunk's HTTP Event Collector (HEC), which may also be relevantdepending on the integration specifics.

asked 23/09/2024
Corey Workman
45 questions

Question 52

Report Export Collapse

Which app allows a user to run Splunk queries from within Phantom?

Splunk App for Phantom?
Splunk App for Phantom?
The Integrated Splunk/Phantom app.
The Integrated Splunk/Phantom app.
Phantom App for Splunk.
Phantom App for Splunk.
Splunk App for Phantom Reporting.
Splunk App for Phantom Reporting.
Suggested answer: A
asked 23/09/2024
Aparna Roy
49 questions

Question 53

Report Export Collapse

Which Phantom VPE Nock S used to add information to custom lists?

Action blocks
Action blocks
Filter blocks
Filter blocks
API blocks
API blocks
Decision blocks
Decision blocks
Suggested answer: C
asked 23/09/2024
ABDOUL RAZAK TIENDREBEOGO
30 questions

Question 54

Report Export Collapse

How is it possible to evaluate user prompt results?

Set action_result.summary. status to required.
Set action_result.summary. status to required.
Set the user prompt to reinvoke if it times out.
Set the user prompt to reinvoke if it times out.
Set action_result. summary. response to required.
Set action_result. summary. response to required.
Add a decision Mode
Add a decision Mode
Suggested answer: C
Explanation:

In Splunk Phantom, user prompts are actions that require human input. To evaluate the resultsof a user prompt, you can set the response requirement in the action result summary. Bysetting action_result.summary.response to required, the playbook ensures that it captures theuser's input and can act upon it. This is critical in scenarios where subsequent actions dependon the choices made by the user in response to a prompt. Without setting this, the playbookwould not have a defined way to handle the user response, which might lead to incorrect orunexpected playbook behavior.

asked 23/09/2024
Venkatesh Ampolu
47 questions

Question 55

Report Export Collapse

When is using decision blocks most useful?

When selecting one (or zero) possible paths in the playbook.
When selecting one (or zero) possible paths in the playbook.
When processing different data in parallel.
When processing different data in parallel.
When evaluating complex, multi-value results or artifacts.
When evaluating complex, multi-value results or artifacts.
When modifying downstream data hi one or more paths in the playbook.
When modifying downstream data hi one or more paths in the playbook.
Suggested answer: A
asked 23/09/2024
Emmanuel Esquivel Guzman
37 questions

Question 56

Report Export Collapse

Which of the following accurately describes the Files tab on the Investigate page?

A user can upload the output from a detonate action to the the files tab for further investigation.
A user can upload the output from a detonate action to the the files tab for further investigation.
Files tab items and artifacts are the only data sources that can populate active cases.
Files tab items and artifacts are the only data sources that can populate active cases.
Files tab items cannot be added to investigations. Instead, add them to action blocks.
Files tab items cannot be added to investigations. Instead, add them to action blocks.
Phantom memory requirements remain static, regardless of Files tab usage.
Phantom memory requirements remain static, regardless of Files tab usage.
Suggested answer: A
Explanation:

The Files tab on the Investigate page allows the user to upload, download, and view filesrelated to an investigation. A user can upload the output from a detonate action to the Files tabfor further investigation, such as analyzing the file metadata, content, or hash. Files tab itemsand artifacts are not the only data sources that can populate active cases, as cases can alsoinclude events, tasks, notes, and comments. Files tab items can be added to investigations byusing the add file action block or the Add File button on the Files tab. Phantom memoryrequirements may increase depending on the Files tab usage, as files are stored in the Phantomdatabase.The Files tab on the Investigate page in Splunk Phantom is an area where users can manage andanalyze files related to an investigation. Users can upload files, such as outputs from a'detonate file' action which analyzes potentially malicious files in a sandbox environment. Thefiles tab allows users to store and further investigate these outputs, which can include reports,logs, or any other file types that have been generated or are relevant to the investigation. TheFiles tab is an integral part of the investigation process, providing easy access to file data foranalysis and correlation with other incident data.

asked 23/09/2024
Aurelie Touraille Colombo
33 questions

Question 57

Report Export Collapse

What are the differences between cases and events?

Become a Premium Member for full access
  Unlock Premium Member

Question 58

Report Export Collapse

Which Phantom API command is used to create a custom list?

Become a Premium Member for full access
  Unlock Premium Member

Question 59

Report Export Collapse

Why is it good playbook design to create smaller and more focused playbooks? (select all that apply)

Become a Premium Member for full access
  Unlock Premium Member

Question 60

Report Export Collapse

What is the default log level for system health debug logs?

Become a Premium Member for full access
  Unlock Premium Member
Total 96 questions
Go to page: of 10