Splunk SPLK-2003 Practice Test - Questions Answers, Page 6
List of questions
A user wants to use their Splunk Cloud instance as the external Splunk instance for Phantom. What ports need to be opened on the Splunk Cloud instance to facilitate this? Assume default ports are in use.
Which app allows a user to run Splunk queries from within Phantom?
Which Phantom VPE Nock S used to add information to custom lists?
How is it possible to evaluate user prompt results?
When is using decision blocks most useful?
Which of the following accurately describes the Files tab on the Investigate page?
What are the differences between cases and events?
Which Phantom API command is used to create a custom list?
Why is it good playbook design to create smaller and more focused playbooks? (select all that apply)
Reduces amount of playbook data stored in each repo.
Reduce large complex playbooks which become difficult to maintain.
Encourages code reuse in a more compartmentalized form.
To avoid duplication of code across multiple playbooks.
What is the default log level for system health debug logs?
INFO
WARN
ERROR
DEBUG
Question