Splunk IT Service Intelligence Certified Admin — Question 8

Two action blocks, geolocate_ip_1 and file_reputation_2, are connected to a decision block. Which of the following is a correct configuration for making a decision on the action results from one of the given blocks?

Answer options

Correct answer: B

Explanation

Option B is correct because it uses the right parameter and evaluation option to check if the country code from the geolocate_ip_1 action result is within a specified list. Options A and D are incorrect as they refer to response codes instead of country codes. Option C is incorrect because it uses the wrong evaluation operator and does not provide a value to compare against.