Halloween Special Limited Time Flat 70% Discount offer - Ends in 0d 00h 00m 00s - Coupon code: 70spcl

Splunk SPLK-1005 Splunk Cloud Certified Admin Exam Practice Test

Page: 1 / 6
Total 60 questions

Splunk Cloud Certified Admin Questions and Answers

Question 1

For the following data, what would be the correct attribute/value oair to use to successfully extract the correct timestamp from all the events?

Question # 1

Options:

A.

TIMK_FORMAT = %b %d %H:%M:%S %z

B.

DATETIME CONFIG= %Y-%m-%d %H:%M:%S %2

C.

TIME_FORMAT = %b %d %H:%M:%S

D.

DATETIKE CONFIG = Sb %d %H:%M:%S

Question 2

Which of the following is correct in regard to configuring a Universal Forwarder as an Intermediate Forwarder?

Options:

A.

This can only be turned on using the Settings > Forwarding and Receiving menu in Splunk Web/UI.

B.

The configuration changes can be made using Splunk Web. CU, directly in configuration files, or via a deployment app.

C.

The configuration changes can be made using CU, directly in configuration files, or via a deployment app.

D.

It is only possible to make this change directly in configuration files or via a deployment app.

Question 3

Which of the following is not considered a best practice for the deployment server?

Options:

A.

Create small, single-purpose deployment apps.

B.

Dedicate a Splunk instance as the deployment server.

C.

Use a Linux server as the deployment server.

D.

Create large, multi-purpose deployment apps.

Question 4

Which of the following is not a path used by Splunk to execute scripts?

Options:

A.

SPLUNK_HOME/etc/system/bin

B.

SPLUNK HOME/etc/appa//bin

C.

SPLUNKHOMS/ctc/scripts/local

D.

SPLUNK_HOME/bin/scripts

Question 5

Which of the following is an accurate statement about the delete command?

Options:

A.

The delete command removes events from disk.

B.

By default, only admins can run the delete command.

C.

Events are virtually deleted by marking them as deleted.

D.

Deleting events reclaims disk space.

Question 6

Windows Input types are collected in Splunk via a script which is configurable using the GUI. What is this type of input called?

Options:

A.

Batch

B.

Scripted

C.

Modular

D.

Front-end

Question 7

Which of the following is a valid stanza in props. conf?

Options:

A.

[sourcetype::linux_secure]

B.

[host=nyc25]

C.

[host::nyc*]

D.

[host:nyc*]

Question 8

Which of the following stanzas would enable a TCP input on port 1025, allowing traffic from all IP addresses except 10.5.5.1?

A)

Question # 8

B)

Question # 8

C)

Question # 8

D)

Question # 8

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 9

When monitoring network inputs, there will be times when the forwarder is unable to send data to the indexers. Splunk uses a memory queue and a disk queue. Which setting is used for the disk queue?

Options:

A.

queueSize

B.

maxQeueSize

C.

diskQiioiioiiizo

D.

persistentQueueSize

Question 10

When a forwarder phones home to a Deployment Server it compares the check-sum value of the forwarder's app to the Deployment Server's app. What happens to the app If the check-sum values do not match?

Options:

A.

The app on the forwarder is always deleted and re-downloaded from the Deployment Server.

B.

The app on the forwarder is only deleted and re-downloaded from the Deployment Server if the forwarder's app has a smaller check-sum value.

C.

The app is downloaded from the Deployment Server and the changes are merged.

D.

A warning is generated on the Deployment Server stating the apps are out of sync. An Admin will need to confirm which version of the app should be used.

Question 11

Which of the following are valid settings for file and directory monitor inputs?

A)

Question # 11

B)

Question # 11

C)

Question # 11

D)

Question # 11

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 12

Where is the recommended place to deploy input apps that are not permitted on Splunk Cloud?

Options:

A.

Universal Forwarder or Heavy Forwarder.

B.

Heavy Forwarder only.

C.

Universal Forwarder only.

D.

Apps cannot be installed on on-prem instances.

Question 13

In what scenarios would transforms.conf be used?

Options:

A.

Per-Event Index Routing, Applying Event Types, SEOCMD operations

B.

Per-Event Sourcetype, Per-Event Host Name, Per-Event Index Routing

C.

Per-Event Host Name, Per-Event Index Rooting, SEDCMD operations

D.

Per-Event Sourcetype, Per-Event Index Routing, Applying Event Types

Question 14

What syntax is required in inputs.conf to ingest data from files or directories?

Options:

A.

A monitor stanza, sourcetype, and Index is required to ingest data.

B.

A monitor stanza, sourcetype, index, and hostis required to ingest data.

C.

A monitor stanza and sourcetype is required to ingest data.

D.

Only the monitor stanza is required to ingest data.

Question 15

Which statement is true about monitor inputs?

Options:

A.

Monitor inputs are configured in the monitor, conf file.

B.

The ignoreOlderThan option allows files to be ignored based on the file modification time.

C.

ThecrSaltsetting is required.

D.

Monitor inputs can ignore a file's existing content, indexing new data as it arrives, by configuring the tailProcessor option.

Question 16

Which of the following tasks is the responsibility of a Splunk Cloud administrator?

Options:

A.

Configuring deployer

B.

Configuring cluster master

C.

Configuring indexers

D.

Configuring indexes

Question 17

Li was asked to create a Splunk configuration to monitor syslog files stored on Linux servers at their organization. This configuration will be pushed out to multiple systems via a Splunk app using the on-prem deployment server.

The system administrators have provided Li with a directory listing for the logging locations on three syslog hosts, which are representative of the file structure for all systems collecting this data. An example from each system is shown below:

Question # 17

A)

Question # 17

B)

Question # 17

C)

Question # 17

D)

Question # 17

Options:

A.

OptionA

B.

OptionB

C.

OptionC

D.

OptionD

Question 18

In which of the following situations should Splunk Support be contacted?

Options:

A.

When a custom search needs tuning due to not performing as expected.

B.

When an app on Splunkbase indicates Request Install.

C.

Before using the delete command.

D.

When a new role that mirrors sc_admin is required.

Page: 1 / 6
Total 60 questions