Black Friday Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: cramtick70

SPLK-1005 Splunk Cloud Certified Admin Questions and Answers

Questions 4

Which of the following would always require raising a support ticket?

Options:

A.

Capacity or configuration changes in Splunk Cloud.

B.

Search does not return expected results in Splunk Cloud.

C.

A user is unable to log into Splunk Cloud.

D.

Data is not indexed in Splunk Cloud.

Buy Now
Questions 5

In Splunk terminology, what is an index?

Options:

A.

A data repository that contains raw, compressed data along with psidx files.

B.

A data repository that contains raw, compressed data along with tsidx files.

C.

A data repository that contains raw, uncompressed data along with psidx files.

D.

A data repository that contains raw, uncompressed data along with tsidx files.

Buy Now
Questions 6

How is it possible to test a script from the Splunk perspective before using it within a scripted input?

Options:

A.

splunk run

B.

splunk script

C.

./$SPLUNK_HOME/etc/apps//bin/

D.

splunk cmd

Buy Now
Questions 7

What is the correct syntax to monitor /apache/too/logo, /apache/bor/logs, and /apache/bar/l/logo?

A)

B)

C)

D)

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 8

When should Splunk Cloud Support be contacted?

Options:

A.

For scripted input troubleshooting.

B.

For all configuration changes.

C.

When unable to resolve issues or perform problem isolation.

D.

For resizing, license changes, or any purchases.

Buy Now
Questions 9

Where is the recommended place to deploy input apps that are not permitted on Splunk Cloud?

Options:

A.

Universal Forwarder or Heavy Forwarder.

B.

Heavy Forwarder only.

C.

Universal Forwarder only.

D.

Apps cannot be installed on on-prem instances.

Buy Now
Questions 10

At what point in the indexing pipeline set is SEDCMD applied to data?

Options:

A.

In the aggregator queue

B.

In the parsing queue

C.

In the exec pipeline

D.

In the typing pipeline

Buy Now
Questions 11

Which of the following statements is true regarding sedcmd?

Options:

A.

SEDCMD can be defined in either props.conf or transforms.conf.

B.

SEDCMD does not work on Windows-based installations of Splunk.

C.

SEDCMD uses the same syntax as Splunk's replace command.

D.

SEDCMD provides search and replace functionality using regular expressions and substitutions.

Buy Now
Questions 12

When a forwarder phones home to a Deployment Server it compares the check-sum value of the forwarder's app to the Deployment Server's app. What happens to the app If the check-sum values do not match?

Options:

A.

The app on the forwarder is always deleted and re-downloaded from the Deployment Server.

B.

The app on the forwarder is only deleted and re-downloaded from the Deployment Server if the forwarder's app has a smaller check-sum value.

C.

The app is downloaded from the Deployment Server and the changes are merged.

D.

A warning is generated on the Deployment Server stating the apps are out of sync. An Admin will need to confirm which version of the app should be used.

Buy Now
Questions 13

Which of the following is true when integrating LDAP authentication?

Options:

A.

Splunk stores LDAP end user names and passwords on search heads.

B.

The mapping of LDAP groups to Splunk roles happens automatically.

C.

Splunk Cloud only supports Active Directory LDAP servers.

D.

New user data is cached the first time a user logs in.

Buy Now
Questions 14

When monitoring network inputs, there will be times when the forwarder is unable to send data to the indexers. Splunk uses a memory queue and a disk queue. Which setting is used for the disk queue?

Options:

A.

queueSize

B.

maxQeueSize

C.

diskQiioiioiiizo

D.

persistentQueueSize

Buy Now
Questions 15

By default, which of the following capabilities are granted to the sc_admin role?

Options:

A.

indexes_edit, edit___token, admin_all_objects, delete_by_keyword

B.

indexes_edit, fsh_manage, acs_conf, list_indexesdiscovert

C.

indexes_edit, fsh_manage, admin_all_objects can_delete

D.

indexes_edit, edit_token_http, admin _all objects, edit limits_conf

Buy Now
Questions 16

Which of the following statements regarding apps in Splunk Cloud is true?

Options:

A.

Self-service install of premium apps is possible.

B.

Only Cloud certified and vetted apps are supported.

C.

Any app that can be deployed in an on-prem Splunk Enterprise environment is also supported on Splunk Cloud.

D.

Self-service install is available for all apps on Splunkbase.

Buy Now
Questions 17

Where can an administrator download the Splunk Cloud Universal Forwarder credentials package?

Options:

A.

Splunk Support.

B.

Cloud Monitoring Console forwarder drop-down.

C.

Universal Forwarder app in the Splunk Cloud search head.

D.

Splunkbase.

Buy Now
Questions 18

Which of the following is the default bandwidth limit in the Splunk Universal Forwarder credentials package?

Options:

A.

0KBps

B.

256 KBps

C.

512 KBps

D.

1024 KBps

Buy Now
Questions 19

In which of the following situations should Splunk Support be contacted?

Options:

A.

When a custom search needs tuning due to not performing as expected.

B.

When an app on Splunkbase indicates Request Install.

C.

Before using the delete command.

D.

When a new role that mirrors sc_admin is required.

Buy Now
Questions 20

What Splunk command will allow an administrator to view the runtime configuration instructions for a monitored file in Inputs. cont on the forwarders?

Options:

A.

./splunk _internal call /services/data/input.3/filemonitor

B.

./splunk show config inputs.conf

C.

./splunk _internal rest /services/data/inputs/monitor

D.

./splunk show config inputs

Buy Now
Questions 21

Which of the following are default Splunk Cloud user roles?

Options:

A.

must_delete, power, sc_admin

B.

power, user, admin

C.

apps, power, sc_admin

D.

can delete, users, admin

Buy Now
Questions 22

The following Apache access log is being ingested into Splunk via a monitor input:

How does Splunk determine the time zone for this event?

Options:

A.

The value of the TZ attribute in props. cont for the a :ces3_ccwbined sourcetype.

B.

The value of the TZ attribute in props, conf for the my.webserver.example host.

C.

The time zone of the Heavy/Intermediate Forwarder with the monitor input.

D.

The time zone indicator in the raw event data.

Buy Now
Questions 23

Which of the following lists all parameters supported by the acceptFrom argument?

Options:

A.

IPv4, IPv6, CIDRs, DNS names, Wildcards

B.

IPv4, IPv6, CIDRs, DNS names

C.

CIDRs, DNS names, Wildcards

D.

IPv4. CIDRs, DNS names. Wildcards

Buy Now
Questions 24

In which file can the SH0ULD_LINEMERCE setting be modified?

Options:

A.

transforms.conf

B.

inputs.conf

C.

props.conf

D.

outputs.conf

Buy Now
Exam Code: SPLK-1005
Exam Name: Splunk Cloud Certified Admin
Last Update: Nov 24, 2024
Questions: 80
SPLK-1005 pdf

SPLK-1005 PDF

$25.5  $84.99
SPLK-1005 Engine

SPLK-1005 Testing Engine

$30  $99.99
SPLK-1005 PDF + Engine

SPLK-1005 PDF + Testing Engine

$40.5  $134.99