Winter Special Flat 65% Limited Time Discount offer - Ends in 0d 00h 00m 00s - Coupon code: suredis

Splunk SPLK-1005 Splunk Cloud Certified Admin Exam Practice Test

Demo: 24 questions
Total 80 questions

Splunk Cloud Certified Admin Questions and Answers

Question 1

When monitoring directories that contain mixed file types, which setting should be omitted from inputs, conf and instead be overridden in propo.conf?

Options:

A.

sourcetype

B.

host

C.

source

D.

index

Question 2

How is the forwarder configuration app for Splunk Cloud obtained?

Options:

A.

Use the wget URL presented when an sc_admin user logs in for the first time.

B.

Download from the email sent to the person listed in the SHIP TO: field when the customer licensed Splunk Cloud.

C.

Download from the Splunk Cloud UI under the Universal Forwarder app.

D.

Download from Splunkbase using splunk.com credentials.

Question 3

Which of the following are valid settings for file and directory monitor inputs?

A)

B)

C)

D)

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 4

Which of the following lists all parameters supported by the acceptFrom argument?

Options:

A.

IPv4, IPv6, CIDRs, DNS names, Wildcards

B.

IPv4, IPv6, CIDRs, DNS names

C.

CIDRs, DNS names, Wildcards

D.

IPv4. CIDRs, DNS names. Wildcards

Question 5

The following sample log event shows evidence of credit card numbers being present in the transactions. loc file.

Which of these SEDCM3 settings will mask this and other suspected credit card numbers with an Y character for each character being masked? The indexed event should be formatted as follows:

A)

B)

C)

D)

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 6

In which file can the SH0ULD_LINEMERCE setting be modified?

Options:

A.

transforms.conf

B.

inputs.conf

C.

props.conf

D.

outputs.conf

Question 7

What can be used in a Splunk Cloud environment to create new sourcetypes?

Options:

A.

Data Preview

B.

props. conf can be edited directly from the GUI

C.

Splunk's CLI

D.

Deployment Server

Question 8

When using Splunk Universal Forwarders, which of the following is true?

Options:

A.

No more than six Universal Forwarders may connect directly to Splunk Cloud.

B.

Any number of Universal Forwarders may connect directly to Splunk Cloud.

C.

Universal Forwarders must send data to an Intermediate Forwarder.

D.

There must be one Intermediate Forwarder for every three Universal Forwarders.

Question 9

A monitor has been created in inputs. con: for a directory that contains a mix of file types.

How would a Cloud Admin fine-tune assigned sourcetypes for different files in the directory during the input phase?

Options:

A.

On the Indexer parsing the data, leave sourcetype as automatic for the directory monitor. Then create a props.conf that assigns a specific sourcetype by source stanza.

B.

On the forwarder collecting the data, leave sourcetype as automatic for the directory monitor. Then create a props. conf that assigns a specific sourcetype by source stanza.

C.

On the Indexer parsing the data, set multiple sourcetype_source attributes for the directory monitor collecting the files. Then create a props, com that filters out unwanted files.

D.

On the forwarder collecting the data, set multiple 3ourcotype_sourc« attributes for the directory monitor collecting the files. Then create a props. conf that filters out unwanted files.

Question 10

What is the name of the Splunk index that contains the most valuable information for troubleshooting a Splunk issue?

Options:

A.

_internal

B.

lastchanceindex

C.

_monitoring

D.

defaultdb

Question 11

Which of the following is a valid stanza in props. conf?

Options:

A.

[sourcetype::linux_secure]

B.

[host=nyc25]

C.

[host::nyc*]

D.

[host:nyc*]

Question 12

Configuration folders named default contain configuration files/settings specified in the Splunk product or default settings specified in apps. Which of the following is recommended to override these settings?

Options:

A.

It does not matter whether setting overrides are placed in default or local folders. Both are equally acceptable since Splunk will merge all the files together into one runtime model after each restart.

B.

Any settings to be overridden should be modified in-place wherever the setting was found originally. For example, if overriding a setting originally found in system/default, it should be overridden there to ensure that the desired value is used by Splunk.

C.

Overrides should be placed in a folder named local, ideally within a custom Splunk app. This ensures the overrides are preserved upon product or app upgrade and will also be easier to maintain/support.

D.

Try to store all configuration overrides in system/local folder to keep all configurations in one place. This ensures the modification has the highest precedence over all other configuration entries.

Question 13

What does the followTail attribute do in inputs.conf?

Options:

A.

Pauses a file monitor if the queue is full.

B.

Only creates a tail checkpoint of the monitored file.

C.

Ingests a file starting with new content and then reading older events.

D.

Prevents pre-existing content in a file from being ingested.

Question 14

What syntax is required in inputs.conf to ingest data from files or directories?

Options:

A.

A monitor stanza, sourcetype, and Index is required to ingest data.

B.

A monitor stanza, sourcetype, index, and host is required to ingest data.

C.

A monitor stanza and sourcetype is required to ingest data.

D.

Only the monitor stanza is required to ingest data.

Question 15

When should Splunk Cloud Support be contacted?

Options:

A.

For scripted input troubleshooting.

B.

For all configuration changes.

C.

When unable to resolve issues or perform problem isolation.

D.

For resizing, license changes, or any purchases.

Question 16

When is data deleted from a Splunk Cloud index?

Options:

A.

When buckets roll to frozen, without a defined archive.

B.

When data is deleted via the Splunk Cloud Admin GUI.

C.

When TA_Delete is downloaded and enabled from SplunkBase.

D.

When the daleteindex command is executed from the CLI.

Question 17

Which of the following is true when using Intermediate Forwarders?

Options:

A.

Intermediate Forwarders may be a mix of Universal and Heavy Forwarders.

B.

All Intermediate Forwarders must be Heavy Forwarders.

C.

Intermediate Forwarders may be Universal Forwarders or Heavy Forwarders, but may not be mixed.

D.

All Intermediate Forwarders must be Universal Forwarders.

Question 18

What is the correct syntax to monitor /apache/too/logo, /apache/bor/logs, and /apache/bar/l/logo?

A)

B)

C)

D)

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 19

Which of the following statements is true about data transformations using SEDCMD?

Options:

A.

Can only be used to mask or truncate raw data.

B.

Configured in props.conf and transform.conf.

C.

Can be used to manipulate the sourcetype per event.

D.

Operates on a REGEX pattern match of the source, sourcetype, or host of an event.

Question 20

Which monitor statement will retrieve only files that start with "access" in the directory /opt/log/ww2/?

Options:

A.

[monitor:///opt/lug/.../access]

B.

[monitor:///opt/log/www2/access*]

C.

[monitor:///opt/log/www2/]

D.

[monitor:///opt/log/.../]

Question 21

In which of the following situations should Splunk Support be contacted?

Options:

A.

When a custom search needs tuning due to not performing as expected.

B.

When an app on Splunkbase indicates Request Install.

C.

Before using the delete command.

D.

When a new role that mirrors sc_admin is required.

Question 22

A Splunk Cloud administrator is looking to allow a new group of Splunk users in the marketing department to access the Splunk environment and view a dashboard with relevant data. These users need to access marketing data (stored in the marketing_data index), but shouldn't be able to access other data, such as events related to security or operations.

Which approach would be the best way to accomplish these requirements?

Options:

A.

Create a new user with access to the marketing_data index assigned.

B.

Create a new role that inherits the user role and remove the capability to search indexes other than marketing_data.

C.

Create a new role that inherits the admin rote and assign access to the marketing_dat.a index.

D.

Create a new role that does not inherit from any other role, turn on the same capabilities as the user role, and assign access to the marketing_data index.

Question 23

Which of the following is an accurate statement about the delete command?

Options:

A.

The delete command removes events from disk.

B.

By default, only admins can run the delete command.

C.

Events are virtually deleted by marking them as deleted.

D.

Deleting events reclaims disk space.

Question 24

Files from multiple systems are being stored on a centralized log server. The files are organized into directories based on the original server they came from. Which of the following is a recommended approach for correctly setting the host values based on their origin?

Options:

A.

Use the host segment, setting.

B.

Set host = * in the monitor stanza.

C.

The host value cannot be dynamically set.

D.

Manually create a separate monitor stanza for each host, with the nose = value set.

Demo: 24 questions
Total 80 questions