Winter Special Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: dumps65

Splunk SPLK-1005 Dumps

Page: 1 / 8
Total 80 questions

Splunk Cloud Certified Admin Questions and Answers

Question 1

For the following data, what would be the correct attribute/value oair to use to successfully extract the correct timestamp from all the events?

as

Options:

A.

TIMK_FORMAT = %b %d %H:%M:%S %z

B.

DATETIME CONFIG = %Y-%m-%d %H:%M:%S %2

C.

TIME_FORMAT = %b %d %H:%M:%S

D.

DATETIKE CONFIG = Sb %d %H:%M:%S

Question 2

When creating a new index, which of the following is true about archiving expired events?

Options:

A.

Store expired events in private AWS-based storage.

B.

Expired events cannot be archived.

C.

Archive some expired events from an index and discard others.

D.

Store expired events on-prem using your own storage systems.

Question 3

Where is the recommended place to deploy input apps that are not permitted on Splunk Cloud?

Options:

A.

Universal Forwarder or Heavy Forwarder.

B.

Heavy Forwarder only.

C.

Universal Forwarder only.

D.

Apps cannot be installed on on-prem instances.

Question 4

What Splunk command will allow an administrator to view the runtime configuration instructions for a monitored file in Inputs. cont on the forwarders?

Options:

A.

./splunk _internal call /services/data/input.3/filemonitor

B.

./splunk show config inputs.conf

C.

./splunk _internal rest /services/data/inputs/monitor

D.

./splunk show config inputs

Question 5

When a forwarder phones home to a Deployment Server it compares the check-sum value of the forwarder's app to the Deployment Server's app. What happens to the app If the check-sum values do not match?

Options:

A.

The app on the forwarder is always deleted and re-downloaded from the Deployment Server.

B.

The app on the forwarder is only deleted and re-downloaded from the Deployment Server if the forwarder's app has a smaller check-sum value.

C.

The app is downloaded from the Deployment Server and the changes are merged.

D.

A warning is generated on the Deployment Server stating the apps are out of sync. An Admin will need to confirm which version of the app should be used.

Question 6

In which of the following situations should Splunk Support be contacted?

Options:

A.

When a custom search needs tuning due to not performing as expected.

B.

When an app on Splunkbase indicates Request Install.

C.

Before using the delete command.

D.

When a new role that mirrors sc_admin is required.

Question 7

Which of the following is a valid stanza in props. conf?

Options:

A.

[sourcetype::linux_secure]

B.

[host=nyc25]

C.

[host::nyc*]

D.

[host:nyc*]

Question 8

Which of the following are valid settings for file and directory monitor inputs?

A)

as

B)

as

C)

as

D)

as

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 9

Which of the following tasks is the responsibility of a Splunk Cloud administrator?

Options:

A.

Configuring deployer

B.

Configuring cluster master

C.

Configuring indexers

D.

Configuring indexes

Question 10

A customer wants to mask unstructured data before sending it to Splunk Cloud. Where should SEBCMD be configured for this?

Options:

A.

props. conf on a Splunk Cloud search head,

B.

props.conf on a Heavy Forwarder.

C.

transforms, cent on a Splunk Cloud indexer.

D.

props. conf- on a Universal Forwarder.

Question 11

In what scenarios would transforms.conf be used?

Options:

A.

Per-Event Index Routing, Applying Event Types, SEOCMD operations

B.

Per-Event Sourcetype, Per-Event Host Name, Per-Event Index Routing

C.

Per-Event Host Name, Per-Event Index Rooting, SEDCMD operations

D.

Per-Event Sourcetype, Per-Event Index Routing, Applying Event Types

Question 12

Which of the following is not a path used by Splunk to execute scripts?

Options:

A.

SPLUNK_HOME/etc/system/bin

B.

SPLUNK HOME/etc/appa//bin

C.

SPLUNKHOMS/ctc/scripts/local

D.

SPLUNK_HOME/bin/scripts

Question 13

Which of the following is true when using Intermediate Forwarders?

Options:

A.

Intermediate Forwarders may be a mix of Universal and Heavy Forwarders.

B.

All Intermediate Forwarders must be Heavy Forwarders.

C.

Intermediate Forwarders may be Universal Forwarders or Heavy Forwarders, but may not be mixed.

D.

All Intermediate Forwarders must be Universal Forwarders.

Question 14

When is data deleted from a Splunk Cloud index?

Options:

A.

When buckets roll to frozen, without a defined archive.

B.

When data is deleted via the Splunk Cloud Admin GUI.

C.

When TA_Delete is downloaded and enabled from SplunkBase.

D.

When the daleteindex command is executed from the CLI.

Question 15

What is the recommended method to test the onboarding of a new data source before putting it in production?

Options:

A.

Send test data to a test index.

B.

Send data to the associated production index.

C.

Replicate Splunk deployment in a test environment.

D.

Send data to the chance index.

Question 16

What is the correct syntax to monitor /apache/too/logo, /apache/bor/logs, and /apache/bar/l/logo?

A)

as

B)

as

C)

as

D)

as

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 17

Which of the following is true when integrating LDAP authentication?

Options:

A.

Splunk stores LDAP end user names and passwords on search heads.

B.

The mapping of LDAP groups to Splunk roles happens automatically.

C.

Splunk Cloud only supports Active Directory LDAP servers.

D.

New user data is cached the first time a user logs in.

Question 18

Given the following set of files, which of the monitor stanzas below will result in Splunk monitoring all of the files ending with .log?

Files:

    /var/log/www1/secure.log

    /var/log/www1/access.log

    /var/log/www2/logs/secure.log

    /var/log/www2/access.log

    /var/log/www2/access.log.1

Options:

A.

[monitor:///var/log/*/*.log]

B.

[monitor:///var/log/.../*.log]

C.

[monitor:///var/log/*/*]

D.

[monitor:///var/log/.../*]

Question 19

Which of the following is not considered a best practice for the deployment server?

Options:

A.

Create small, single-purpose deployment apps.

B.

Dedicate a Splunk instance as the deployment server.

C.

Use a Linux server as the deployment server.

D.

Create large, multi-purpose deployment apps.

Question 20

Files from multiple systems are being stored on a centralized log server. The files are organized into directories based on the original server they came from. Which of the following is a recommended approach for correctly setting the host values based on their origin?

Options:

A.

Use the host segment, setting.

B.

Set host = * in the monitor stanza.

C.

The host value cannot be dynamically set.

D.

Manually create a separate monitor stanza for each host, with the nose = value set.

Question 21

Which of the following is an accurate statement about the delete command?

Options:

A.

The delete command removes events from disk.

B.

By default, only admins can run the delete command.

C.

Events are virtually deleted by marking them as deleted.

D.

Deleting events reclaims disk space.

Question 22

A Splunk Cloud administrator is looking to allow a new group of Splunk users in the marketing department to access the Splunk environment and view a dashboard with relevant data. These users need to access marketing data (stored in the marketing_data index), but shouldn't be able to access other data, such as events related to security or operations.

Which approach would be the best way to accomplish these requirements?

Options:

A.

Create a new user with access to the marketing_data index assigned.

B.

Create a new role that inherits the user role and remove the capability to search indexes other than marketing_data.

C.

Create a new role that inherits the admin rote and assign access to the marketing_dat.a index.

D.

Create a new role that does not inherit from any other role, turn on the same capabilities as the user role, and assign access to the marketing_data index.

Question 23

When should Splunk Cloud Support be contacted?

Options:

A.

For scripted input troubleshooting.

B.

For all configuration changes.

C.

When unable to resolve issues or perform problem isolation.

D.

For resizing, license changes, or any purchases.

Question 24

What is the name of the Splunk index that contains the most valuable information for troubleshooting a Splunk issue?

Options:

A.

_internal

B.

lastchanceindex

C.

_monitoring

D.

defaultdb

Page: 1 / 8
Total 80 questions