Weekend Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code = simple70

Pass the Splunk Cloud Certified Admin SPLK-1005 Questions and answers with ExamsMirror

Practice at least 50% of the questions to maximize your chances of passing.
Exam SPLK-1005 Premium Access

View all detail and faqs for the SPLK-1005 exam


512 Students Passed

93% Average Score

93% Same Questions
Viewing page 1 out of 3 pages
Viewing questions 1-10 out of questions
Questions # 1:

What can be used in a Splunk Cloud environment to create new sourcetypes?

Options:

A.

Data Preview

B.

props. conf can be edited directly from the GUI

C.

Splunk's CLI

D.

Deployment Server

Questions # 2:

Which of the following is not a path used by Splunk to execute scripts?

Options:

A.

SPLUNK_HOME/etc/system/bin

B.

SPLUNK HOME/etc/appa/<app name>/bin

C.

SPLUNKHOMS/ctc/scripts/local

D.

SPLUNK_HOME/bin/scripts

Questions # 3:

Which of the following statements regarding apps in Splunk Cloud is true?

Options:

A.

Self-service install of premium apps is possible.

B.

Only Cloud certified and vetted apps are supported.

C.

Any app that can be deployed in an on-prem Splunk Enterprise environment is also supported on Splunk Cloud.

D.

Self-service install is available for all apps on Splunkbase.

Questions # 4:

When adding a directory monitor and specifying a sourcetype explicitly, it applies to all files in the directory and subdirectories. If automatic sourcetyping is used, a user can selectively override it in which file on the forwarder?

Options:

A.

transforms.conf

B.

props.conf

C.

inputs.conf

D.

outputs.cont

Questions # 5:

A Splunk Cloud administrator is looking to allow a new group of Splunk users in the marketing department to access the Splunk environment and view a dashboard with relevant data. These users need to access marketing data (stored in the marketing_data index), but shouldn't be able to access other data, such as events related to security or operations.

Which approach would be the best way to accomplish these requirements?

Options:

A.

Create a new user with access to the marketing_data index assigned.

B.

Create a new role that inherits the user role and remove the capability to search indexes other than marketing_data.

C.

Create a new role that inherits the admin rote and assign access to the marketing_dat.a index.

D.

Create a new role that does not inherit from any other role, turn on the same capabilities as the user role, and assign access to the marketing_data index.

Questions # 6:

Which of the following is correct in regard to configuring a Universal Forwarder as an Intermediate Forwarder?

Options:

A.

This can only be turned on using the Settings > Forwarding and Receiving menu in Splunk Web/UI.

B.

The configuration changes can be made using Splunk Web. CU, directly in configuration files, or via a deployment app.

C.

The configuration changes can be made using CU, directly in configuration files, or via a deployment app.

D.

It is only possible to make this change directly in configuration files or via a deployment app.

Questions # 7:

How are HTTP Event Collector (HEC) tokens configured in a managed Splunk Cloud environment?

Options:

A.

Any token will be accepted by HEC, the data may just end up in the wrong index.

B.

A token is generated when configuring a HEC input, which should be provided to the application developers.

C.

Obtain a token from the organization's application developers and apply it in Settings > Data Inputs > HTTP Event Collector > New Token.

D.

Open a support case for each new data input and a token will be provided.

Questions # 8:

Which of the following are default Splunk Cloud user roles?

Options:

A.

must_delete, power, sc_admin

B.

power, user, admin

C.

apps, power, sc_admin

D.

can delete, users, admin

Questions # 9:

In which file can the SH0ULD_LINEMERCE setting be modified?

Options:

A.

transforms.conf

B.

inputs.conf

C.

props.conf

D.

outputs.conf

Questions # 10:

Due to internal security policies, a Splunk Cloud administrator cannot send data directly to Splunk Cloud from certain data sources. Additional parsing and API-based data sources also need to be sent to Splunk Cloud. What forwarder type should the Splunk Cloud administrator use to satisfy these requirements within their environment?

Options:

A.

Syslog-ng server with a universal forwarder

B.

Light forwarder as an intermediate forwarder

C.

Heavy forwarder as an intermediate forwarder

D.

Universal forwarder as an intermediate forwarder

Viewing page 1 out of 3 pages
Viewing questions 1-10 out of questions
TOP CODES

TOP CODES

Top selling exam codes in the certification world, popular, in demand and updated to help you pass on the first try.