Pre-Summer Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: validbest

Pass the Splunk Cloud Certified Admin SPLK-1005 Questions and answers with ValidTests

Exam SPLK-1005 All Questions
Exam SPLK-1005 Premium Access

View all detail and faqs for the SPLK-1005 exam

Viewing page 2 out of 3 pages
Viewing questions 11-20 out of questions
Questions # 11:

What is a private app?

Options:

A.

An app where only a specific role has read and write access.

B.

An app that is only viewable by a specific user.

C.

An app that is created and used only by a specific organization.

D.

An app where only a specific role has read access.

Expert Solution
Questions # 12:

At what point in the indexing pipeline set is SEDCMD applied to data?

Question # 12

Options:

A.

In the aggregator queue

B.

In the parsing queue

C.

In the exec pipeline

D.

In the typing pipeline

Expert Solution
Questions # 13:

Which of the following tasks is the responsibility of a Splunk Cloud administrator?

Options:

A.

Configuring deployer

B.

Configuring cluster master

C.

Configuring indexers

D.

Configuring indexes

Expert Solution
Questions # 14:

Windows Input types are collected in Splunk via a script which is configurable using the GUI. What is this type of input called?

Options:

A.

Batch

B.

Scripted

C.

Modular

D.

Front-end

Expert Solution
Questions # 15:

Where is the recommended place to deploy input apps that are not permitted on Splunk Cloud?

Options:

A.

Universal Forwarder or Heavy Forwarder.

B.

Heavy Forwarder only.

C.

Universal Forwarder only.

D.

Apps cannot be installed on on-prem instances.

Expert Solution
Questions # 16:

What syntax is required in inputs.conf to ingest data from files or directories?

Options:

A.

A monitor stanza, sourcetype, and Index is required to ingest data.

B.

A monitor stanza, sourcetype, index, and host is required to ingest data.

C.

A monitor stanza and sourcetype is required to ingest data.

D.

Only the monitor stanza is required to ingest data.

Expert Solution
Questions # 17:

Which of the following are default Splunk Cloud user roles?

Options:

A.

must_delete, power, sc_admin

B.

power, user, admin

C.

apps, power, sc_admin

D.

can delete, users, admin

Expert Solution
Questions # 18:

For the following data, what would be the correct attribute/value oair to use to successfully extract the correct timestamp from all the events?

Question # 18

Options:

A.

TIMK_FORMAT = %b %d %H:%M:%S %z

B.

DATETIME CONFIG = %Y-%m-%d %H:%M:%S %2

C.

TIME_FORMAT = %b %d %H:%M:%S

D.

DATETIKE CONFIG = Sb %d %H:%M:%S

Expert Solution
Questions # 19:

What information is identified during the input phase of the ingestion process?

Options:

A.

Line breaking and timestamp.

B.

A hash of the message payload.

C.

Metadata fields like sourcetype and host.

D.

SRC and DST IP addresses and ports.

Expert Solution
Questions # 20:

A Splunk Cloud administrator is looking to allow a new group of Splunk users in the marketing department to access the Splunk environment and view a dashboard with relevant data. These users need to access marketing data (stored in the marketing_data index), but shouldn't be able to access other data, such as events related to security or operations.

Which approach would be the best way to accomplish these requirements?

Options:

A.

Create a new user with access to the marketing_data index assigned.

B.

Create a new role that inherits the user role and remove the capability to search indexes other than marketing_data.

C.

Create a new role that inherits the admin rote and assign access to the marketing_dat.a index.

D.

Create a new role that does not inherit from any other role, turn on the same capabilities as the user role, and assign access to the marketing_data index.

Expert Solution
Viewing page 2 out of 3 pages
Viewing questions 11-20 out of questions