Pass the Splunk Splunk Enterprise Certified Admin SPLK-1003 Questions and answers with CertsForce

Viewing page 5 out of 6 pages
Viewing questions 41-50 out of questions
Questions # 41:

Which of the following indexes come pre-configured with Splunk Enterprise? (select all that apply)

Options:

A.

_license


B.

_lnternal


C.

_external


D.

_thefishbucket


Expert Solution
Questions # 42:

In case of a conflict between a whitelist and a blacklist input setting, which one is used?

Options:

A.

Blacklist


B.

Whitelist


C.

They cancel each other out.


D.

Whichever is entered into the configuration first.


Expert Solution
Questions # 43:

When running a real-time search, search results are pulled from which Splunk component?

Options:

A.

Heavy forwarders and search peers


B.

Heavy forwarders


C.

Search heads


D.

Search peers


Expert Solution
Questions # 44:

What is the difference between the two wildcards ... and - for the monitor stanza in inputs, conf?

Options:

A.

... is not supported in monitor stanzas


B.

There is no difference, they are interchangable and match anything beyond directory boundaries.


C.

* matches anything in that specific directory path segment, whereas ... recurses through subdirectories as well.


D.

... matches anything in that specific directory path segment, whereas - recurses through subdirectories as well.


Expert Solution
Questions # 45:

Which of the following is valid distribute search group?

A)

B)

Question # 45

C)

Question # 45

D)

Question # 45

Options:

A.

option A


B.

Option B


C.

Option C


D.

Option D


Expert Solution
Questions # 46:

When does a warm bucket roll over to a cold bucket?

Options:

A.

When Splunk is restarted.


B.

When the maximum warm bucket age has been reached.


C.

When the maximum warm bucket size has been reached.


D.

When the maximum number of warm buckets is reached.


Expert Solution
Questions # 47:

Which parent directory contains the configuration files in Splunk?

Options:

A.

SSFLUNK_HOME/etc


B.

SSPLUNK_HOME/var


C.

SSPLUNK_HOME/conf


D.

SSPLUNK_HOME/default


Expert Solution
Questions # 48:

Which of the following authentication types requires scripting in Splunk?

Options:

A.

ADFS


B.

LDAP


C.

SAML


D.

RADIUS


Expert Solution
Questions # 49:

How is a remote monitor input distributed to forwarders?

Options:

A.

As an app.


B.

As a forward.conf file.


C.

As a monitor.conf file.


D.

As a forwarder monitor profile.


Expert Solution
Questions # 50:

Where are deployment server apps mapped to clients?

Options:

A.

Apps tab in forwarder management interface or clientapps.conf.


B.

Clients tab in forwarder management interface or deploymentclient.conf.


C.

Server Classes tab in forwarder management interface or serverclass.conf.


D.

Client Applications tab in forwarder management interface or clientapps.conf.


Expert Solution
Viewing page 5 out of 6 pages
Viewing questions 41-50 out of questions