Pass the Splunk Splunk Cloud Certified Admin SPLK-1005 Questions and answers with CertsForce

Viewing page 1 out of 3 pages
Viewing questions 1-10 out of questions
Questions # 1:

In which file can the SH0ULD_LINEMERCE setting be modified?

Options:

A.

transforms.conf


B.

inputs.conf


C.

props.conf


D.

outputs.conf


Expert Solution
Questions # 2:

Which of the following is a valid method to test if a forwarder can successfully send data to Splunk Cloud?

Options:

A.

Search the _audit index to confirm whether the forwarder ID was registered.


B.

Use oneshot from the CLI on the forwarders, then check to see if those logs show up in the Splunk Cloud environment.


C.

On Splunk Cloud UI, click Add Data and upload a test file, then search to see if the logs show up.


D.

Ping the inputssl.example.splunkcloud.com to see if it returns the ping.


Expert Solution
Questions # 3:

Which of the following files is used for both search-time and index-time configuration?

Options:

A.

inputs.conf


B.

props.conf


C.

macros.conf


D.

savesearch.conf


Expert Solution
Questions # 4:

The following sample log event shows evidence of credit card numbers being present in the transactions. loc file.

Question # 4

Which of these SEDCM3 settings will mask this and other suspected credit card numbers with an Y character for each character being masked? The indexed event should be formatted as follows:

Question # 4

A)

Question # 4

B)

Question # 4

C)

Question # 4

D)

Question # 4

Options:

A.

Option A


B.

Option B


C.

Option C


D.

Option D


Expert Solution
Questions # 5:

By default, which of the following capabilities are granted to the sc_admin role?

Options:

A.

indexes_edit, edit___token, admin_all_objects, delete_by_keyword


B.

indexes_edit, fsh_manage, acs_conf, list_indexesdiscovert


C.

indexes_edit, fsh_manage, admin_all_objects can_delete


D.

indexes_edit, edit_token_http, admin _all objects, edit limits_conf


Expert Solution
Questions # 6:

Which of the following is not a path used by Splunk to execute scripts?

Options:

A.

SPLUNK_HOME/etc/system/bin


B.

SPLUNK HOME/etc/appa/<app name>/bin


C.

SPLUNKHOMS/ctc/scripts/local


D.

SPLUNK_HOME/bin/scripts


Expert Solution
Questions # 7:

Due to internal security policies, a Splunk Cloud administrator cannot send data directly to Splunk Cloud from certain data sources. Additional parsing and API-based data sources also need to be sent to Splunk Cloud. What forwarder type should the Splunk Cloud administrator use to satisfy these requirements within their environment?

Options:

A.

Syslog-ng server with a universal forwarder


B.

Light forwarder as an intermediate forwarder


C.

Heavy forwarder as an intermediate forwarder


D.

Universal forwarder as an intermediate forwarder


Expert Solution
Questions # 8:

When creating a new index, which of the following is true about archiving expired events?

Options:

A.

Store expired events in private AWS-based storage.


B.

Expired events cannot be archived.


C.

Archive some expired events from an index and discard others.


D.

Store expired events on-prem using your own storage systems.


Expert Solution
Questions # 9:

Which file or folder below is not a required part of a deployment app?

Options:

A.

app.conf (in default or local)


B.

local.meta


C.

metadata folder


D.

props.conf


Expert Solution
Questions # 10:

Which of the following are features of a managed Splunk Cloud environment?

Options:

A.

Availability of premium apps, no IP address whitelisting or blacklisting, deployed in US East AWS region.


B.

20GB daily maximum data ingestion, no SSO integration, no availability of premium apps.


C.

Availability of premium apps, SSO integration, IP address whitelisting and blacklisting.


D.

Availability of premium apps, SSO integration, maximum concurrent search limit of 20.


Expert Solution
Viewing page 1 out of 3 pages
Viewing questions 1-10 out of questions