Labour Day Special 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: exams65

Splunk Enterprise Certified Admin Exam Question and Answers

Splunk Enterprise Certified Admin Exam

Last Update May 2, 2024
Total Questions : 174

We are offering FREE SPLK-1003 Splunk exam questions. All you do is to just go and sign up. Give your details, prepare SPLK-1003 free exam questions and then go for complete pool of Splunk Enterprise Certified Admin Exam test questions that will help you more.

SPLK-1003 pdf

SPLK-1003 PDF

$35  $99.99
SPLK-1003 Engine

SPLK-1003 Testing Engine

$42  $119.99
SPLK-1003 PDF + Engine

SPLK-1003 PDF + Testing Engine

$56  $159.99
Questions 1

What is the name of the object that stores events inside of an index?

Options:

A.  

Container

B.  

Bucket

C.  

Data layer

D.  

Indexer

Discussion 0
Questions 2

Which option accurately describes the purpose of the HTTP Event Collector (HEC)?

Options:

A.  

A token-based HTTP input that is secure and scalable and that requires the use of forwarders

B.  

A token-based HTTP input that is secure and scalable and that does not require the use of forwarders.

C.  

An agent-based HTTP input that is secure and scalable and that does not require the use of forwarders.

D.  

A token-based HTTP input that is insecure and non-scalable and that does not require the use of forwarders.

Discussion 0
Questions 3

Windows can prevent a Splunk forwarder from reading open files. If files need to be read while they are being written to, what type of input stanza needs to be created?

Options:

A.  

Tail Reader

B.  

Upload

C.  

MonitorNoHandIe

D.  

Monitor

Discussion 0
Questions 4

Which is a valid stanza for a network input?

Options:

A.  

[udp://172.16.10.1:9997]

connection = dns

sourcetype = dns

B.  

[any://172.16.10.1:10001]

connection_host = ip

sourcetype = web

C.  

[tcp://172.16.10.1:9997]

connection_host = web

sourcetype = web

D.  

[tcp://172.16.10.1:10001]

connection_host = dns

sourcetype = dns

Discussion 0
Questions 5

When configuring monitor inputs with whitelists or blacklists, what is the supported method of filtering the lists?

Options:

A.  

Slash notation

B.  

Regular expression

C.  

Irregular expression

D.  

Wildcard-only expression

Discussion 0
Questions 6

Which of the following is the use case for the deployment server feature of Splunk?

Options:

A.  

Managing distributed workloads in a Splunk environment.

B.  

Automating upgrades of Splunk forwarder installations on endpoints.

C.  

Orchestrating the operations and scale of a containerized Splunk deployment.

D.  

Updating configuration and distributing apps to processing components, primarily forwarders.

Discussion 0
Questions 7

If an update is made to an attribute in inputs.conf on a universal forwarder, on which Splunk component

would the fishbucket need to be reset in order to reindex the data?

Options:

A.  

Indexer

B.  

Forwarder

C.  

Search head

D.  

Deployment server

Discussion 0
Questions 8

Which of the following apply to how distributed search works? (select all that apply)

Options:

A.  

The search head dispatches searches to the peers

B.  

The search peers pull the data from the forwarders.

C.  

Peers run searches in parallel and return their portion of results.

D.  

The search head consolidates the individual results and prepares reports

Discussion 0
Questions 9

Local user accounts created in Splunk store passwords in which file?

Options:

A.  

$ SFLUNK_HOME/etc/passwd

B.  

$ SFLUNK_HOME/etc/authentication

C.  

$ S?LUNK_HOME/etc/users/passwd.conf

D.  

$ SPLUNK HOME/etc/users/authentication.conf

Discussion 0
Questions 10

The volume of data from collecting log files from 50 Linux servers and 200 Windows servers will require

multiple indexers. Following best practices, which types of Splunk component instances are needed?

Options:

A.  

Indexers, search head, universal forwarders, license master

B.  

Indexers, search head, deployment server, universal forwarders

C.  

Indexers, search head, deployment server, license master, universal forwarder

D.  

Indexers, search head, deployment server, license master, universal forwarder, heavy forwarder

Discussion 0
Questions 11

Which forwarder is recommended by Splunk to use in a production environment?

Options:

A.  

Heavy forwarder

B.  

SSL forwarder

C.  

Lightweight forwarder

D.  

Universal forwarder

Discussion 0
Questions 12

Which of the following is a benefit of distributed search?

Options:

A.  

Peers run search in sequence.

B.  

Peers run search in parallel.

C.  

Resilience from indexer failure.

D.  

Resilience from search head failure.

Discussion 0
Questions 13

After configuring a universal forwarder to communicate with an indexer, which index can be checked via the Splunk Web UI for a successful connection?

Options:

A.  

index=main

B.  

index=test

C.  

index=summary

D.  

index=_internal

Discussion 0
Questions 14

A company moves to a distributed architecture to meet the growing demand for the use of Splunk. What parameter can be configured to enable automatic load balancing in the

Universal Forwarder to send data to the indexers?

Options:

A.  

Create one outputs . conf file for each of the server addresses in the indexing tier.

B.  

Configure the outputs . conf file to point to any server in the indexing tier and Splunk will configure the data to be sent to all of the indexers.

C.  

Splunk does not do load balancing and requires a hardware load balancer to balance traffic across the indexers.

D.  

Set the stanza to have a server value equal to a comma-separated list of IP addresses and indexer ports for each of the indexers in the environment.

Discussion 0
Questions 15

Which of the following applies only to Splunk index data integrity check?

Options:

A.  

Lookup table

B.  

Summary Index

C.  

Raw data in the index

D.  

Data model acceleration

Discussion 0
Questions 16

Which of the following are reasons to create separate indexes? (Choose all that apply.)

Options:

A.  

Different retention times.

B.  

Increase number of users.

C.  

Restrict user permissions.

D.  

File organization.

Discussion 0
Questions 17

Which parent directory contains the configuration files in Splunk?

Options:

A.  

SSFLUNK_HOME/etc

B.  

SSPLUNK_HOME/var

C.  

SSPLUNK_HOME/conf

D.  

SSPLUNK_HOME/default

Discussion 0
Questions 18

What are the values forhostandindexfor[stanza1]used by Splunk during index time, given the following configuration files?

Options:

A.  

host=server1

index=unixinfo

B.  

host=server1

index=searchinfo

C.  

host=searchsvr1

index=searchinfo

D.  

host=unixsvr1

index=unixinfo

Discussion 0
Questions 19

For single line event sourcetypes. it is most efficient to set SHOULD_linemerge to what value?

Options:

A.  

True

B.  

False

C.  

D.  

Newline Character

Discussion 0
Questions 20

How can native authentication be disabled in Splunk?

Options:

A.  

Remove the $SPLUNK_HOME/etc/passwd file

B.  

Create an empty $SPLUNK_HOME/etc/passwd file

C.  

Set SPLUNK_AUTHENTICATION=false in splunk-launch.conf

D.  

Set nativeAuthentication=false in authentication.conf

Discussion 0
Questions 21

When does a warm bucket roll over to a cold bucket?

Options:

A.  

When Splunk is restarted.

B.  

When the maximum warm bucket age has been reached.

C.  

When the maximum warm bucket size has been reached.

D.  

When the maximum number of warm buckets is reached.

Discussion 0
Questions 22

A user recently installed an application to index NCINX access logs. After configuring the application, they realize that no data is being ingested. Which configuration file do they need to edit to ingest the access logs to ensure it remains unaffected after upgrade?

Options:

A.  

Option A

B.  

Option B

C.  

Option C

D.  

Option D

Discussion 0
Questions 23

Which of the following is a valid distributed search group?

Options:

A.  

[distributedSearch:Paris] default = false servers = server1, server2

B.  

[searchGroup:Paris] default = false servers = server1:8089, server2:8089

C.  

[searchGroup:Paris] default = false servers = server1:9997, server2:9997

D.  

[distributedSearch:Paris] default = false servers = server1:8089; server2:8089

Discussion 0
Questions 24

In a distributed environment, which Splunk component is used to distribute apps and configurations to the

other Splunk instances?

Options:

A.  

Indexer

B.  

Deployer

C.  

Forwarder

D.  

Deployment server

Discussion 0
Questions 25

Which of the following are supported configuration methods to add inputs on a forwarder? (select all that apply)

Options:

A.  

CLI

B.  

Edit inputs . conf

C.  

Edit forwarder.conf

D.  

Forwarder Management

Discussion 0
Questions 26

Assume a file is being monitored and the data was incorrectly indexed to an exclusive index. The index is

cleaned and now the data must be reindexed. What other index must be cleaned to reset the input checkpoint

information for that file?

Options:

A.  

_audit

B.  

_checkpoint

C.  

_introspection

D.  

_thefishbucket

Discussion 0
Questions 27

A security team needs to ingest a static file for a specific incident. The log file has not been collected previously and future updates to the file must not be indexed.

Which command would meet these needs?

Options:

A.  

splunk add one shot / opt/ incident [data .log —index incident

B.  

splunk edit monitor /opt/incident/data.* —index incident

C.  

splunk add monitor /opt/incident/data.log —index incident

D.  

splunk edit oneshot [opt/ incident/data.* —index incident

Discussion 0
Questions 28

Which of the following are supported options when configuring optional network inputs?

Options:

A.  

Metadata override, sender filtering options, network input queues (quantum queues)

B.  

Metadata override, sender filtering options, network input queues (memory/persistent queues)

C.  

Filename override, sender filtering options, network output queues (memory/persistent queues)

D.  

Metadata override, receiver filtering options, network input queues (memory/persistent queues)

Discussion 0
Questions 29

When running a real-time search, search results are pulled from which Splunk component?

Options:

A.  

Heavy forwarders and search peers

B.  

Heavy forwarders

C.  

Search heads

D.  

Search peers

Discussion 0
Questions 30

What type of Splunk license is pre-selected in a brand new Splunk installation?

Options:

A.  

Free license

B.  

Forwarder license

C.  

Enterprise trial license

D.  

Enterprise license

Discussion 0
Questions 31

What hardware attribute would need to be changed to increase the number of simultaneous searches (ad-hoc and scheduled) on a single search head?

Options:

A.  

Disk

B.  

CPUs

C.  

Memory

D.  

Network interface cards

Discussion 0
Questions 32

UsingSEDCMDinprops.confallows raw data to be modified. With the given event below, which option will mask the first three digits of theAcctIDfield resulting output:[22/Oct/2018:15:50:21] VendorID=1234 Code=B AcctID=xxx5309

Event:

[22/Oct/2018:15:50:21] VendorID=1234 Code=B AcctID=xxx5309

Options:

A.  

SEDCMD-1acct = s/VendorID=\d{3}(\d{4})/VendorID=xxx/g

B.  

SEDCMD-xxxAcct = s/AcctID=\d{3}(\d{4})/AcctID=xxx/g

C.  

SEDCMD-1acct = s/AcctID=\d{3}(\d{4})/AcctID=\1xxx/g

D.  

SEDCMD-1acct = s/AcctID=\d{3}(\d{4})/AcctID=xxx\1/g

Discussion 0
Questions 33

Which additional component is required for a search head cluster?

Options:

A.  

Deployer

B.  

Cluster Master

C.  

Monitoring Console

D.  

Management Console

Discussion 0
Questions 34

What are the minimum required settings when creating a network input in Splunk?

Options:

A.  

Protocol, port number

B.  

Protocol, port, location

C.  

Protocol, username, port

D.  

Protocol, IP. port number

Discussion 0
Questions 35

What will the following inputs. conf stanza do?

[script://myscript . sh]

Interval=0

Options:

A.  

The script will run at the default interval of 60 seconds.

B.  

The script will not be run.

C.  

The script will be run only once for each time Splunk is restarted.

D.  

The script will be run. As soon as the script exits, Splunk restarts it.

Discussion 0
Questions 36

Which option on the Add Data menu is most useful for testing data ingestion without creating inputs.conf?

Options:

A.  

Upload option

B.  

Forward option

C.  

Monitor option

D.  

Download option

Discussion 0
Questions 37

Which of the following are required when defining an index in indexes. conf? (select all that apply)

Options:

A.  

coldPath

B.  

homePath

C.  

frozenPath

D.  

thawedPath

Discussion 0
Questions 38

What is the command to reset the fishbucket for one source?

Options:

A.  

rm -r ~/splunkforwarder/var/lib/splunk/fishbucket

B.  

splunk clean eventdata -index _thefishbucket

C.  

splunk cmd btprobe -d SPLUNK_HOME/var/lib/splunk/fishbucket/splunk_private_db --file --reset

D.  

splunk btool fishbucket reset

Discussion 0
Questions 39

Where should apps be located on the deployment server that the clients pull from?

Options:

A.  

$SFLUNK_KOME/etc/apps

B.  

$SPLUNK_HCME/etc/sear:ch

C.  

$SPLUNK_HCME/etc/master-apps

D.  

$SPLUNK HCME/etc/deployment-apps

Discussion 0
Questions 40

Which data pipeline phase is the last opportunity for defining event boundaries?

Options:

A.  

Input phase

B.  

Indexing phase

C.  

Parsing phase

D.  

Search phase

Discussion 0
Questions 41

Which of the following statements describe deployment management? (select all that apply)

Options:

A.  

Requires an Enterprise license

B.  

Is responsible for sending apps to forwarders.

C.  

Once used, is the only way to manage forwarders

D.  

Can automatically restart the host OS running the forwarder.

Discussion 0
Questions 42

Which of the following must be done to define user permissions when integrating Splunk with LDAP?

Options:

A.  

Map Users

B.  

Map Groups

C.  

Map LDAP Inheritance

D.  

Map LDAP to Active Directory

Discussion 0
Questions 43

Which Splunk component would one use to perform line breaking prior to indexing?

Options:

A.  

Heavy Forwarder

B.  

Universal Forwarder

C.  

Search head

D.  

This can only be done at the indexing layer.

Discussion 0
Questions 44

What is the correct order of steps in Duo Multifactor Authentication?

Options:

A.  

1 Request Login

2. Connect to SAML server

3 Duo MFA

4 Create User session

5 Authentication Granted 6. Log into Splunk

B.  

1. Request Login 2 Duo MFA

3. Authentication Granted 4 Connect to SAML server

5. Log into Splunk

6. Create User session

C.  

1 Request Login

2 Check authentication / group mapping

3 Authentication Granted

4. Duo MFA

5. Create User session

6. Log into Splunk

D.  

1 Request Login 2 Duo MFA

3. Check authentication / group mapping

4 Create User session

5. Authentication Granted

6 Log into Splunk

Discussion 0
Questions 45

What options are available when creating custom roles? (select all that apply)

Options:

A.  

Restrict search terms

B.  

Whitelist search terms

C.  

Limit the number of concurrent search jobs

D.  

Allow or restrict indexes that can be searched.

Discussion 0
Questions 46

Which of the following are methods for adding inputs in Splunk? (select all that apply)

Options:

A.  

CLI

B.  

Splunk Web

C.  

Editing inputs. conf

D.  

Editing monitor. conf

Discussion 0
Questions 47

Which Splunk component(s) would break a stream of syslog inputs into individual events? (select all that apply)

Options:

A.  

Universal Forwarder

B.  

Search head

C.  

Heavy Forwarder

D.  

Indexer

Discussion 0
Questions 48

The priority of layered Splunk configuration files depends on the file's:

Options:

A.  

Owner

B.  

Weight

C.  

Context

D.  

Creation time

Discussion 0
Questions 49

What action is required to enable forwarder management in Splunk Web?

Options:

A.  

Navigate to Settings > Server Settings > General Settings, and set an App server port.

B.  

Navigate to Settings > Forwarding and receiving, and click on Enable Forwarding.

C.  

Create a server class and map it to a client inSPLUNK_HOME/etc/system/local/serverclass.conf.

D.  

Place an app in theSPLUNK_HOME/etc/deployment-appsdirectory of the deployment server.

Discussion 0
Questions 50

What event-processing pipelines are used to process data for indexing? (select all that apply)

Options:

A.  

Typing pipeline

B.  

Parsing pipeline

C.  

fifo pipeline

D.  

Indexing pipeline

Discussion 0
Questions 51

Which pathway represents where a network input in Splunk might be found?

Options:

A.  

$SPLUNK HOME/ etc/ apps/ ne two r k/ inputs.conf

B.  

$SPLUNK HOME/ etc/ apps/ $appName/ local / inputs.conf

C.  

$SPLUNK HOME/ system/ local /udp.conf

D.  

$SPLUNK HOME/ var/lib/ splunk/$inputName/homePath/

Discussion 0