Skip to content

Core Certified Power User Practice Questions

Prepare for SPLK-1002 with more than an answer.

295 questions in the full set20 sample questionsUpdated Jan 26, 2026
Exam fee
$130 USD
Level
Entry
Valid for
Does not expire
Domains covered on the exam 10
  1. Using Transforming Commands for Visualizations10%
  2. Filtering and Formatting Results10%
  3. Correlating Events10%
  4. Creating and Managing Fields10%
  5. Creating Field Aliases and Calculated Fields10%
  6. Creating Tags and Event Types10%
  7. Creating and Using Macros10%
  8. Creating and Using Workflow Actions10%
  9. Creating Data Models10%
  10. Using the Common Information Model (CIM) Add-On10%
  1. 1

    Data models are composed of one or more of which of the following datasets? (Choose all that apply.)

    Show answer details
  2. 2

    Which delimiters can the Field Extractor (FX) detect? (Choose all that apply.)

    Show answer details
  3. 3

    Which Knowledge Object does the Splunk Common Information Model (CIM) use to normalize data, in addition to field aliases, event types, and tags?

    Show answer details
  4. 4

    Which of the following statements describes POST workflow actions?

    Show answer details

    Correct answer: D

    Reference: httDs://docs.sDlunk.com/Documentation/SDlunk/8.0.3/Knowledge/SetupaPOSTworkflowaction

  5. 5

    An administrator created a search workflow action to help junior analysts investigate failed logins. When a junior analyst clicks the workflow action, the new search runs but returns no results, even though the administrator can run it successfully and see results. What is the most likely reason for this discrepancy?

    sequenceDiagram participant Junior Analyst participant Splunk UI participant Splunk Search Head participant Indexer Junior Analyst->>Splunk UI: Clicks Workflow Action Splunk UI->>Splunk Search Head: Executes search string Splunk Search Head->>Indexer: Runs search with Analyst's permissions Indexer-->>Splunk Search Head: Returns no results Splunk Search Head-->>Splunk UI: Displays 'No results found'

    Show answer details

    Correct answer: B

    Workflow actions always execute with the permissions of the user who clicks them, not the user who created them. The most common reason for a search to work for an admin but not for a junior user is role-based access control (RBAC). The junior analyst's role likely lacks permission to search the index (e.g., the security index) that contains the relevant data, so the search returns no results for them.

  6. 6

    3Which workflow uses field values to perform a secondary search?

    Show answer details

    Correct answer: C

    C

  7. 7

    What is the correct syntax to search for a tag associated with a value on a specific field?

    Show answer details
  8. 8

    What is the correct syntax to search for a tag associated with a value on a specific field?

    Show answer details
  9. 9

    What are the two parts of a root event dataset?

    Show answer details
  10. 10

    When using| timechart by host, which field is represented in the x-axis?

    Show answer details

Create an account to continue.