Skip to content

SPLK-1005 Cloud Certified Admin Practice Questions

Prepare for SPLK-1005 with more than an answer.

156 questions in the full set20 sample questionsUpdated Jan 26, 2026
Exam fee
$130 USD
Level
Professional
Valid for
2 years
Domains covered on the exam 13
  1. Splunk Cloud Overview5%
  2. Index Management5%
  3. User Authentication and Authorization5%
  4. Splunk Configuration Files5%
  5. Getting Data in Cloud15%
  6. Forwarder Management5%
  7. Monitor Inputs15%
  8. Network and Other Inputs10%
  9. Fine-tuning Inputs5%
  10. Parsing Phase and Data Preview10%
  11. Manipulating Raw Data10%
  12. Installing and Managing Apps5%
  13. Working with Splunk Cloud Support5%
  1. 1

    A Splunk Cloud administrator needs to collect Windows Security event logs. Which inputs.conf stanza correctly configures a Universal Forwarder to collect these specific logs?

    Show answer details

    Correct answer: D

    Splunk provides a dedicated input type for Windows Event Logs. The correct stanza format is [WinEventLog:// ], where is the name of the event channel, such as Application, System, or Security. This method is the most efficient and reliable way to collect Windows event data.

  2. 2

    A Splunk Cloud admin is using SEDCMD in props.conf to remove verbose debugging strings from events at index time. The configuration is:
    [my_sourcetype]
    SEDCMD-remove_debug = s/DEBUG:\s.*//g

    After applying the configuration, the admin notices that although the DEBUG: strings are removed, some events are now truncated or malformed. What is a key consideration when using SEDCMD that could explain this issue?

    Show answer details

    Correct answer: D

    SEDCMD runs before line breaking. If events are multi-line, a greedy regex like .* can match across line boundaries and consume parts of what should have been separate events. This can cause event truncation and malformed data. The regex should be made non-greedy or more specific to avoid matching across newlines if they are present in the data stream before line merging decisions are finalized.

  3. 3

    What is the primary difference between a 'Managed' Splunk Cloud Platform deployment and a 'Self-Service' one from the administrator's perspective?

    Show answer details

    Correct answer: A

    The core difference lies in the division of administrative responsibilities. In a 'Managed' (now often part of higher-tier offerings) deployment, certain administrative actions, such as installing private apps or making specific low-level configuration changes, require opening a support ticket. In a 'Self-Service' deployment, administrators are empowered to perform more of these tasks themselves through tools like the Admin Config Service (ACS) API and the Splunk Web UI.

  4. 4

    A Splunk Cloud administrator needs to forward data from a central syslog server to Splunk Cloud. The syslog server receives a high volume of data from hundreds of network devices. To ensure reliable, acknowledged delivery of this data, which input configuration should be used on the intermediate forwarder that reads the syslog data?

    Show answer details

    Correct answer: D

    TCP (Transmission Control Protocol) is a connection-oriented protocol that provides guaranteed, acknowledged delivery of data. For critical data like syslog where data loss is unacceptable, TCP is the preferred protocol. UDP (User Datagram Protocol) is connectionless and does not guarantee delivery, making it unsuitable for this reliability requirement.

  5. 5

    A Splunk Cloud admin has configured a Universal Forwarder with the following inputs.conf:

    [monitor:///var/log/messages]
    disabled = 0
    host_segment = 3
    

    The full path to the log file on a server named webserver-prod-01.example.com is /var/log/messages. What will the host field be for events from this file?

    Show answer details

    Correct answer: C

    The host_segment attribute is used to extract a segment from the file's source path to use as the host field. However, host_segment only applies if the host attribute is NOT already set to a value derived from serverName in server.conf or the machine's hostname. By default, a Universal Forwarder sets the host to its own hostname. Therefore, host_segment is ignored, and the host field will be the server's fully qualified domain name.

  6. 6

    A financial services company is using Splunk Cloud Platform and has a requirement to segregate data from their trading, compliance, and retail banking applications into distinct indexes. The Splunk Cloud admin has created the indexes: trading_prod, compliance_prod, and retail_prod. To control access, three roles have been created: trading_user, compliance_user, and retail_user. Which configuration ensures that users in the trading_user role can only search the trading_prod index and no other indexes?

    Show answer details

    Correct answer: A

    The srchIndexesAllowed parameter in a role's configuration is the primary mechanism for restricting which indexes a role can search. Setting it to trading_prod explicitly limits searches for that role to only that index. Using srchFilter would still allow searches against other indexes if the user knew to specify them, it only applies a default filter. importRoles is for role inheritance, and srchIndexesDefault only sets the default index to search if none is specified.

  7. 7

    A Splunk Cloud administrator is configuring a monitor input on a Universal Forwarder to collect logs from /var/log/app/. This directory contains access.log, error.log, and debug.log. The administrator wants to assign different sourcetypes (app_access, app_error, app_debug) based on the filename. What is the most efficient method to achieve this on the data input side?

    Show answer details

    Correct answer: D

    Splunk best practice for assigning sourcetypes to files within a single monitored directory is to define the monitor input in inputs.conf without a sourcetype setting, and then use props.conf on the forwarder to assign sourcetypes based on the source field. This allows for granular control and is more scalable than creating multiple monitor stanzas.

  8. 8

    A Splunk Cloud administrator is troubleshooting an issue where events from a critical application are not being indexed. The data is sent from a Universal Forwarder to Splunk Cloud. The administrator runs the following command on the forwarder: splunk list forward-server. The output shows the Splunk Cloud indexer endpoint is active. What is the next logical step to diagnose the problem on the Universal Forwarder?

    Show answer details

    Correct answer: A

    After verifying the forwarder is configured to send data to the correct destination, the next step is to check its internal log, splunkd.log. This log file contains detailed information about the forwarder's operations, including file monitoring activities, connection status, and potential errors (e.g., 'file too large', 'permission denied', 'connection refused') that would explain why data is not being sent.

  9. 9

    A Splunk Cloud admin needs to onboard a new data source that produces multi-line Java stack traces. Each event begins with a timestamp, but subsequent lines of the stack trace do not. How should the administrator configure line breaking to ensure each full stack trace is treated as a single event?

    Example event:

    2023-10-27 10:30:15,123 ERROR [main] com.example.App - An exception occurred
    java.lang.RuntimeException: Operation failed
    at com.example.Service.performAction(Service.java:42)
    at com.example.App.main(App.java:10)
    
    Show answer details

    Correct answer: A

    For multi-line events where only the first line matches a specific pattern (like a timestamp), the correct approach is to set SHOULD_LINEMERGE = true to enable line merging, and then use BREAK_ONLY_BEFORE with a regular expression that matches the beginning of a new event. The regex ^\d{4}-\d{2}-\d{2} correctly identifies the start of a new log entry, causing Splunk to break before this line and merge all subsequent lines that do not match into the previous event.

  10. 10

    True or False: In a Splunk Cloud Platform environment, a Cloud administrator can directly edit the authorize.conf file in the backend to create and modify user roles.

    Show answer details

    Correct answer: B

    In Splunk Cloud Platform, administrators do not have direct file system access to the backend instances. Configuration changes, including role definitions which are stored in authorize.conf, must be managed through the Splunk Web UI, REST API, or by deploying private apps. Direct file editing is a key difference between Splunk Enterprise and Splunk Cloud.

Create an account to continue.