SPLK-1005 Cloud Certified Admin Practice Questions
Prepare for SPLK-1005 with more than an answer.
- Exam fee
- $130 USD
- Level
- Professional
- Valid for
- 2 years
Domains covered on the exam 13
- Splunk Cloud Overview5%
- Index Management5%
- User Authentication and Authorization5%
- Splunk Configuration Files5%
- Getting Data in Cloud15%
- Forwarder Management5%
- Monitor Inputs15%
- Network and Other Inputs10%
- Fine-tuning Inputs5%
- Parsing Phase and Data Preview10%
- Manipulating Raw Data10%
- Installing and Managing Apps5%
- Working with Splunk Cloud Support5%
- 1
A Splunk Cloud administrator needs to collect Windows Security event logs. Which
inputs.confstanza correctly configures a Universal Forwarder to collect these specific logs?Show answer details
Correct answer: D
Splunk provides a dedicated input type for Windows Event Logs. The correct stanza format is
[WinEventLog:// ], whereis the name of the event channel, such as Application, System, or Security. This method is the most efficient and reliable way to collect Windows event data. - 2
A Splunk Cloud admin is using
SEDCMDinprops.confto remove verbose debugging strings from events at index time. The configuration is:[my_sourcetype]SEDCMD-remove_debug = s/DEBUG:\s.*//gAfter applying the configuration, the admin notices that although the
DEBUG:strings are removed, some events are now truncated or malformed. What is a key consideration when usingSEDCMDthat could explain this issue?Show answer details
Correct answer: D
SEDCMDruns before line breaking. If events are multi-line, a greedy regex like.*can match across line boundaries and consume parts of what should have been separate events. This can cause event truncation and malformed data. The regex should be made non-greedy or more specific to avoid matching across newlines if they are present in the data stream before line merging decisions are finalized. - 3
What is the primary difference between a 'Managed' Splunk Cloud Platform deployment and a 'Self-Service' one from the administrator's perspective?
Show answer details
Correct answer: A
The core difference lies in the division of administrative responsibilities. In a 'Managed' (now often part of higher-tier offerings) deployment, certain administrative actions, such as installing private apps or making specific low-level configuration changes, require opening a support ticket. In a 'Self-Service' deployment, administrators are empowered to perform more of these tasks themselves through tools like the Admin Config Service (ACS) API and the Splunk Web UI.
- 4
A Splunk Cloud administrator needs to forward data from a central syslog server to Splunk Cloud. The syslog server receives a high volume of data from hundreds of network devices. To ensure reliable, acknowledged delivery of this data, which input configuration should be used on the intermediate forwarder that reads the syslog data?
Show answer details
Correct answer: D
TCP (Transmission Control Protocol) is a connection-oriented protocol that provides guaranteed, acknowledged delivery of data. For critical data like syslog where data loss is unacceptable, TCP is the preferred protocol. UDP (User Datagram Protocol) is connectionless and does not guarantee delivery, making it unsuitable for this reliability requirement.
- 5
A Splunk Cloud admin has configured a Universal Forwarder with the following
inputs.conf:[monitor:///var/log/messages] disabled = 0 host_segment = 3The full path to the log file on a server named
webserver-prod-01.example.comis/var/log/messages. What will thehostfield be for events from this file?Show answer details
Correct answer: C
The
host_segmentattribute is used to extract a segment from the file's source path to use as the host field. However,host_segmentonly applies if thehostattribute is NOT already set to a value derived fromserverNameinserver.confor the machine's hostname. By default, a Universal Forwarder sets the host to its own hostname. Therefore,host_segmentis ignored, and the host field will be the server's fully qualified domain name. - 6
A financial services company is using Splunk Cloud Platform and has a requirement to segregate data from their trading, compliance, and retail banking applications into distinct indexes. The Splunk Cloud admin has created the indexes:
trading_prod,compliance_prod, andretail_prod. To control access, three roles have been created:trading_user,compliance_user, andretail_user. Which configuration ensures that users in thetrading_userrole can only search thetrading_prodindex and no other indexes?Show answer details
Correct answer: A
The
srchIndexesAllowedparameter in a role's configuration is the primary mechanism for restricting which indexes a role can search. Setting it totrading_prodexplicitly limits searches for that role to only that index. UsingsrchFilterwould still allow searches against other indexes if the user knew to specify them, it only applies a default filter.importRolesis for role inheritance, andsrchIndexesDefaultonly sets the default index to search if none is specified. - 7
A Splunk Cloud administrator is configuring a monitor input on a Universal Forwarder to collect logs from
/var/log/app/. This directory containsaccess.log,error.log, anddebug.log. The administrator wants to assign different sourcetypes (app_access,app_error,app_debug) based on the filename. What is the most efficient method to achieve this on the data input side?Show answer details
Correct answer: D
Splunk best practice for assigning sourcetypes to files within a single monitored directory is to define the monitor input in
inputs.confwithout asourcetypesetting, and then useprops.confon the forwarder to assign sourcetypes based on thesourcefield. This allows for granular control and is more scalable than creating multiple monitor stanzas. - 8
A Splunk Cloud administrator is troubleshooting an issue where events from a critical application are not being indexed. The data is sent from a Universal Forwarder to Splunk Cloud. The administrator runs the following command on the forwarder:
splunk list forward-server. The output shows the Splunk Cloud indexer endpoint is active. What is the next logical step to diagnose the problem on the Universal Forwarder?Show answer details
Correct answer: A
After verifying the forwarder is configured to send data to the correct destination, the next step is to check its internal log,
splunkd.log. This log file contains detailed information about the forwarder's operations, including file monitoring activities, connection status, and potential errors (e.g., 'file too large', 'permission denied', 'connection refused') that would explain why data is not being sent. - 9
A Splunk Cloud admin needs to onboard a new data source that produces multi-line Java stack traces. Each event begins with a timestamp, but subsequent lines of the stack trace do not. How should the administrator configure line breaking to ensure each full stack trace is treated as a single event?
Example event:
2023-10-27 10:30:15,123 ERROR [main] com.example.App - An exception occurred java.lang.RuntimeException: Operation failed at com.example.Service.performAction(Service.java:42) at com.example.App.main(App.java:10)Show answer details
Correct answer: A
For multi-line events where only the first line matches a specific pattern (like a timestamp), the correct approach is to set
SHOULD_LINEMERGE = trueto enable line merging, and then useBREAK_ONLY_BEFOREwith a regular expression that matches the beginning of a new event. The regex^\d{4}-\d{2}-\d{2}correctly identifies the start of a new log entry, causing Splunk to break before this line and merge all subsequent lines that do not match into the previous event. - 10
True or False: In a Splunk Cloud Platform environment, a Cloud administrator can directly edit the
authorize.conffile in the backend to create and modify user roles.Show answer details
Correct answer: B
In Splunk Cloud Platform, administrators do not have direct file system access to the backend instances. Configuration changes, including role definitions which are stored in
authorize.conf, must be managed through the Splunk Web UI, REST API, or by deploying private apps. Direct file editing is a key difference between Splunk Enterprise and Splunk Cloud.
