ExamGecko
Home Home / Splunk / SPLK-1001

Splunk SPLK-1001 Practice Test - Questions Answers, Page 13

Question list
Search
Search

Universal forwarder is recommended for forwarding the logs to indexers.

A.
False
A.
False
Answers
B.
True
B.
True
Answers
Suggested answer: B

Splunk apps are used for following (Choose three.):

A.
Designed to cater numerous use cases and empower Splunk.
A.
Designed to cater numerous use cases and empower Splunk.
Answers
B.
We can not install Splunk App.
B.
We can not install Splunk App.
Answers
C.
Allows multiple workspaces for different use cases/user roles.
C.
Allows multiple workspaces for different use cases/user roles.
Answers
D.
It is collection of different Splunk config files like data inputs, UI and Knowledge Object.
D.
It is collection of different Splunk config files like data inputs, UI and Knowledge Object.
Answers
Suggested answer: A, C, D

Three basic components of Splunk are (Choose three.):

A.
Forwarders
A.
Forwarders
Answers
B.
Deployment Server
B.
Deployment Server
Answers
C.
Indexer
C.
Indexer
Answers
D.
Knowledge Objects
D.
Knowledge Objects
Answers
E.
Index
E.
Index
Answers
F.
Search Head
F.
Search Head
Answers
Suggested answer: A, C, F

What is Splunk?

A.
Splunk is a software platform to search, analyze and visualize the machine-generated data.
A.
Splunk is a software platform to search, analyze and visualize the machine-generated data.
Answers
B.
Database management tool.
B.
Database management tool.
Answers
C.
Security Information and Event Management (SIEM).
C.
Security Information and Event Management (SIEM).
Answers
D.
Cloud based application that help in analyzing logs.
D.
Cloud based application that help in analyzing logs.
Answers
Suggested answer: A

We should use heavy forwarder for sending event-based data to Indexers.

A.
False
A.
False
Answers
B.
True
B.
True
Answers
Suggested answer: B

Splunk Enterprise is used as a Scalable service in Splunk Cloud.

A.
True
A.
True
Answers
B.
False
B.
False
Answers
Suggested answer: A

Which component of Splunk let us write SPL query to find the required data?

A.
Forwarders
A.
Forwarders
Answers
B.
Indexer
B.
Indexer
Answers
C.
Heavy Forwarders
C.
Heavy Forwarders
Answers
D.
Search head
D.
Search head
Answers
Suggested answer: D

All components are installed and administered in Splunk Enterprise on-premise.

A.
True
A.
True
Answers
B.
False
B.
False
Answers
Suggested answer: A

Log filtering/parsing can be done from _____________.

A.
Index Forwarders (IF)
A.
Index Forwarders (IF)
Answers
B.
Universal Forwarders (UF)
B.
Universal Forwarders (UF)
Answers
C.
Super Forwarder (SF)
C.
Super Forwarder (SF)
Answers
D.
Heavy Forwarders (HF)
D.
Heavy Forwarders (HF)
Answers
Suggested answer: D

Which is the default app for Splunk Enterprise?

A.
Splunk Enterprise Security Suite
A.
Splunk Enterprise Security Suite
Answers
B.
Searching and Reporting
B.
Searching and Reporting
Answers
C.
Reporting and Searching
C.
Reporting and Searching
Answers
D.
Splunk apps for Security
D.
Splunk apps for Security
Answers
Suggested answer: B
Total 246 questions
Go to page: of 25