ExamGecko
Home Home / Splunk / SPLK-1001

Splunk SPLK-1001 Practice Test - Questions Answers, Page 6

Question list
Search
Search

Which of the following describes lookup files?

A.
Lookup fields cannot be used in searches
A.
Lookup fields cannot be used in searches
Answers
B.
Lookups contain static data available in the index
B.
Lookups contain static data available in the index
Answers
C.
Lookups add more fields to results returned by a search
C.
Lookups add more fields to results returned by a search
Answers
D.
Lookups pull data at index time and add them to search results
D.
Lookups pull data at index time and add them to search results
Answers
Suggested answer: B

When running searches command modifiers in the search string are displayed in what color?

A.
Red
A.
Red
Answers
B.
Blue
B.
Blue
Answers
C.
Orange
C.
Orange
Answers
D.
Highlighted
D.
Highlighted
Answers
Suggested answer: B

How do you add or remove fields from search results?

A.
Use field +to add and field -to remove.
A.
Use field +to add and field -to remove.
Answers
B.
Use table +to add and table -to remove.
B.
Use table +to add and table -to remove.
Answers
C.
Use fields +to add and fields –to remove.
C.
Use fields +to add and fields –to remove.
Answers
D.
Use fields Plus to add and fields Minus to remove.
D.
Use fields Plus to add and fields Minus to remove.
Answers
Suggested answer: C

What are the steps to schedule a report?

A.
After saving the report, click Schedule.
A.
After saving the report, click Schedule.
Answers
B.
After saving the report, click Event Type.
B.
After saving the report, click Event Type.
Answers
C.
After saving the report, click Scheduling.
C.
After saving the report, click Scheduling.
Answers
D.
After saving the report, click Dashboard Panel.
D.
After saving the report, click Dashboard Panel.
Answers
Suggested answer: A

By default, how long does Splunk retain a search job?

A.
10 Minutes
A.
10 Minutes
Answers
B.
15 Minutes
B.
15 Minutes
Answers
C.
1 Day
C.
1 Day
Answers
D.
7 Days
D.
7 Days
Answers
Suggested answer: A

Which Boolean operator is implied between search terms, unless otherwise specified?

A.
OR
A.
OR
Answers
B.
AND
B.
AND
Answers
C.
NOT
C.
NOT
Answers
D.
NAND
D.
NAND
Answers
Suggested answer: B

What is a primary function of a scheduled report?

A.
Auto-detect changes in performance
A.
Auto-detect changes in performance
Answers
B.
Auto-generated PDF reports of overall data trends
B.
Auto-generated PDF reports of overall data trends
Answers
C.
Regularly scheduled archiving to keep disk space use low
C.
Regularly scheduled archiving to keep disk space use low
Answers
D.
Triggering an alert in your Splunk instance when certain conditions are met
D.
Triggering an alert in your Splunk instance when certain conditions are met
Answers
Suggested answer: D

When sorting on multiple fields with the sort command, what delimiter can be used between the field names in the search?

A.
|
A.
|
Answers
B.
$
B.
$
Answers
C.
!
C.
!
Answers
D.
,
D.
,
Answers
Suggested answer: D

Which search string is the most efficient?

A.
"failed password"
A.
"failed password"
Answers
B.
''failed password"*
B.
''failed password"*
Answers
C.
index=* "failed password"
C.
index=* "failed password"
Answers
D.
index=security "failed password"
D.
index=security "failed password"
Answers
Suggested answer: D

Which search string matches only events with the status_code of 4:4?

A.
status_code !=404
A.
status_code !=404
Answers
B.
status_code>=400
B.
status_code>=400
Answers
C.
status_code<=404
C.
status_code<=404
Answers
D.
status code>403 status_code<405
D.
status code>403 status_code<405
Answers
Suggested answer: D
Total 246 questions
Go to page: of 25