ExamGecko
Home / Splunk / SPLK-1003
Ask Question

Splunk SPLK-1003 Practice Test - Questions Answers, Page 5

Question list
Search

Question 41

Report
Export
Collapse

Where should apps be located on the deployment server that the clients pull from?

$SFLUNK_KOME/etc/apps
$SFLUNK_KOME/etc/apps
$SPLUNK_HCME/etc/sear:ch
$SPLUNK_HCME/etc/sear:ch
$SPLUNK_HCME/etc/master-apps
$SPLUNK_HCME/etc/master-apps
$SPLUNK HCME/etc/deployment-apps
$SPLUNK HCME/etc/deployment-apps
Suggested answer: D

Explanation:

After an app is downloaded, it resides under $SPLUNK_HOME/etc/apps on the deployment clients.

But it resided in the $SPLUNK_HOME/etc/deployment-apps location in the deployment server.

asked 23/09/2024
Bonginhlanhla Mtshali
36 questions

Question 42

Report
Export
Collapse

This file has been manually created on a universal forwarder

Splunk SPLK-1003 image Question 42 75350 09232024004541000000

A new Splunk admin comes in and connects the universal forwarders to a deployment server and deploys the same app with a new

Splunk SPLK-1003 image Question 42 75350 09232024004541000000

Which file is now monitored?

/var/log/messages
/var/log/messages
/var/log/maillog
/var/log/maillog
/var/log/maillog and /var/log/messages
/var/log/maillog and /var/log/messages
none of the above
none of the above
Suggested answer: B
asked 23/09/2024
Sukhpreet Sidhu
40 questions

Question 43

Report
Export
Collapse

In which phase of the index time process does the license metering occur?

input phase
input phase
Parsing phase
Parsing phase
Indexing phase
Indexing phase
Licensing phase
Licensing phase
Suggested answer: C

Explanation:

"When ingesting event data, the measured data volume is based on the new raw data that is placed into the indexing pipeline. Because the data is measured at the indexing pipeline, data that is filetered and dropped prior to indexing does not count against the license volume qota."

https://docs.splunk.com/Documentation/Splunk/8.0.6/Admin/HowSplunklicensingworks

asked 23/09/2024
Grzegorz GÅ‚ogowski
32 questions

Question 44

Report
Export
Collapse

You update a props. conf file while Splunk is running. You do not restart Splunk and you run this command: splunk btoo1 props list —debug. What will the output be?

list of all the configurations on-disk that Splunk contains.
list of all the configurations on-disk that Splunk contains.
A verbose list of all configurations as they were when splunkd started.
A verbose list of all configurations as they were when splunkd started.
A list of props. conf configurations as they are on-disk along with a file path from which the configuration is located
A list of props. conf configurations as they are on-disk along with a file path from which the configuration is located
A list of the current running props, conf configurations along with a file path from which the configuration was made
A list of the current running props, conf configurations along with a file path from which the configuration was made
Suggested answer: C

Explanation:

https://docs.splunk.com/Documentation/Splunk/8.0.1/Troubleshooting/Usebtooltotroubleshootconfigurations

"The btool command simulates the merging process using the on-disk conf files and creates a report showing the merged settings."

"The report does not necessarily represent what's loaded in memory. If a conf file change is made that requires a service restart, the btool report shows the change even though that change isn't active."

asked 23/09/2024
Sukhpal Singh
31 questions

Question 45

Report
Export
Collapse

When running the command shown below, what is the default path in which deployment server.

conf is created?

splunk set deploy-poll deployServer:port

SFLUNK_HOME/etc/deployment
SFLUNK_HOME/etc/deployment
SPLUNK_HOME/etc/system/local
SPLUNK_HOME/etc/system/local
SPLUNK_HOME/etc/system/default
SPLUNK_HOME/etc/system/default
SPLUNK_KOME/etc/apps/deployment
SPLUNK_KOME/etc/apps/deployment
Suggested answer: C

Explanation:

https://docs.splunk.com/Documentation/Splunk/8.1.1/Updating/Definedeploymentclasses#Ways_to_define_server_classes

"When you use forwarder management to create a new server class, it saves the server class definition in a copy of serverclass.conf under $SPLUNK_HOME/etc/system/local. If, instead of using forwarder management, you decide to directly edit serverclass.conf, it is recommended that you create the serverclass.conf file in that same directory, $SPLUNK_HOME/etc/system/local."

asked 23/09/2024
Sukhpal Singh
31 questions

Question 46

Report
Export
Collapse

The priority of layered Splunk configuration files depends on the file's:

Owner
Owner
Weight
Weight
Context
Context
Creation time
Creation time
Suggested answer: C

Explanation:

https://docs.splunk.com/Documentation/Splunk/7.3.0/Admin/Wheretofindtheconfigurationfiles

"To determine the order of directories for evaluating configuration file precendence, Splunk software considers each file's context. Configuration files operate in either a global context or in the context of the current app and user"

asked 23/09/2024
Gishi Anurag
30 questions

Question 47

Report
Export
Collapse

When configuring monitor inputs with whitelists or blacklists, what is the supported method of filtering the lists?

Slash notation
Slash notation
Regular expression
Regular expression
Irregular expression
Irregular expression
Wildcard-only expression
Wildcard-only expression
Suggested answer: B

Explanation:

https://docs.splunk.com/Documentation/Splunk/latest/Data/Whitelistorblacklistspecificincomingdata#Include_or_exclude_specific_incoming_data

asked 23/09/2024
Carlotta Agape
39 questions

Question 48

Report
Export
Collapse

Which of the following statements describes how distributed search works?

Forwarders pull data from the search peers.
Forwarders pull data from the search peers.
Search heads store a portion of the searchable data.
Search heads store a portion of the searchable data.
The search head dispatches searches to the search peers.
The search head dispatches searches to the search peers.
Search results are replicated within the indexer cluster.
Search results are replicated within the indexer cluster.
Suggested answer: C

Explanation:

URL https://docs.splunk.com/Documentation/Splunk/8.2.2/DistSearch/Configuredistributedsearch

"To activate distributed search, you add search peers, or indexers, to a Splunk Enterprise instance that you desingate as a search head. You do this by specifying each search peer manually."

asked 23/09/2024
Albert Smith
39 questions

Question 49

Report
Export
Collapse

Which feature in Splunk allows Event Breaking, Timestamp extractions, and any advanced configurations found in props.conf to be validated all through the UI?

Apps
Apps
Search
Search
Data preview
Data preview
Forwarder inputs
Forwarder inputs
Suggested answer: C

Explanation:

http://www.splunk.com/view/SP-CAAAGPR

asked 23/09/2024
Premier Lane
36 questions

Question 50

Report
Export
Collapse

Which of the following statements accurately describes using SSL to secure the feed from a forwarder?

It does not encrypt the certificate password.
It does not encrypt the certificate password.
SSL automatically compresses the feed by default.
SSL automatically compresses the feed by default.
It requires that the forwarder be set to compressed=true.
It requires that the forwarder be set to compressed=true.
It requires that the receiver be set to compression=true.
It requires that the receiver be set to compression=true.
Suggested answer: A

Explanation:

Reference: https://docs.splunk.com/Documentation/Splunk/8.0.5/Security/AboutsecuringyourSplunkconfigurationwithSSL

asked 23/09/2024
Vitalii Lutsenko
33 questions
Total 189 questions
Go to page: of 19