Splunk SPLK-1005 Practice Test - Questions Answers
List of questions
Related questions
A monitor has been created in inputs. con: for a directory that contains a mix of file types.
How would a Cloud Admin fine-tune assigned sourcetypes for different files in the directory during the input phase?
On the Indexer parsing the data, leave sourcetype as automatic for the directory monitor. Then create a props.conf that assigns a specific sourcetype by source stanza.
On the forwarder collecting the data, leave sourcetype as automatic for the directory monitor. Then create a props. conf that assigns a specific sourcetype by source stanza.
On the Indexer parsing the data, set multiple sourcetype_source attributes for the directory monitor collecting the files. Then create a props, com that filters out unwanted files.
On the forwarder collecting the data, set multiple 3ourcotype_sourc attributes for the directory monitor collecting the files. Then create a props. conf that filters out unwanted files.
Windows Input types are collected in Splunk via a script which is configurable using the GUI. What is this type of input called?
Batch
Scripted
Modular
Front-end
The following sample log event shows evidence of credit card numbers being present in the transactions. loc file.
Which of these SEDCM3 settings will mask this and other suspected credit card numbers with an Y character for each character being masked? The indexed event should be formatted as follows:
A)
B)
C)
D)
Option A
Option B
Option C
Option D
Which of the following is a correct statement about Universal Forwarders?
The Universal Forwarder must be able to contact the license master.
A Universal Forwarder must connect to Splunk Cloud via a Heavy Forwarder.
A Universal Forwarder can be an Intermediate Forwarder.
The default output bandwidth is 500KBps.
Which of the following is true when integrating LDAP authentication?
Splunk stores LDAP end user names and passwords on search heads.
The mapping of LDAP groups to Splunk roles happens automatically.
Splunk Cloud only supports Active Directory LDAP servers.
New user data is cached the first time a user logs in.
A Splunk Cloud administrator is looking to allow a new group of Splunk users in the marketing department to access the Splunk environment and view a dashboard with relevant data. These users need to access marketing data (stored in the marketing_data index), but shouldn't be able to access other data, such as events related to security or operations.
Which approach would be the best way to accomplish these requirements?
Create a new user with access to the marketing_data index assigned.
Create a new role that inherits the user role and remove the capability to search indexes other than marketing_data.
Create a new role that inherits the admin rote and assign access to the marketing_dat.a index.
Create a new role that does not inherit from any other role, turn on the same capabilities as the user role, and assign access to the marketing_data index.
Files from multiple systems are being stored on a centralized log server. The files are organized into directories based on the original server they came from. Which of the following is a recommended approach for correctly setting the host values based on their origin?
Use the host segment, setting.
Set host = * in the monitor stanza.
The host value cannot be dynamically set.
Manually create a separate monitor stanza for each host, with the nose = value set.
In which file can the SH0ULD_LINEMERCE setting be modified?
transforms.conf
inputs.conf
props.conf
outputs.conf
What is the recommended approach to collect data from network devices?
TCP/UDP Feed > Heavy Forwarder > Intermediate Forwarder > Splunk Cloud
TCP/UDP Feed > Syslog Server with Universal Forwarder > Splunk Cloud
TCP/UDP Feed > Universal Forwarder > Intermediate Forwarder > Splunk Cloud
TCP/UDP Feed > Intermediate Forwarder > Heavy Forwarder > Splunk Cloud
When a forwarder phones home to a Deployment Server it compares the check-sum value of the forwarder's app to the Deployment Server's app. What happens to the app If the check-sum values do not match?
The app on the forwarder is always deleted and re-downloaded from the Deployment Server.
The app on the forwarder is only deleted and re-downloaded from the Deployment Server if the forwarder's app has a smaller check-sum value.
The app is downloaded from the Deployment Server and the changes are merged.
A warning is generated on the Deployment Server stating the apps are out of sync. An Admin will need to confirm which version of the app should be used.
Question