Splunk Cloud Certified Admin Free Sample Questions

20 free sample questions156 in the full practice test

Try simulator

SPLK-1005 Sample Questions

  1. Question 1

    A financial services company is using Splunk Cloud Platform and has a requirement to segregate data from their trading, compliance, and retail banking applications into distinct indexes. The Splunk Cloud admin has created the indexes: trading_prod, compliance_prod, and retail_prod. To control access, three roles have been created: trading_user, compliance_user, and retail_user. Which configuration ensures that users in the trading_user role can only search the trading_prod index and no other indexes?

    Answer and explanation

    Correct answer: B

    The srchIndexesAllowed parameter in a role's configuration is the primary mechanism for restricting which indexes a role can search. Setting it to trading_prod explicitly limits searches for that role to only that index. Using srchFilter would still allow searches against other indexes if the user knew to specify them, it only applies a default filter. importRoles is for role inheritance, and srchIndexesDefault only sets the default index to search if none is specified.

  2. Question 2

    A Splunk Cloud administrator is configuring a monitor input on a Universal Forwarder to collect logs from /var/log/app/. This directory contains access.log, error.log, and debug.log. The administrator wants to assign different sourcetypes (app_access, app_error, app_debug) based on the filename. What is the most efficient method to achieve this on the data input side?

    Answer and explanation

    Correct answer: D

    Splunk best practice for assigning sourcetypes to files within a single monitored directory is to define the monitor input in inputs.conf without a sourcetype setting, and then use props.conf on the forwarder to assign sourcetypes based on the source field. This allows for granular control and is more scalable than creating multiple monitor stanzas.

  3. Question 3

    A Splunk Cloud administrator is troubleshooting an issue where events from a critical application are not being indexed. The data is sent from a Universal Forwarder to Splunk Cloud. The administrator runs the following command on the forwarder: splunk list forward-server. The output shows the Splunk Cloud indexer endpoint is active. What is the next logical step to diagnose the problem on the Universal Forwarder?

    Answer and explanation

    Correct answer: B

    After verifying the forwarder is configured to send data to the correct destination, the next step is to check its internal log, splunkd.log. This log file contains detailed information about the forwarder's operations, including file monitoring activities, connection status, and potential errors (e.g., 'file too large', 'permission denied', 'connection refused') that would explain why data is not being sent.

  4. Question 4

    A Splunk Cloud admin needs to onboard a new data source that produces multi-line Java stack traces. Each event begins with a timestamp, but subsequent lines of the stack trace do not. How should the administrator configure line breaking to ensure each full stack trace is treated as a single event?

    Example event:

    2023-10-27 10:30:15,123 ERROR [main] com.example.App - An exception occurred
    java.lang.RuntimeException: Operation failed
    at com.example.Service.performAction(Service.java:42)
    at com.example.App.main(App.java:10)
    
    Answer and explanation

    Correct answer: C

    For multi-line events where only the first line matches a specific pattern (like a timestamp), the correct approach is to set SHOULD_LINEMERGE = true to enable line merging, and then use BREAK_ONLY_BEFORE with a regular expression that matches the beginning of a new event. The regex ^\d{4}-\d{2}-\d{2} correctly identifies the start of a new log entry, causing Splunk to break before this line and merge all subsequent lines that do not match into the previous event.

  5. Question 5

    True or False: In a Splunk Cloud Platform environment, a Cloud administrator can directly edit the authorize.conf file in the backend to create and modify user roles.

    Answer and explanation

    Correct answer: B

    In Splunk Cloud Platform, administrators do not have direct file system access to the backend instances. Configuration changes, including role definitions which are stored in authorize.conf, must be managed through the Splunk Web UI, REST API, or by deploying private apps. Direct file editing is a key difference between Splunk Enterprise and Splunk Cloud.

  6. Question 6

    Multiple answers

    An e-commerce company uses the Splunk HTTP Event Collector (HEC) to ingest transaction data from a microservice. To ensure data is routed to the correct index and assigned the correct sourcetype, the developers have been instructed to include specific HEC headers. However, the Splunk Cloud admin notices all data is landing in the default index for the HEC token. Which TWO of the following could be the cause of this issue? (Select TWO)

    Answer and explanation

    Correct answers: A, C

  7. Question 7

    A Splunk Cloud admin needs to mask Personally Identifiable Information (PII) from incoming web server logs. Specifically, the credit card numbers in the format CCN=1234-5678-9012-3456 must be replaced with CCN=XXXX-XXXX-XXXX-XXXX at index time. Which configuration combination in props.conf and transforms.conf on the search head (or relevant parsing tier) will accomplish this?

    Answer and explanation

    Correct answer: A

    This is the correct method for index-time data masking. The props.conf stanza invokes a transformation. The transforms.conf stanza defines that transformation: REGEX matches the pattern to be replaced, FORMAT defines the replacement string, and DEST_KEY = _raw specifies that the transformation should be applied directly to the raw event data before it is written to disk.

  8. Question 8

    A Splunk Cloud administrator is using a Deployment Server to manage a fleet of Universal Forwarders. A new server class, [serverClass:linux_web_servers], has been created to deploy a web log collection app. However, after creating the server class, none of the target Linux servers are downloading the new app. The whitelist.0 is correctly configured to match the hostnames. What is a common reason for this failure?

    Answer and explanation

    Correct answer: B

    After making changes to serverclass.conf or adding/modifying apps in the deployment-apps directory, the deployment server configuration must be reloaded for the changes to take effect. This can be done via the UI or by running the CLI command splunk reload deploy-server. Without this step, the deployment server is unaware of the new server class and will not instruct clients to download the associated apps.

  9. Question 9

    When creating a new index in Splunk Cloud Platform via the UI, what is the purpose of the 'Max Size of Entire Index' setting?

    Answer and explanation

    Correct answer: C

    The 'Max Size of Entire Index' (internally maxTotalDataSizeMB) setting determines the maximum total size the index can occupy on disk. When this size limit is reached, Splunk will begin to delete the oldest data (buckets) from the index to make room for new data, regardless of the time-based retention policy ('Retention (days)'). It is a size-based retention control.

  10. Question 10

    A Splunk Cloud admin is setting up a scripted input on a Linux Universal Forwarder. The script, /opt/splunkforwarder/bin/scripts/get_metrics.sh, runs correctly when executed manually from the command line. The inputs.conf stanza is as follows:

    [script:///opt/splunkforwarder/bin/scripts/get_metrics.sh]
    interval = 300
    sourcetype = custom_metrics
    index = metrics
    disabled = 0
    

    After configuration, no data appears in the metrics index. What is the most likely cause for this issue?

    Answer and explanation

    Correct answer: B

    For a scripted input to work, the Splunk process (typically running as user 'splunk') must have execute permissions on the script file. Even if the script runs correctly for the admin user ('root' or another user), it will fail to execute by the forwarder if permissions are not correctly set (e.g., via chmod a+x get_metrics.sh). This is one of the most common issues with scripted inputs.

Register free to unlock 10 more sample questions

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 156 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon