Question 1
A financial services company is using Splunk Cloud Platform and has a requirement to segregate data from their trading, compliance, and retail banking applications into distinct indexes. The Splunk Cloud admin has created the indexes: trading_prod, compliance_prod, and retail_prod. To control access, three roles have been created: trading_user, compliance_user, and retail_user. Which configuration ensures that users in the trading_user role can only search the trading_prod index and no other indexes?
Answer and explanation
Correct answer: B
The srchIndexesAllowed parameter in a role's configuration is the primary mechanism for restricting which indexes a role can search. Setting it to trading_prod explicitly limits searches for that role to only that index. Using srchFilter would still allow searches against other indexes if the user knew to specify them, it only applies a default filter. importRoles is for role inheritance, and srchIndexesDefault only sets the default index to search if none is specified.