Splunk Core Certified Consultant Free Sample Questions

20 free sample questions242 in the full practice test

Try simulator

SPLK-3003 Sample Questions

  1. Question 1

    A financial services client has a 3-site indexer cluster (NYC, LON, TOK) configured for disaster recovery. The master node, located in NYC, has site_replication_factor = origin:1, total:2 and site_search_factor = origin:1, total:2. The LON site experiences a complete network outage. A historical search is executed from the NYC search head, which has search affinity disabled (site0). What is the expected behavior of the search results?

    Answer and explanation

    Correct answer: C

    On a three-site cluster, site_replication_factor = origin:1, total:2 keeps one copy on the origin site and sends the remaining copy to a site that has no copy yet, so the two copies of every bucket sit on two different sites. site_search_factor = origin:1, total:2 makes both copies searchable. When LON fails, every bucket therefore still has a searchable copy in NYC or TOK. The manager detects the failure after the heartbeat timeout (60 seconds by default); until it has reassigned primacy to the surviving searchable copies, searches return partial results. Then the cluster is valid again and the search returns complete results. No copies need to be converted, because the surviving copies are already searchable.

  2. Question 2

    A consultant is designing a data onboarding solution for a high-volume, custom binary log format from a proprietary manufacturing system. The logs must be parsed on a Heavy Forwarder (HF) before being sent to indexers. To ensure data integrity and prevent data loss during potential HF restarts or network issues, which configuration is most critical in outputs.conf on the HF?

    Answer and explanation

    Correct answer: B

    useACK = true enables indexer acknowledgment, which is disabled by default. The forwarder keeps a copy of each data block in its in-memory wait queue until the indexer confirms it has written the data to disk. If no acknowledgment arrives (the indexer goes down, its disk is full, or the network drops), the forwarder resends the block, to the next indexer when load balancing is used. This protects data in flight, though a resend after a lost ACK can create duplicates. During a forwarder shutdown it waits up to ackTimeoutOnShutdown (30 s) for outstanding ACKs. compressed, autoLBFrequency and sendCookedData = false do not protect against data loss.

  3. Question 3

    A large retail company is using a 5-node Search Head Cluster (SHC). During a major holiday sale, users report that dashboards are intermittently failing to load and saved searches are being skipped. A review of splunkd.log on the SHC members reveals messages related to KV Store contention and replication failures. The consultant suspects that a high frequency of lookups and summary updates from multiple apps are overwhelming the KV Store. Which of the following actions represents a robust, long-term solution to this problem?

    Answer and explanation

    Correct answer: D

    In a search head cluster every KV store write is delegated to the KV store captain, while reads stay local. Write-heavy apps therefore load one KV store that the whole cluster shares, and adding members does not spread that write load. Moving the apps with heavy KV store use to their own, smaller search head cluster gives them a separate KV store and removes their contention from the primary cluster. Moving high-write lookups to CSV goes against Splunk guidance: CSV lookups suit files that are small or rarely modified and need a full rewrite for every edit, while KV store lookups suit large or frequently updated tables. splunk clean kvstore deletes KV store data and is meant for resynchronization or restore, and search concurrency settings do not address KV store contention.

  4. Question 4

    A consultant is optimizing search performance. They have identified several inefficient searches that use join with a large result set. They plan to replace these with the stats command. Which of the following is a primary advantage of using stats over join for correlating data from multiple sourcetypes?

    Answer and explanation

    Correct answer: B

    Splunk recommends stats (or transaction) over join and append in most cases. The usual rewrite is one search that retrieves every sourcetype (for example sourcetype=a OR sourcetype=b) followed by stats ... by , so the events are fetched once and correlated in a single pass. join must run a separate subsearch, and by default only 50,000 right-side rows can be joined, within 60 seconds ([join] subsearch_maxout and subsearch_maxtime in limits.conf), so large correlations are truncated. stats is a transforming command, not a streaming one. Reading accelerated summaries is what tstats does, and stats outputs a results table, not _raw events.

  5. Question 5

    During a Splunk deployment, a client requires that data from their PCI-compliant systems be stored in a specific, encrypted index with a 365-day retention policy, while all other data goes to a general index with a 90-day retention. Both data types arrive on the same port of a Heavy Forwarder. What is the most appropriate method to route this data to the correct indexes?

    Answer and explanation

    Correct answer: C

    The correct way to route events to different indexes based on their content is at parse time on a Heavy Forwarder or on the Indexers. This is achieved by defining a stanza in props.conf that applies a TRANSFORMS- class. This class then points to a stanza in transforms.conf which uses a regular expression (REGEX) to match event patterns and sets the DEST_KEY to _MetaData:Index with the FORMAT set to the target index name (e.g., pci_index). This ensures events are written to the correct index upon arrival.

  6. Question 6

    A new Monitoring Console (MC) is being set up on a dedicated instance to monitor a large Splunk environment that includes a multisite indexer cluster. The cluster's peer nodes are not appearing in the MC dashboards, although the search heads, the cluster manager, and the license manager are. All instances can communicate with the MC instance, and firewall rules are correct. What is a likely cause for the missing indexers?

    Answer and explanation

    Correct answer: A

    The MC is a search head that gathers data by searching other instances. Most instances (search heads, deployment servers, the license manager, non-clustered indexers) are added to it as search peers, but the docs say: "Do not add clustered indexers." Instead, you add the cluster manager as a search peer and configure the MC instance as a search head of the indexer cluster, as a multisite search head when the cluster is multisite. The MC then reaches the cluster's peers through the cluster, the same way any cluster search head does. If that step is missed, the cluster's indexers are missing from the MC even though the other instances appear. There is no [mc_roles] stanza, and licenses do not restrict monitoring.

  7. Question 7

    True or False: In a multi-site indexer cluster, setting site=site0 in a peer's server.conf effectively makes that peer's data available to all sites, overriding any site-specific replication policies for that node.

    Answer and explanation

    Correct answer: B

    False. site0 is not a valid site for a peer node. According to server.conf, site0 can be set only on search heads or on forwarders that participate in indexer discovery. On a search head it disables search affinity; on an indexer-discovery forwarder it sends data to peers on all sites. Every peer must belong to a real site (site1 to site63) so that the manager can apply the site replication and search factors.

  8. Question 8

    A consultant needs to configure a universal forwarder to send different log sources to two separate indexer clusters: one for security data (sec_cluster) and one for operations data (ops_cluster). How should outputs.conf be configured on the universal forwarder to achieve this?

    Answer and explanation

    Correct answer: D

    Define one target group per destination in outputs.conf (for example [tcpout:sec_cluster] and [tcpout:ops_cluster], each with its server list). Then set _TCP_ROUTING = in each input stanza of inputs.conf, so security inputs go to sec_cluster and operations inputs go to ops_cluster. A universal forwarder can route by data input this way. Event-based routing through props.conf/transforms.conf works only on a heavy forwarder.

  9. Question 9

    A client's Splunk Enterprise environment is integrated with SAML for single sign-on. A small group of emergency administrators must be able to log in to Splunk Web with local Splunk credentials if the SAML identity provider is unavailable. What must the consultant do to provide this?

    Answer and explanation

    Correct answer: A

    No extra setting is needed. Native Splunk authentication always takes precedence over external schemes, so native accounts keep working while SAML is enabled. To bypass the SAML redirect, the administrators browse to https:// : /en-US/account/login?loginType=splunk and sign in with their local credentials. This works even when the IdP is unreachable. authentication.conf has no "fallback" setting, authType accepts only one value, and [roleMap_SAML] maps IdP groups to roles; it does not enable local login.

  10. Question 10

    A deployment server manages over 1,000 universal forwarders. A previous administrator throttled app downloads, and app rollouts now take a very long time even though the server has ample CPU, memory and network bandwidth. Which serverclass.conf setting controls how many deployment clients can download app bundles from the deployment server at the same time?

    Answer and explanation

    Correct answer: A

    maxConcurrentDownloads in the [global] stanza of serverclass.conf sets the maximum number of deployment clients that can download app bundles from the deployment server at the same time. A client that is refused retries at its next phone home. The default 0 means no limit, so raising the throttled value (or resetting it to 0) lets more forwarders download at once. phoneHomeIntervalInSecs is a client-side deploymentclient.conf setting. crossServerChecksum keeps app checksums consistent across several deployment servers behind a load balancer. restartSplunkd only controls whether clients restart after an app update.

Register free to unlock 10 more sample questions

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 242 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon