Limited-Time Offer: Enjoy 50% Savings! Ends in 00h 00m 00s Coupon code: 50OFF
Skip to content

Free Splunk Enterprise Certified Admin SPLK-1003 Exam Questions

Page: 1 / 6 Total 60 questions

Want more questions? Get Premium Access.

Question 1

Which optional configuration setting in inputs .conf allows you to selectively forward the data to specific indexer(s)?

Correct Answer: A. _TCP_ROUTING
Explanation:

https://docs.splunk.com/Documentation/Splunk/7.0.3/Forwarding/Routeandfilterdatad#Perform_selective_indexing_and_forwarding

Specifies a comma-separated list of tcpout group names. Use this setting to selectively forward your data to specific indexers by specifying the tcpout groups that the forwarder should use when forwarding the data. Define the tcpout group names in the outputs.conf file in [tcpout:<tcpout_group_name>] stanzas. The groups present in defaultGroup in [tcpout] stanza in the outputs.conf file.


Question 2

Which of the following Splunk components require a separate installation package?

Correct Answer: C. Universal forwarder
Explanation:

The Splunk component that requires a separate installation package is the universal forwarder. The universal forwarder is a lightweight Splunk agent that forwards data to indexers or other forwarders. The universal forwarder has a different installation package than the Splunk Enterprise package, which includes all the other Splunk components. Therefore, option C is the correct answer. Reference:Splunk Enterprise Certified Admin | Splunk, [About installing Splunk Enterprise with a universal forwarder - Splunk Documentation]

Question 3

Where are deployment server apps mapped to clients?

Correct Answer: C. Server Classes tab in forwarder management interface or serverclass.conf.
Explanation:

Updateconfigurations#2._Reload_the_deployment_server

https://docs.splunk.com/Documentation/Splunk/8.0.5/Updating/Useserverclass.conf

'Use serverclass.conf to define server classes' 'The most important settings define the set of deployment clients and the set of apps for each server class.'

Question 4

UsingSEDCMDinprops.confallows raw data to be modified. With the given event below, which option will mask the first three digits of theAcctIDfield resulting output:[22/Oct/2018:15:50:21] VendorID=1234 Code=B AcctID=xxx5309

Event:

[22/Oct/2018:15:50:21] VendorID=1234 Code=B AcctID=xxx5309

Correct Answer: D. SEDCMD-1acct = s/AcctID=\d{3}(\d{4})/AcctID=xxx\1/g
Explanation:

https://docs.splunk.com/Documentation/Splunk/8.2.2/Data/Anonymizedata

Scrolling down to the section titled 'Define the sed script in props.conf shows the correct syntax of an example which validates that the number/character /1 immediately preceded the /g


Question 5

A configuration file in a deployed app needs to be directly edited. Which steps would ensure a successful deployment to clients?

Correct Answer: C. Make the change in $SPLUNK HOME/etc/dep10yment apps/$appName/10ca1/ on the deployment server, and then run $SPLUNK HOME/bin/sp1unk reload deploy---server.
Explanation:

According to the Splunk documentation1, to customize a configuration file, you need to create a new file with the same name in a local or app directory. Then, add the specific settings that you want to customize to the local configuration file. Never change or copy the configuration files in the default directory. The files in the default directory must remain intact and in their original location. The Splunk Enterprise upgrade process overwrites the default directory.

To deploy configuration files to deployment clients, you need to use the deployment server.The deployment server is a Splunk Enterprise instance that distributes content and updates to deployment clients2.The deployment server uses a directory called $SPLUNK_HOME/etc/deployment-apps to store the apps and configuration files that itdeploys to clients2.To update the configuration files in this directory, you need to edit them manually and then run the command $SPLUNK_HOME/bin/sp1unk reload deploy---server to make the changes take effect2.

Therefore, option A is incorrect because it does not include the reload command. Option B is incorrect because it makes the change on a deployment client instead of the deployment server. Option D is incorrect because it changes the default directory instead of the local directory.


Question 6

When are knowledge bundles distributed to search peers?

Correct Answer: D. When a distributed search is initiated.
Explanation:

'The search head replicates the knowledge bundle periodically in the background or when initiating a search. ' 'As part of the distributed search process, the search head replicates and distributes its knowledge objects to its search peers, or indexers. Knowledge objects include saved searches, event types, and other entities used in searching accorss indexes. The search head needs to distribute this material to its search peers so that they can properly execute queries on its behalf.'


Question 7

What are the required stanza attributes when configuring the transforms. conf to manipulate or remove events?

Correct Answer: C. REGEX, DEST_KEY, FORMAT
Explanation:

REGEX = <regular expression>

* Enter a regular expression to operate on your data.

FORMAT = <string>

* NOTE: This option is valid for both index-time and search-time field extraction. Index-time field extraction configuration require the FORMAT settings. The FORMAT settings is optional for search-time field extraction configurations.

* This setting specifies the format of the event, including any field names or values you want to add.

DEST_KEY = <key>

* NOTE: This setting is only valid for index-time field extractions.

* Specifies where SPLUNK software stores the expanded FORMAT results in accordance with the REGEX match.


Question 8

How would you configure your distsearch conf to allow you to run the search below? sourcetype=access_combined status=200 action=purchase splunk_setver_group=HOUSTON

A)

B)

C)

D)

Correct Answer: C. Option C
Explanation:

https://docs.splunk.com/Documentation/Splunk/8.0.3/DistSearch/Distributedsearchgroups


Question 9

TheLINE_BREAKERattribute is configured in which configuration file?

Correct Answer: A. props.conf

Question 10

Which of the methods listed below supports muti-factor authentication?

Correct Answer: B. Security Assertion Markup Language (SAML)
Explanation:

SAML is an open standard for exchanging authentication and authorization data between parties, especially between an identity provider and a service provider1.SAML supports multi-factor authentication by allowing the identity provider to require the user to present two or more factors of evidence to prove their identity2. For example, the user may need to enter a password and a one-time code sent to their phone, or scan their fingerprint and face.