Labour Day Special Limited Time Flat 70% Discount offer - Ends in 0d 00h 00m 00s - Coupon code: 70spcl

Splunk SPLK-1001 Splunk Core Certified User Exam Exam Practice Test

Page: 1 / 24
Total 244 questions

Splunk Core Certified User Exam Questions and Answers

Question 1

Interesting fields are the fields that have at least 20% of resulting fields.

Options:

A.

True

B.

False

Question 2

This function of the stats command allows you to return the middle-most value of field X.

Options:

A.

Median(X)

B.

Eval by X

C.

Fields(X)

D.

Values(X)

Question 3

Uploading local files though Upload options index the file only once.

Options:

A.

No

B.

Yes

Question 4

What is the correct order of steps for creating a new lookup?

1. Configure the lookup to run automatically

2. Create the lookup table

3. Define the lookup

Options:

A.

2, 1, 3

B.

1, 2, 3

C.

2, 3, 1

D.

3, 2, 1

Question 5

How many minutes, by default, is the time to live (ttl) for an ad-hoc search job?

Options:

A.

5 minutes

B.

1 minute

C.

10 minutes

D.

60 minutes

Question 6

What is the primary use for the rare command1?

Options:

A.

To sort field values in descending order

B.

To return only fields containing five or fewer values

C.

To find the least common values of a field in a dataset

D.

To find the fields with the fewest number of values across a dataset

Question 7

Which of the following is a metadata field assigned to every event in Splunk?

Options:

A.

host

B.

owner

C.

bytes

D.

action

Question 8

In the fields sidebar, which character denotes alphanumeric field values?

Options:

A.

#

B.

%

C.

a

D.

a#

Question 9

How are events displayed after a search is executed?

Options:

A.

In chronological order.

B.

Randomly by default.

C.

In reverse chronological order.

D.

Alphabetically according to field name.

Question 10

It is no possible for a single instance of Splunk to manage the input, parsing and indexing of machine data.

Options:

A.

True

B.

False

Question 11

Which statement is true about Splunk alerts?

Options:

A.

Alerts are based on searches that are either run on a scheduled interval or in real-time.

B.

Alerts are based on searches and when triggered will only send an email notification.

C.

Alerts are based on searches and require cron to run on scheduled interval.

D.

Alerts are based on searches that are run exclusively as real-time.

Question 12

What can be configured using the Edit Job Settings menu?

Options:

A.

Export the results to CSV format

B.

Add the Job results to a dashboard

C.

Schedule the Job to re-run in 10 minutes

D.

Change Job Lifetime from 10 minutes to 7 days.

Question 13

Which events will be returned by the following search string?

host=www3 status=503

Options:

A.

All events that either have a host of www3 or a status of 503.

B.

All events with a host of www3 that also have a status of 503

C.

We need more information: we cannot tell without knowing the time range

D.

We need more information a search cannot be run without specifying an index

Question 14

What are Splunk alerts based on?

Options:

A.

Dashboards

B.

Searches

C.

Webhooks

D.

Reports

Question 15

What syntax is used to link key/value pairs in search strings?

Options:

A.

Parentheses

B.

@ or # symbols

C.

Quotation marks

D.

Relational operators such as =, <, or >

Question 16

What is the result of the following search?

index=myindex source=c: \mydata. txt NOT error=*

Options:

A.

Only data where the error field is present and does not contain a value will be displayed.

B.

Only data with a value in the field error will be displayed.

C.

Only data that does not contain the error field will be displayed.

D.

Only data where the value of the field error does not equal an asterisk (*) will be displayed.

Question 17

Which of the following are not true about lookups? (Select all that apply.)

Options:

A.

Lookups can be time based

B.

Search results can be used to populate a lookup table

C.

Splunk DB Connect can be used to populate a lookup table from relational databases

D.

Output from a script can be used to populate a lookup table

E.

Lookup have a 10mg maximum size limit

Question 18

What is one benefit of creating dashboard panels from reports?

Options:

A.

Any newly created dashboard will include that report.

B.

There are no benefits to creating dashboard panels from reports.

C.

It makes the dashboard more efficient because it only has to run one search string.

D.

Any change to the underlying report will affect every dashboard that utilizes that report.

Question 19

Events in Splunk are automatically segregated using data and time.

Options:

A.

Yes

B.

No

Question 20

You can view the search result in following format (Choose three.):

Options:

A.

Table

B.

Raw

C.

Pie Chart

D.

List

Question 21

Which Boolean operator is always implied between two search terms, unless otherwise specified?

Options:

A.

OR

B.

NOT

C.

AND

D.

XOR

Question 22

Which of the following are common constraints of the top command?

Options:

A.

limit, count

B.

limit, showpercent

C.

limits, countfield

D.

showperc, countfield

Question 23

Data summary button just below the search bar gives you the following (Choose three.):

Options:

A.

Hosts

B.

Sourcetypes

C.

Sources

D.

Indexes

Question 24

Can you stop or pause the searching?

Options:

A.

No

B.

Yes

Question 25

All components are installed and administered in Splunk Enterprise on-premise.

Options:

A.

True

B.

False

Question 26

What is the correct way to use a time range specifier in the search bar so that the search looks back 2 hours?

Options:

A.

latest=-2h

B.

earliest=-2h

C.

latest=-2hour@d

D.

earliest=-2hour@d

Question 27

Creating Data Models:

Object ATTRIBUTES do not define ___________.

Options:

A.

a base search for the object

B.

fields for the object

Question 28

By default, which of the following fields would be listed in the fields sidebar under interesting Fields?

Options:

A.

host

B.

index

C.

source

D.

sourcetype

Question 29

Fields are searchable key value pairs in your event data.

Options:

A.

True

B.

False

Question 30

Which Field/Value pair will return only events found in the index named security?

Options:

A.

index!=Security

B.

Index-security

C.

Index=Security

D.

index=Security

Question 31

Which symbol is used to snap the time?

Options:

A.

@

B.

&

C.

*

D.

#

Question 32

Which of the following searches would return events with failure in index netfw or warn or critical in index netops?

Options:

A.

(index=netfw failure) AND index=netops warn OR critical

B.

(index=netfw failure) OR (index=netops (warn OR critical))

C.

(index=netfw failure) AND (index=netops (warn OR critical))

D.

(index=netfw failure) OR index=netops OR (warn OR critical)

Question 33

Which of the statements is correct regarding click and drag option in timeline?

Options:

A.

The new result after selecting the range by dragging filters the events and displays the most recent first.

B.

There is no functionality like click and drag in Splunk's timeline.

C.

Using this option executes a new query.

D.

This doesn't execute a new query

Question 34

Which is not a comparison operator in Splunk

Options:

A.

<=

B.

=

C.

!=

D.

>

E.

?=

Question 35

@ Symbol can be used in advanced time unit option.

Options:

A.

No

B.

Yes

Question 36

When saving a search directly to a dashboard panel instead of saving as a report first, which of the following is

created?

Options:

A.

Cloned panel

B.

Inline panel

C.

Report panel

D.

Prebuilt panel

Question 37

What happens when a field is added to the Selected Fields list in the fields sidebar'?

Options:

A.

Splunk will re-run the search job in Verbose Mode to prioritize the new Selected Field

B.

Splunk will highlight related fields as a suggestion to add them to the Selected Fields list.

C.

Custom selections will replace the Interesting Fields that Splunk populated into the list at search time

D.

The selected field and its corresponding values will appear underneath the events in the search results

Question 38

How many main user roles do you have in Splunk?

Options:

A.

2

B.

4

C.

1

D.

3

Question 39

Which of the following is the most efficient search?

Options:

A.

index=* “failed password”

B.

“failed password” index=*

C.

(index=* OR index=security) “failed password”

D.

index=security “failed password”

Question 40

Splunk shows data in __________________.

Options:

A.

ASCII Character order.

B.

Reverse chronological order.

C.

Alphanumeric order.

D.

Chronological order.

Question 41

Which of the following is true about user account settings and preferences?

Options:

A.

Search & Reporting is the only app that can be set as the default application.

B.

Full names can only be changed by accounts with a Power User or Admin role.

C.

Time zones are automatically updated based on the setting of the computer accessing Splunk.

D.

Full name, time zone, and default app can be defined by clicking the login name in the Splunk bar.

Question 42

Which of the following is the best way to create a report that shows the last 24 hours of events?

Options:

A.

Use earliest=-1d@d latest=@d

B.

Set a real-time search over a 24-hour window

C.

Use the time range picket to select “Yesterday”

D.

Use the time range picker to select “Last 24 hours”

Question 43

In a deployment with multiple indexes, what will happen when a search is run and an index is not specified in the search string?

Options:

A.

No events will be returned.

B.

Splunk will prompt you to specify an index.

C.

All non-indexed events to which the user has access will be returned.

D.

Events from every index searched by default to which the user has access will be returned.

Question 44

What does the rare command do?

Options:

A.

Returns the least common field values of a given field in the results.

B.

Returns the most common field values of a given field in the results.

C.

Returns the top 10 field values of a given field in the results.

D.

Returns the lowest 10 field values of a given field in the results.

Question 45

!= and NOT are same arguments.

Options:

A.

True

B.

False

Question 46

It is not possible for a single instance of Splunk to manage the input, parsing and indexing of machine.

Options:

A.

True

B.

False

Question 47

What kind of logs can Splunk Index?

Options:

A.

Only A, B

B.

Router and Switch Logs

C.

Firewall and Web Server Logs

D.

Only C

E.

Database logs

F.

All firewall, web server, database, router and switch logs

Question 48

In the Search and Reporting app, which tab displays timecharts and bar charts?

Options:

A.

Events

B.

Patterns

C.

Statistics

D.

Visualization

Question 49

By default search results are not returned in ________ order.

Options:

A.

Chronological

B.

Reverser chronological

C.

ASCIE

D.

Alphabetical

Question 50

These users can create global knowledge objects. (Select all that apply.)

Options:

A.

users

B.

power users

C.

administrators

Question 51

Put query into separate lines where | (Pipes) are used by selecting following options.

Options:

A.

CTRL + Enter

B.

Shift + Enter

C.

Space + Enter

D.

ALT + Enter

Question 52

The better way of writing search query for index is:

Options:

A.

index=a index=b

B.

(index=a OR index=b)

C.

index=(a & b)

D.

index = a, b

Question 53

There are three different search modes in Splunk (Choose three.):

Options:

A.

Automatic

B.

Smart

C.

Fast

D.

Verbose

Question 54

Splunk index time process can be broken down into __________ phases.

Options:

A.

3

B.

2

C.

4

D.

1

Question 55

The new data uploaded in Splunk are shown in ________________.

Options:

A.

Real-time

B.

10 Minutes

C.

Overnight Download

D.

30 Minutes

Question 56

Which of the following are functions of the stats command?

Options:

A.

count, sum, add

B.

count, sum, less

C.

sum, avg, values

D.

sum, values, table

Question 57

When is an alert triggered?

Options:

A.

When Splunk encounters a syntax error in a search

B.

When a trigger action meets the predefined conditions

C.

When an event in a search matches up with a data model

D.

When results of a search meet a specifically defined condition

Question 58

What is a suggested Splunk best practice for naming reports?

Options:

A.

Reports are best named using many numbers so they can be more easily sorted.

B.

Use a consistent naming convention so they are easily separated by characteristics such as group and object.

C.

Name reports as uniquely as possible with no overlap to differentiate them from one another.

D.

Any naming convention is fine as long as you keep an external spreadsheet to keep track.

Question 59

Which of the following constraints can be used with the top command?

Options:

A.

limit

B.

useperc

C.

addtotals

D.

fieldcount

Question 60

What is the primary use for the rare command?

Options:

A.

To sort field values in descending order.

B.

To return only fields containing five of fewer values.

C.

To find the least common values of a field in a dataset.

D.

To find the fields with the fewest number of values across a dataset.

Question 61

Selected fields are a set of configurable fields displayed for each event.

Options:

A.

True

B.

False

Question 62

Which of the following statements about case sensitivity is true?

Options:

A.

Both field names and field values ARE case sensitive.

B.

Field names ARE case sensitive; field values are NOT.

C.

Field values ARE case sensitive; field names ARE NOT.

D.

Both field names and field values ARE NOT case sensitive.

Question 63

Which Boolean operator is implied between search terms, unless otherwise specified?

Options:

A.

OR

B.

AND

C.

NOT

D.

NAND

Question 64

Which of the following Splunk components typically resides on the machines where data originates?

Options:

A.

Indexer

B.

Forwarder

C.

Search head

D.

Deployment server

Question 65

It is mandatory for the lookup file to have this for an automatic lookup to work.

Options:

A.

Source type

B.

At least five columns

C.

Timestamp

D.

Input filed

Question 66

Which of the following is an option after clicking an item in search results?

Options:

A.

Saving the item to a report

B.

Adding the item to the search.

C.

Adding the item to a dashboard

D.

Saving the search to a JSON file.

Question 67

Which is the default app for Splunk Enterprise?

Options:

A.

Splunk Enterprise Security Suite

B.

Searching and Reporting

C.

Reporting and Searching

D.

Splunk apps for Security

Question 68

What must be done in order to use a lookup table in Splunk?

Options:

A.

The lookup must be configured to run automatically.

B.

The contents of the lookup file must be copied and pasted into the search bar.

C.

The lookup file must be uploaded to Splunk and a lookup definition must be created.

D.

The lookup file must be uploaded to the etc/apps/lookups folder for automatic ingestion.

Question 69

Splunk Components:

Which of the following are responsible for reducing search results?

Options:

A.

search heads

B.

indexers

C.

forwarders

Question 70

Select the statements that are true for timeline in Splunk (Choose four.):

Options:

A.

Timeline shows distribution of events specified in the time range in the form of bars.

B.

Single click to see the result for particular time period.

C.

You can click and drag across the bar for selecting the range.

D.

This is default view and you can't make any changes to it.

E.

You can hover your mouse for details like total events, time and date.

Question 71

Matching of parentheses is a feature of Splunk Assistant.

Options:

A.

No

B.

Yes

Question 72

In monitor option you can select the following options in GUI.

Options:

A.

Only HTTP Event Collector (HEC) and TCP/UDP

B.

None of the above

C.

Only TCP/UDP

D.

Only Scripts

E.

Filed & Directories, HTTP Event Collector (HEC), TCP/UDP and Scripts

Question 73

Search Assistant is enabled by default in the SPL editor with compact settings.

Options:

A.

No

B.

Yes

Page: 1 / 24
Total 244 questions