SPLK-1005 Online Practice Questions

Home / Splunk / SPLK-1005

Latest SPLK-1005 Exam Practice Questions

The practice questions for SPLK-1005 exam was last updated on 2025-04-26 .

Viewing page 1 out of 5 pages.

Viewing questions 1 out of 28 questions.

Question#1

Which file or folder below is not a required part of a deployment app?

A. app.conf (in default or local)
B. local.meta
C. metadata folder
D. props.conf

Explanation:
When creating a deployment app in Splunk, certain files and folders are considered essential to ensure proper configuration and operation:
app.conf (in default or local): This is required as it defines the app's metadata and behaviors.
local.meta: This file is important for defining access permissions for the app and is often included. metadata folder: The metadata folder contains files like local.meta and default.meta and is typically required for defining permissions and other metadata-related settings.
props.conf: While props.conf is essential for many Splunk apps, it is not mandatory unless you need to define specific data parsing or transformation rules.
D. props.conf is the correct answer because, although it is commonly used, it is not a mandatory part of every deployment app. An app may not need data parsing configurations, and thus, props.conf might not be present in some apps.
Splunk Documentation
Reference: Building Splunk Apps
Deployment Apps
This confirms that props.conf is not a required part of a deployment app, making it the correct answer.

Question#2

What information is identified during the input phase of the ingestion process?

A. Line breaking and timestamp.
B. A hash of the message payload.
C. Metadata fields like sourcetype and host.
D. SRC and DST IP addresses and ports.

Explanation:
During the input phase, Splunk assigns metadata fields such as sourcetype, host, and source, which are critical for data categorization and routing. [Reference: Splunk Docs on data ingestion stages]

Question#3

Which configuration shown is used to enable a forwarder as a deployment client of the server 10.1.2.3?

A. [target-broker:deploymentServer] targetUri = 10.1.2.3:9997
B. [target-broker:deploymentserver] targetUri = 10.1.2.3:8089
C. [target-broker:deploymentserver] deploymentserver = 10.1.2.3:9997
D. [target-broker:deploymentserver] deploymentserver = 10.1.2.3:8089

Explanation:
For setting up a deployment client, the correct stanza syntax in inputs.conf includes specifying targetUri with the port 8089, which is the management port for Splunk instances, not the data port 9997. [Reference: Splunk Docs on deployment server configurations]

Question#4

In case of a Change Request, which of the following should submit a support case for Splunk Support?

A. The party requesting the change.
B. Certified Splunk Cloud administrator.
C. Splunk infrastructure owner.
D. Any person with the appropriate entitlement

Explanation:
In Splunk Cloud, when there is a need for a change request that might involve modifying settings, upgrading, or other actions requiring Splunk Support, the process typically requires submitting a support case.
D. Any person with the appropriate entitlement: This is the correct answer. Any individual who has the necessary permissions or entitlements within the Splunk environment can submit a support case.
This includes administrators or users who have been granted the ability to engage with Splunk Support. The request does not necessarily have to come from a Certified Splunk Cloud Administrator or the infrastructure owner; rather, it can be submitted by anyone with the correct level of access.
Splunk Documentation
Reference: Submitting a Splunk Support Case
Managing User Roles and Entitlements

Question#5

Which of the following tasks is the responsibility of a Splunk Cloud administrator?

A. Configuring deployer
B. Configuring cluster master
C. Configuring indexers
D. Configuring indexes

Explanation:
In Splunk Cloud, configuring indexes is one of the primary responsibilities of a Splunk Cloud administrator. This task includes setting up new indexes, managing retention policies, and configuring index settings as required by the organization's data retention and compliance policies. Other tasks like configuring deployer, cluster master, or indexers are typically handled by Splunk Enterprise administrators, not Splunk Cloud administrators.
Splunk Documentation
Reference: Splunk Cloud Administrator Guide

Exam Code: SPLK-1005Q & A: 80 Q&AsUpdated:  2025-04-26

 Get All SPLK-1005 Q&As