Free SPLK-1003 Exam Braindumps

Pass your Splunk Enterprise Certified Admin exam with these free Questions and Answers

Page 3 of 28
QUESTION 6

Which layers are involved in Splunk configuration file layering? (Select all that apply.)

  1. A. App context
  2. B. User context
  3. C. Global context
  4. D. Forwarder context

Correct Answer: AC
Reference: https://docs.splunk.com/Documentation/Splunk/7.3.1/Admin/Wheretofindtheconfigurationfiles

QUESTION 7

What are the minimum required settings when creating a network input in Splunk?

  1. A. Protocol, port number
  2. B. Protocol, port, location
  3. C. Protocol, username, port
  4. D. Protocol, IP, port number

Correct Answer: A
Reference: https://docs.splunk.com/Documentation/Splunk/7.3.1/Data/UsetheHTTPEventCollector

QUESTION 8

How does the Monitoring Console monitor forwarders?

  1. A. By pulling internal logs from forwarders.
  2. B. By using the forwarder monitoring add-on.
  3. C. With internal logs forwarded by forwarders.
  4. D. With internal logs forwarder by deployment server.

Correct Answer: A

QUESTION 9

With authentication methods are natively supported within Splunk Enterprise? (Select all that apply.)

  1. A. LDAP
  2. B. SAML
  3. C. RADIUS
  4. D. Duo Multifactor Authentication

Correct Answer: AD
Reference: https://docs.splunk.com/Documentation/Splunk/7.3.1/Security/SetupuserauthenticationwithSplunk

QUESTION 10

Within props.conf, which stanzas are valid for data modification? (Select all that apply.)

  1. A. Host
  2. B. Server
  3. C. Source
  4. D. Sourcetype

Correct Answer: CD
Reference: https://answers.splunk.com/answers/3687/host-stanza-in-props-conf-not-being-honored-for-udp-514-data-sources.html

Page 3 of 28

Post your Comments and Discuss Splunk SPLK-1003 exam with other Community members: