10 free sample questions from a bank of 105, with the correct answers and explanations. No signup required — start practising right now.
1Suppose the following query in a Simple XML dashboard returns a table including hyperlinks:
index news sourcetype web_proxy | table sourcetype title link
Which of the following is a valid dynamic drilldown element to allow a user of the dashboard to visit the hyperlinks contained in the link field?
$row.link$
$$row.link$$
$row.link|n$
http://localhost:8000/debug/refresh
Answer: A
2Which of the following options would be the best way to identify processor bottlenecks of a search?
Using the REST API.
Using the search job inspector.
Using the Splunk Monitoring Console.
Searching the Splunk logs using index=ג€ internalג€.
Answer: C
3Which of the following is true of a namespace?
The namespace is a type of token filter.
The namespace includes an app attribute which cannot be a wildcard.
The namespace filters the knowledge objects returned by the REST API.
The namespace does not filter knowledge objects returned by the REST API.
Answer: D
4What must be done when calling the serviceNS endpoint?
Authenticate with an admin user.
Specify the user and app context in the URI.
Authenticate with the user of the required context.
Pass the user and app context in the request payload.
Answer: B
5Assuming permissions are set appropriately, which REST endpoint path can be used by someone with a power user role to access information about mySearch, a saved search owned by someone with a user role?
/servicesNS/-/data/saved/searches/mySearch
/servicesNS/object/saved/searches/mySearch
/servicesNS/search/saved/searches/mySearch
/servicesNS/-/search/saved/searches/mySearch
Answer: D
6Using Splunk Web to modify config settings for a shared object, a revised config file with those changes is placed in which directory?
$SPLUNK_HOME/etc/apps/myApp/local
$SPLUNK_HOME/etc/system/default/
$SPLUNK_HOME/etc/system/local
$SPLUNK_HOME/etc/apps/myApp/default
Answer: A
7What application security best practices should be adhered to while developing an app for Splunk? (Select all that apply.)
Review the OWASP Top Ten List.
Store passwords in clear text in .conf files.
Review the OWASP Secure Coding Practices Quick Reference Guide.
Ensure that third-party libraries that the app depends on have no outstanding CVE vulnerabilities.
Answer: A, C
8There is a global search named global_search defined on a form as shown below:
index-_internal source-*splunkd.log | stats count by component, log_level
Which of the following would be a valid post-processing search? (Select all that apply.)
| tstats count
sourcetype=mysourcetype
stats sum(count) AS count by log level
search log_level=error | stats sum(count) AS count by component
Answer: C, D
9In order to successfully accelerate a report, which criteria must the search meet? (Select all that apply.)
Cannot use event sampling.
Use a transforming command.
Use a standard Splunk visualization.
Commands before the first transforming command must be streamable.
Answer: A, B, D
10Which statements are true regarding HEC (HTTP Event Collector) tokens? (Select all that apply.)
Multiple tokens can be created for use with different sourcetypes and indexes.
The edit token http admin role capability is required to create a token.
To create a token, send a POST request to services/collector endpoint.
Tokens can be edited using the data/inputs/http/{tokenName} endpoint.