Sign In
Home/Splunk/SPLK-2001/Free questions

SPLK-2001 — Free Practice Questions

10 free sample questions from a bank of 105, with the correct answers and explanations. No signup required — start practising right now.

1Suppose the following query in a Simple XML dashboard returns a table including hyperlinks: index news sourcetype web_proxy | table sourcetype title link Which of the following is a valid dynamic drilldown element to allow a user of the dashboard to visit the hyperlinks contained in the link field?
  • $row.link$
  • $$row.link$$
  • $row.link|n$
  • http://localhost:8000/debug/refresh
Answer: A
2Which of the following options would be the best way to identify processor bottlenecks of a search?
  • Using the REST API.
  • Using the search job inspector.
  • Using the Splunk Monitoring Console.
  • Searching the Splunk logs using index=ג€ internalג€.
Answer: C
3Which of the following is true of a namespace?
  • The namespace is a type of token filter.
  • The namespace includes an app attribute which cannot be a wildcard.
  • The namespace filters the knowledge objects returned by the REST API.
  • The namespace does not filter knowledge objects returned by the REST API.
Answer: D
4What must be done when calling the serviceNS endpoint?
  • Authenticate with an admin user.
  • Specify the user and app context in the URI.
  • Authenticate with the user of the required context.
  • Pass the user and app context in the request payload.
Answer: B
5Assuming permissions are set appropriately, which REST endpoint path can be used by someone with a power user role to access information about mySearch, a saved search owned by someone with a user role?
  • /servicesNS/-/data/saved/searches/mySearch
  • /servicesNS/object/saved/searches/mySearch
  • /servicesNS/search/saved/searches/mySearch
  • /servicesNS/-/search/saved/searches/mySearch
Answer: D
6Using Splunk Web to modify config settings for a shared object, a revised config file with those changes is placed in which directory?
  • $SPLUNK_HOME/etc/apps/myApp/local
  • $SPLUNK_HOME/etc/system/default/
  • $SPLUNK_HOME/etc/system/local
  • $SPLUNK_HOME/etc/apps/myApp/default
Answer: A
7What application security best practices should be adhered to while developing an app for Splunk? (Select all that apply.)
  • Review the OWASP Top Ten List.
  • Store passwords in clear text in .conf files.
  • Review the OWASP Secure Coding Practices Quick Reference Guide.
  • Ensure that third-party libraries that the app depends on have no outstanding CVE vulnerabilities.
Answer: A, C
8There is a global search named global_search defined on a form as shown below: index-_internal source-*splunkd.log | stats count by component, log_level Which of the following would be a valid post-processing search? (Select all that apply.)
  • | tstats count
  • sourcetype=mysourcetype
  • stats sum(count) AS count by log level
  • search log_level=error | stats sum(count) AS count by component
Answer: C, D
9In order to successfully accelerate a report, which criteria must the search meet? (Select all that apply.)
  • Cannot use event sampling.
  • Use a transforming command.
  • Use a standard Splunk visualization.
  • Commands before the first transforming command must be streamable.
Answer: A, B, D
10Which statements are true regarding HEC (HTTP Event Collector) tokens? (Select all that apply.)
  • Multiple tokens can be created for use with different sourcetypes and indexes.
  • The edit token http admin role capability is required to create a token.
  • To create a token, send a POST request to services/collector endpoint.
  • Tokens can be edited using the data/inputs/http/{tokenName} endpoint.
Answer: A, C

Want the full bank of 105 questions for SPLK-2001? See all practice exams.