Practice Free SPLK-1001 Exam Online Questions
Question #61
Data sources being opened and read applies to:
- A . None of the above
- B . Indexing Phase
- C . Parsing Phase
- D . Input Phase
- E . License Metering
Question #62
According to Splunk best practices, which placement of the wildcard results in the most efficient search?
- A . f*il
- B . *fail
- C . fail*
- D . *fail*
Question #63
Which search string is the most efficient?
- A . "failed password"
- B . ”failed password"*
- C . index=* "failed password"
- D . index=security "failed password"
Question #64
A collection of items containing things such as data inputs, UI elements, and knowledge objects is known as what?
- A . An app
- B . JSON
- C . A role
- D . An enhanced solution
Question #65
Monitor option in Add Data provides _______________.
- A . Only continuous monitoring.
- B . Only One-time monitoring.
- C . None of the above.
- D . Both One-time and continuous monitoring
Question #66
Splunk Components:
Which of the following are responsible for parsing incoming data and storing data on disc?
- A . forwarders
- B . indexers
- C . search heads
Question #67
Which of the following are not true about lookups? (Select all that apply.)
- A . Lookups can be time based
- B . Search results can be used to populate a lookup table
- C . Splunk DB Connect can be used to populate a lookup table from relational databases
- D . Output from a script can be used to populate a lookup table
- E . Lookup have a 10mg maximum size limit
Question #68
Query – status != 100:
- A . Will return event where status field exist but value of that field is not 100.
- B . Will return event where status field exist but value of that field is not 100 and all events where status field doesn’t exist.
- C . Will get different results depending on data
Question #69
What is one benefit of creating dashboard panels from reports?
- A . Any newly created dashboard will include that report.
- B . There are no benefits to creating dashboard panels from reports.
- C . It makes the dashboard more efficient because it only has to run one search string.
- D . Any change to the underlying report will affect every dashboard that utilizes that report.
Question #70
Which of the following are Splunk premium enhanced solutions? (Choose three.)
- A . Splunk User Behavior Analytics (UBA)
- B . Splunk IT Service Intelligence (ITSI)
- C . Splunk Enterprise Security (ES)
- D . Splunk Analytics Security (AS)