Prepare Top Splunk SPLK-1001 Exam Study Guide Practice Questions Edition [Q68-Q90]

Share

Prepare Top Splunk SPLK-1001 Exam Study Guide Practice Questions Edition

Go to SPLK-1001 Questions - Try SPLK-1001 dumps pdf 


What to Know Before Sitting for This Exam?

There are no certain prerequisites for taking SPLK-1001 test but the vendor recommends that the entrants attend the Splunk Fundamentals 1 training first to get ready for their exams and gain all the required knowledge & skills. Through the Fundamentals 1 course, students will cover quizzes, lectures, and hands-on labs that are part of the professional training path to ensure they are better prepared to face the final test.

 

NEW QUESTION 68
Uploading local files though Upload options index the file only once.

  • A. Yes
  • B. No

Answer: A

 

NEW QUESTION 69
What can be configured using the Edit Job Settings menu?

  • A. Change Job Lifetime from 10 minutes to 7 days.
  • B. Schedule the Job to re-run in 10 minutes
  • C. Add the Job results to a dashboard
  • D. Export the results to CSV format

Answer: A

 

NEW QUESTION 70
Which of the following statements describes a search job?

  • A. A search job can only be paused when less than 50% of events are returned
  • B. A search job can only be stopped when less than 50% of events are returned
  • C. Once a search job begins, it cannot be stopped
  • D. Once a search job begins, it can be stopped or paused at any point in time

Answer: D

 

NEW QUESTION 71
Which search string returns a filed containing the number of matching events and names that field Event Count?

  • A. index=security failure | stats dc(count) as "Event Count"
  • B. index=security failure | stats count as "Event Count"
  • C. index=security failure | stats sum as "Event Count"
  • D. index=security failure | stats count by "Event Count"

Answer: C

 

NEW QUESTION 72
How can results from a specified static lookup file be displayed?

  • A. Settings > Lookups > Upload
  • B. lookup command
  • C. inputlookup command
  • D. Settings > Lookups > Input

Answer: C

 

NEW QUESTION 73
Lookups allow you to overwrite your raw event.

  • A. True
  • B. False

Answer: A

 

NEW QUESTION 74
What is a quick, comprehensive way to learn what data is present in a Splunk deployment?

  • A. Search index=* sourcetype=* host=*
  • B. Click Data Summary in Splunk Web
  • C. Review Splunk reports
  • D. Run ./splunk show

Answer: B

 

NEW QUESTION 75
Following are the time selection option while making search:
(Choose all that apply.)

  • A. Presets
  • B. Date & Time Range
  • C. Relative
  • D. Date Range
  • E. Advanced

Answer: A,B,C,D,E

 

NEW QUESTION 76
When looking at a dashboard panel that is based on a report, which of the following is true'?

  • A. You can modify the search string in the panel but you cannot change and configure the visualization
  • B. You can modify the search string in the panel and you can change and configure the visualization
  • C. You cannot modify the search string in the panel, and you cannot change and configure the visualization
  • D. You cannot modify the search string in the panel, but you can change and configure the visualization

Answer: D

 

NEW QUESTION 77
Clicking a SEGMENT on a chart, ________.

  • A. adds the highlighted value to the search criteria
  • B. drills down for that value
  • C. highlights the field value across the chart

Answer: A

 

NEW QUESTION 78
In automatic lookup definitions, the _____ fields are those that are not in the event data.

  • A. input
  • B. output

Answer: B

 

NEW QUESTION 79
Which search will return the 15 least common field values for the dest_ipfield?

  • A. sourcetype=firewall | rare limit=15 dest_ip
  • B. sourcetype=firewall | rare num=15 dest_ip
  • C. sourcetype=firewall | rare last=15 dest_ip
  • D. sourcetype=firewall | rare count=15 dest_ip

Answer: D

Explanation:
Explanation/Reference: https://answers.splunk.com/answers/41928/add-a-lookup-csv-colum-information-to-the-results-of- a-inputlookup-search.html

 

NEW QUESTION 80
How can search results be kept longer than 7 days?

  • A. By scheduling a report.
  • B. By changing the job settings.
  • C. By creating a link to the job.
  • D. By changing the time range picker to more than 7 days.

Answer: B

 

NEW QUESTION 81
It is mandatory for the lookup file to have this for an automatic lookup to work.

  • A. Input filed
  • B. Timestamp
  • C. Source type
  • D. At least five columns

Answer: A

 

NEW QUESTION 82
What is Splunk?

  • A. Security Information and Event Management (SIEM).
  • B. Splunk is a software platform to search, analyze and visualize the machine-generated data.
  • C. Cloud based application that help in analyzing logs.
  • D. Database management tool.

Answer: B

 

NEW QUESTION 83
Which is a primary function of the timeline located under the search bar?

  • A. To sort the events returned by the search command in chronological order
  • B. To differentiate between structured and unstructured events in the data
  • C. To zoom in and zoom out. although this does not change the scale of the chart
  • D. To show peaks and/or valleys in the timeline, which can indicate spikes in activity or downtime

Answer: D

 

NEW QUESTION 84
Which is a primary function of the timeline located under the search bar?

  • A. To sort the events returned by the search command in chronological order
  • B. To show peaks and/or valleys in the timeline, which can indicate spikes in activity or downtime
  • C. To zoom in and zoom out. although this does not change the scale of the chart
  • D. To differentiate between structured and unstructured events in the data

Answer: C

 

NEW QUESTION 85
Which search will return the 15 least common field values for the dest_ip field?

  • A. sourcetype=firewall | rare limit=15 dest_ip
  • B. sourcetype=firewall | rare num=15 dest_ip
  • C. sourcetype=firewall | rare last=15 dest_ip
  • D. sourcetype=firewall | rare count=15 dest_ip

Answer: D

 

NEW QUESTION 86
Following are the time selection option while making search:
(Choose all that apply.)

  • A. Date & Time Range
  • B. Relative
  • C. Date Range
  • D. Advanced
  • E. Presets

Answer: D

 

NEW QUESTION 87
Splunk extracts fields from event data at index time and at search time.

  • A. True
  • B. False

Answer: A

Explanation:
Explanation/Reference: https://docs.splunk.com/Documentation/Splunk/7.2.3/SearchTutorial/Usefieldstosearch

 

NEW QUESTION 88
Which search string matches only events with the status_code of 4:4?

  • A. status_code>=400
  • B. status_code !=404
  • C. status_code<=404
  • D. status code>403 status_code<405

Answer: C

 

NEW QUESTION 89
How are events displayed after a search is executed?

  • A. Randomly by default.
  • B. In chronological order.
  • C. In reverse chronological order.
  • D. Alphabetically according to field name.

Answer: B

 

NEW QUESTION 90
......


Splunk SPLK-1001 Exam Syllabus Topics:

TopicDetails
Topic 1
  • Using Basic Transforming Commands
  • The Top Command
  • The Rare Command, The Stats Command
Topic 2
  • Splunk Components
  • Understand the Uses of Splunk
  • Define Splunk Apps
  • Customizing User Settings
  • Basic Navigation in Splunk
Topic 3
  • Creating and Using Lookups
  • Describe Lookups
  • Examine a Lookup File Example
  • Create a Lookup File and Create a Lookup Definition
  • Configure an Automatic Lookup
Topic 4
  • Specify Indexes in Searches
  • Use the Following Commands to Perform Searches: Tables, Rename, Fields, Dedup, & Sort
Topic 5
  • Work with Events
  • Control a Search Job
  • Save Search Results
Topic 6
  • Run Basic Searches
  • Set the Time Range of a Search
  • Identify the Contents of Search Results
  • Refine Searches
  • Use the Timeline
Topic 7
  • Search Language Fundamentals
  • Review Basic Search Commands and General Search Practices
  • Examine the Search Pipeline

 

Free Splunk Core Certified User SPLK-1001 Exam Question: https://www.pass4surecert.com/Splunk/SPLK-1001-practice-exam-dumps.html

Dumps Practice Exam Questions Study Guide for the SPLK-1001 Exam: https://drive.google.com/open?id=1_L2PvGJ78jL2RUaQ8ahNjj3lwgD-hzjU