Download Splunk.SPLK-1003.BrainDumps.2019-09-16.28q.vcex

Download Exam

File Info

Exam Splunk Enterprise Certified Admin
Number SPLK-1003
File Name Splunk.SPLK-1003.BrainDumps.2019-09-16.28q.vcex
Size 18 KB
Posted Sep 16, 2019
Download Splunk.SPLK-1003.BrainDumps.2019-09-16.28q.vcex

How to open VCEX & EXAM Files?

Files with VCEX & EXAM extensions can be opened by ProfExam Simulator.

Purchase

Coupon: MASTEREXAM
With discount: 20%






Demo Questions

Question 1

Which parent directory contains the configuration files in Splunk? 


  1. $SPLUNK_HOME/etc
  2. $SPLUNK_HOME/var
  3. $SPLUNK_HOME/conf
  4. $SPLUNK_HOME/default
Correct answer: A
Explanation:
Reference: https://docs.splunk.com/Documentation/Splunk/7.3.1/Admin/Configurationfiledirectories
Reference: https://docs.splunk.com/Documentation/Splunk/7.3.1/Admin/Configurationfiledirectories



Question 2

Which forwarder type can parse data prior to forwarding?


  1. Universal forwarder
  2. Heaviest forwarder
  3. Hyper forwarder
  4. Heavy forwarder
Correct answer: D
Explanation:
Reference: https://docs.splunk.com/Documentation/Splunk/7.3.1/Forwarding/Typesofforwarders
Reference: https://docs.splunk.com/Documentation/Splunk/7.3.1/Forwarding/Typesofforwarders



Question 3

Which Splunk component consolidates the individual results and prepares reports in a distributed environment?


  1. Indexers
  2. Forwarder
  3. Search head
  4. Search peers
Correct answer: A
Explanation:
Reference: https://docs.splunk.com/Documentation/Splunk/7.3.1/Indexer/Advancedindexingstrategy
Reference: https://docs.splunk.com/Documentation/Splunk/7.3.1/Indexer/Advancedindexingstrategy



Question 4

Where should apps be located on the deployment server that the clients pull from? 


  1. $SPLUNK_HOME/etc/apps
  2. $SPLUNK_HOME/etc/search
  3. $SPLUNK_HOME/etc/master-apps
  4. $SPLUNK_HOME/etc/deployment-apps
Correct answer: A
Explanation:
Reference: https://answers.splunk.com/answers/371099/how-to-configure-deployment-apps-to-push-to-client.html
Reference: https://answers.splunk.com/answers/371099/how-to-configure-deployment-apps-to-push-to-client.html



Question 5

This file has been manually created on a universal forwarder:
/opt/splunkforwarder/etc/apps/my_TA/local/inputs.conf 
[monitor:///var/log/messages]
sourcetype=syslog 
index=syslog 
A new Splunk admin comes in and connects the universal forwarders to a deployment server and deploys the same app with a new inputs.conf file:
/opt/splunk/etc/deployment-apps/my_TA/local/inputs.conf 
[monitor:///var/log/maillog]
sourcetype=maillog 
index=syslog 
Which file is now monitored? 


  1. /var/log/messages
  2. /var/log/maillog
  3. /var/log/maillog and /var/log/messages
  4. none of the above
Correct answer: C



Question 6

When configuring monitor inputs with whitelists or blacklists, what is the supported method of filtering the lists?


  1. Slash notation
  2. Regular expression
  3. Irregular expression
  4. Wildcard-only expression
Correct answer: B
Explanation:
Reference: https://docs.splunk.com/Documentation/Splunk/7.3.1/Updating/Filterclients
Reference: https://docs.splunk.com/Documentation/Splunk/7.3.1/Updating/Filterclients



Question 7

What is required when adding a native user to Splunk? (Select all that apply.)


  1. Password 
  2. Username
  3. Full Name
  4. Default app
Correct answer: CD
Explanation:
Reference: https://docs.splunk.com/Documentation/Splunk/7.3.1/Security/Addandeditusers
Reference: https://docs.splunk.com/Documentation/Splunk/7.3.1/Security/Addandeditusers



Question 8

What are the minimum required settings when creating a network input in Splunk?


  1. Protocol, port number
  2. Protocol, port, location
  3. Protocol, username, port
  4. Protocol, IP, port number
Correct answer: A
Explanation:
Reference: https://docs.splunk.com/Documentation/Splunk/7.3.1/Data/UsetheHTTPEventCollector
Reference: https://docs.splunk.com/Documentation/Splunk/7.3.1/Data/UsetheHTTPEventCollector



Question 9

Which Splunk component requires a Forwarder license?


  1. Search head
  2. Heavy forwarder
  3. Heaviest forwarder
  4. Universal forwarder
Correct answer: B
Explanation:
Reference: https://answers.splunk.com/answers/70017/heavy-forwarder-costs-and-licenses.html
Reference: https://answers.splunk.com/answers/70017/heavy-forwarder-costs-and-licenses.html



Question 10

Which optional configuration setting in inputs.conf allows you to selectively forward the data to specific indexer(s)? 


  1. _TCP_ROUTING
  2. _INDEXER_LIST
  3. _INDEXER_GROUP
  4. _INDEXER_ROUTING
Correct answer: A
Explanation:
Reference: https://docs.splunk.com/Documentation/Splunk/7.3.1/Data/Monitorfilesanddirectorieswithinputs.conf
Reference: https://docs.splunk.com/Documentation/Splunk/7.3.1/Data/Monitorfilesanddirectorieswithinputs.conf









CONNECT US

Facebook

Twitter

PROFEXAM WITH A 20% DISCOUNT

You can buy ProfExam with a 20% discount!



HOW TO OPEN VCEX FILES

Use ProfExam Simulator to open VCEX files