Download Splunk.SPLK-1003.TestInside.2019-09-17.36q.vcex

Download Exam

File Info

Exam Splunk Enterprise Certified Admin
Number SPLK-1003
File Name Splunk.SPLK-1003.TestInside.2019-09-17.36q.vcex
Size 22 KB
Posted Sep 17, 2019
Download Splunk.SPLK-1003.TestInside.2019-09-17.36q.vcex

How to open VCEX & EXAM Files?

Files with VCEX & EXAM extensions can be opened by ProfExam Simulator.

Purchase

Coupon: MASTEREXAM
With discount: 20%






Demo Questions

Question 1

Which setting in indexes.conf allows data retention to be controlled by time? 


  1. maxDaysToKeep
  2. moveToFrozenAfter
  3. maxDataRetentionTime
  4. frozenTimePeriodInSecs
Correct answer: D
Explanation:
Reference: https://docs.splunk.com/Documentation/Splunk/7.3.1/Indexer/SmartStoredataretention
Reference: https://docs.splunk.com/Documentation/Splunk/7.3.1/Indexer/SmartStoredataretention



Question 2

The universal forwarder has which capabilities when sending data? (Select all that apply.)


  1. Sending alerts
  2. Compressing data
  3. Obfuscating/hiding data
  4. Indexer acknowledgement
Correct answer: D
Explanation:
Reference: https://docs.splunk.com/Documentation/Splunk/7.3.1/Forwarding/Typesofforwarders
Reference: https://docs.splunk.com/Documentation/Splunk/7.3.1/Forwarding/Typesofforwarders



Question 3

In which Splunk configuration is the SEDCMD used? 


  1. props.conf
  2. inputs.conf
  3. indexes.conf
  4. transforms.conf
Correct answer: A
Explanation:
Reference: https://answers.splunk.com/answers/212128/why-sedcmd-configured-in-propsconf-is-working-duri.html
Reference: https://answers.splunk.com/answers/212128/why-sedcmd-configured-in-propsconf-is-working-duri.html



Question 4

Which of the following are supported configuration methods to add inputs on a forwarder? (Select all that apply.)


  1. CLI
  2. Edit inputs.conf
  3. Edit forwarder.conf
  4. Forwarder Management
Correct answer: B
Explanation:
Reference: https://docs.splunk.com/Documentation/Forwarder/7.3.1/Forwarder/Configuretheuniversalforwarder
Reference: https://docs.splunk.com/Documentation/Forwarder/7.3.1/Forwarder/Configuretheuniversalforwarder



Question 5

Which parent directory contains the configuration files in Splunk? 


  1. $SPLUNK_HOME/etc
  2. $SPLUNK_HOME/var
  3. $SPLUNK_HOME/conf
  4. $SPLUNK_HOME/default
Correct answer: A
Explanation:
Reference: https://docs.splunk.com/Documentation/Splunk/7.3.1/Admin/Configurationfiledirectories
Reference: https://docs.splunk.com/Documentation/Splunk/7.3.1/Admin/Configurationfiledirectories



Question 6

Which forwarder type can parse data prior to forwarding?


  1. Universal forwarder
  2. Heaviest forwarder
  3. Hyper forwarder
  4. Heavy forwarder
Correct answer: D
Explanation:
Reference: https://docs.splunk.com/Documentation/Splunk/7.3.1/Forwarding/Typesofforwarders
Reference: https://docs.splunk.com/Documentation/Splunk/7.3.1/Forwarding/Typesofforwarders



Question 7

Which Splunk component distributes apps and certain other configuration updates to search head cluster members?


  1. Deployer
  2. Cluster master
  3. Deployment server
  4. Search head cluster master
Correct answer: A
Explanation:
Reference: https://docs.splunk.com/Documentation/Splunk/7.3.1/DistSearch/PropagateSHCconfigurationchanges
Reference: https://docs.splunk.com/Documentation/Splunk/7.3.1/DistSearch/PropagateSHCconfigurationchanges



Question 8

This file has been manually created on a universal forwarder:
/opt/splunkforwarder/etc/apps/my_TA/local/inputs.conf 
[monitor:///var/log/messages]
sourcetype=syslog 
index=syslog 
A new Splunk admin comes in and connects the universal forwarders to a deployment server and deploys the same app with a new inputs.conf file:
/opt/splunk/etc/deployment-apps/my_TA/local/inputs.conf 
[monitor:///var/log/maillog]
sourcetype=maillog 
index=syslog 
Which file is now monitored? 


  1. /var/log/messages
  2. /var/log/maillog
  3. /var/log/maillog and /var/log/messages
  4. none of the above
Correct answer: C



Question 9

In which phase of the index time process does the license metering occur?


  1. Input phase
  2. Parsing phase
  3. Indexing phase
  4. Licensing phase
Correct answer: C
Explanation:
Reference: https://docs.splunk.com/Documentation/Splunk/7.3.1/Admin/HowSplunklicensingworks
Reference: https://docs.splunk.com/Documentation/Splunk/7.3.1/Admin/HowSplunklicensingworks



Question 10

You update a props.conf file while Splunk is running. You do not restart Splunk and you run this command: splunk btool props list –-debug. What will the output be?


  1. A list of all the configurations on-disk that Splunk contains.
  2. A verbose list of all configurations as they were when splunkd started.
  3. A list of props.conf configurations as they are on-disk along with a file path from which the configuration is located.
  4. A list of the current running props.conf configurations along with a file path from which the configuration was made.
Correct answer: D
Explanation:
Reference: https://answers.splunk.com/answers/494219/need-help-with-what-should-be-a-simple-precedence.html
Reference: https://answers.splunk.com/answers/494219/need-help-with-what-should-be-a-simple-precedence.html









CONNECT US

Facebook

Twitter

PROFEXAM WITH A 20% DISCOUNT

You can buy ProfExam with a 20% discount!



HOW TO OPEN VCEX FILES

Use ProfExam Simulator to open VCEX files