SPLUNK CERTIFIED ADMIN DUMP EXAM QUESTIONS WITH
ACCURATE SOLUTIONS
What are the minimum required settings when creating a network input in Splunk?
A. Protocol, port number
B. Protocol, port, location
C. Protocol, username, port
D. Protocol, IP. port number -- Correct Answer ✔✔ A
How does the Monitoring Console monitor forwards?
A. By pulling internal logs from forwarders.
B. By using the forwarder monitoring add-on
C. With internal logs forwarded by forwarders
D. With internal logs forwarded by deployment server -- Correct Answer ✔✔ C
How do you remove missing forwarders from the Monitoring Console?
A. By restarting Splunk.
B. By rescanning active forwarders.
C. By reloading the deployment server
D. By rebuilding the forwarder asset table -- Correct Answer ✔✔ D
In which Splunk configuration is the SEDCMD used?
A. props.conf
B. inputs.conf
C. indexes.conf
,D. transforms.conf -- Correct Answer ✔✔ A
When configuring monitor inputs with whitelist or blacklists, what is the supported
method of filtering the lists?
A. Slash notation
B. Regular expression
C. Irregular expression
D. Wildcard-only expression -- Correct Answer ✔✔ B
Which of the following authentication types requires scripting in Splunk?
A. ADFS
B. LDAP
C. SAML
D. RADIUS -- Correct Answer ✔✔ D
What options are available when creating custom roles? (Select all that apply)
A. Restrict search terms
B. Whitelist search terms
C. Limit the number of concurrent search jobs
D. Allow or restrict indexes that can be searched -- Correct Answer ✔✔ ACD
Which Splunk component distributes apps and certain other configuration updates to
search head cluster members?
A. Deployer
B. Cluster Master
C. Deployment Server
D. Search head cluster master -- Correct Answer ✔✔ C
Which of the following apply to how distributed search works? (select all that apply)
A. The search head dispatches searches to the peer
B. The search peers pull the data from the forwarder
, C. Peers run searches in parallel and return their portion of results
D. The search head consolidates the individual results and prepares reports -- Correct
Answer ✔✔ ACD
Which authentication methods are natively supported within Splunk Enterprise? (Select
all that apply)
A. LDAP
B. SAML
C. RADIUS
D. Duo Multifactor Authentication -- Correct Answer ✔✔ AB
Which Splunk component requires a Forwarder license?
A. Search head
B. Heavy Forwarder
C. Heaviest forwarder
D. Universal Forwarder -- Correct Answer ✔✔ B
Which of the following are required when defining an index in indexes.conf? (Select all
that apply)
A. coldPath
B. homePath
C. frozenPath
D. thawedPath -- Correct Answer ✔✔ ABD
Which setting in indexes.conf allows data retention to be controlled by time?
A. maxDaysToKeep
B. moveToFrozenAfter
C. maxDataRetentionTime
D. frozenTimePeriodInSecs -- Correct Answer ✔✔ D
Which of the following are supported configuration methods to add inputs on a
forwarder? (Select all that apply)
ACCURATE SOLUTIONS
What are the minimum required settings when creating a network input in Splunk?
A. Protocol, port number
B. Protocol, port, location
C. Protocol, username, port
D. Protocol, IP. port number -- Correct Answer ✔✔ A
How does the Monitoring Console monitor forwards?
A. By pulling internal logs from forwarders.
B. By using the forwarder monitoring add-on
C. With internal logs forwarded by forwarders
D. With internal logs forwarded by deployment server -- Correct Answer ✔✔ C
How do you remove missing forwarders from the Monitoring Console?
A. By restarting Splunk.
B. By rescanning active forwarders.
C. By reloading the deployment server
D. By rebuilding the forwarder asset table -- Correct Answer ✔✔ D
In which Splunk configuration is the SEDCMD used?
A. props.conf
B. inputs.conf
C. indexes.conf
,D. transforms.conf -- Correct Answer ✔✔ A
When configuring monitor inputs with whitelist or blacklists, what is the supported
method of filtering the lists?
A. Slash notation
B. Regular expression
C. Irregular expression
D. Wildcard-only expression -- Correct Answer ✔✔ B
Which of the following authentication types requires scripting in Splunk?
A. ADFS
B. LDAP
C. SAML
D. RADIUS -- Correct Answer ✔✔ D
What options are available when creating custom roles? (Select all that apply)
A. Restrict search terms
B. Whitelist search terms
C. Limit the number of concurrent search jobs
D. Allow or restrict indexes that can be searched -- Correct Answer ✔✔ ACD
Which Splunk component distributes apps and certain other configuration updates to
search head cluster members?
A. Deployer
B. Cluster Master
C. Deployment Server
D. Search head cluster master -- Correct Answer ✔✔ C
Which of the following apply to how distributed search works? (select all that apply)
A. The search head dispatches searches to the peer
B. The search peers pull the data from the forwarder
, C. Peers run searches in parallel and return their portion of results
D. The search head consolidates the individual results and prepares reports -- Correct
Answer ✔✔ ACD
Which authentication methods are natively supported within Splunk Enterprise? (Select
all that apply)
A. LDAP
B. SAML
C. RADIUS
D. Duo Multifactor Authentication -- Correct Answer ✔✔ AB
Which Splunk component requires a Forwarder license?
A. Search head
B. Heavy Forwarder
C. Heaviest forwarder
D. Universal Forwarder -- Correct Answer ✔✔ B
Which of the following are required when defining an index in indexes.conf? (Select all
that apply)
A. coldPath
B. homePath
C. frozenPath
D. thawedPath -- Correct Answer ✔✔ ABD
Which setting in indexes.conf allows data retention to be controlled by time?
A. maxDaysToKeep
B. moveToFrozenAfter
C. maxDataRetentionTime
D. frozenTimePeriodInSecs -- Correct Answer ✔✔ D
Which of the following are supported configuration methods to add inputs on a
forwarder? (Select all that apply)