Weekend Sale 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: sale65best

Free Splunk SPLK-1003 Practice Exam with Questions & Answers | Set: 4

Questions 31

Local user accounts created in Splunk store passwords in which file?

Options:
A.

$ SFLUNK_HOME/etc/passwd

B.

$ SFLUNK_HOME/etc/authentication

C.

$ S?LUNK_HOME/etc/users/passwd.conf

D.

$ SPLUNK HOME/etc/users/authentication.conf

Splunk SPLK-1003 Premium Access
Questions 32

What is an example of a proper configuration for CHARSET within props.conf?

Options:
A.

[host: : server. splunk. com]CHARSET = BIG5

B.

[index: :main]CHARSET = BIG5

C.

[sourcetype: : son]CHARSET = BIG5

D.

[source: : /var/log/ splunk]CHARSET = BIG5

Questions 33

When deploying apps, which attribute in the forwarder management interface determines the apps that clients install?

Options:
A.

App Class

B.

Client Class

C.

Server Class

D.

Forwarder Class

Questions 34

When deploying apps on Universal Forwarders using the deployment server, what is the correct component and location of the app before it is deployed?

Options:
A.

On Universal Forwarder, $SPLUNK_HOME/etc/apps

B.

On Deployment Server, $SPLUNK_HOME/etc/apps

C.

On Deployment Server, $SPLUNK_HOME/etc/deployment-apps

D.

On Universal Forwarder, $SPLUNK_HOME/etc/deployment-apps

Questions 35

Which Splunk component(s) would break a stream of syslog inputs into individual events? (select all that apply)

Options:
A.

Universal Forwarder

B.

Search head

C.

Heavy Forwarder

D.

Indexer

Questions 36

User role inheritance allows what to be inherited from the parent role? (select all that apply)

Options:
A.

Parents

B.

Capabilities

C.

Index access

D.

Search history

Questions 37

An admin is running the latest version of Splunk with a 500 GB license. The current daily volume of new data

is 300 GB per day. To minimize license issues, what is the best way to add 10 TB of historical data to the

index?

Options:
A.

Buy a bigger Splunk license.

B.

Add 2.5 TB each day for the next 5 days.

C.

Add all 10 TB in a single 24 hour period.

D.

Add 200 GB of historical data each day for 50 days.

Questions 38

When would the following command be used?

Options:
A.

To verify' the integrity of a local index.

B.

To verify the integrity of a SmartStore index.

C.

To verify the integrity of a SmartStore bucket.

D.

To verify the integrity of a local bucket.

Questions 39

Which of the following methods will connect a deployment client to a deployment server? (select all that apply)

Options:
A.

Run $SPLUNK_ROME/bin/ splunk set deploy-poll : from the command line of the deployment client.

B.

Create and edit a deploymentserver . conf file in SSPLVNE{ on the deployment server.

C.

Create and edit a deploymentclient . conf file in SSPLTJNE( EOME/etc/ system/local on the deployment client.

D.

Run $SPLUNK ROME/bin/spiunk set deploy-poi i : from the command line of the deployment server.

Questions 40

Which of the following is true when authenticating users to Splunk using LDAP?

Options:
A.

LDAP group names must match the Splunk role name defined in authorize.conf.

B.

Splunk will search each LDAP strategy in the order in which they are listed in authentication.conf.

C.

Splunk only supports encrypted LDAP connections.

D.

LDAP will take precedence over local users with the same username as defined in etc/passwd.