Big Halloween Sale 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: sale65best

Free Splunk SPLK-1003 Practice Exam with Questions & Answers | Set: 4

Questions 31

What is the valid option for a [monitor] stanza in inputs.conf?

Options:
A.

enabled

B.

datasource

C.

server_name

D.

ignoreOlderThan

Splunk SPLK-1003 Premium Access
Questions 32

Which of the following is true when authenticating users to Splunk using LDAP?

Options:
A.

LDAP group names must match the Splunk role name defined in authorize.conf.

B.

Splunk will search each LDAP strategy in the order in which they are listed in authentication.conf.

C.

Splunk only supports encrypted LDAP connections.

D.

LDAP will take precedence over local users with the same username as defined in etc/passwd.

Questions 33

Running this search in a distributed environment:

On what Splunk component does the eval command get executed?

Options:
A.

Heavy Forwarders

B.

Universal Forwarders

C.

Search peers

D.

Search heads

Questions 34

Which of the following is true regarding LDAP integration with Splunk Enterprise?

Options:
A.

Having the change authentication capability will not allow setup of the LDAP integration.

B.

Mappings can be changed at any time if the user has the power role.

C.

A user cannot log in via LDAP unless they have an associated Splunk role.

D.

LDAP integration will not function unless all groups are mapped to an LDAP group.

Questions 35

Which of the following types of data count against the license daily quota?

Options:
A.

Replicated data

B.

splunkd logs

C.

Summary index data

D.

Windows internal logs

Questions 36

Which valid bucket types are searchable? (select all that apply)

Options:
A.

Hot buckets

B.

Cold buckets

C.

Warm buckets

D.

Frozen buckets

Questions 37

In case of a conflict between a whitelist and a blacklist input setting, which one is used?

Options:
A.

Blacklist

B.

Whitelist

C.

They cancel each other out.

D.

Whichever is entered into the configuration first.

Questions 38

What options are available when creating custom roles? (select all that apply)

Options:
A.

Restrict search terms

B.

Whitelist search terms

C.

Limit the number of concurrent search jobs

D.

Allow or restrict indexes that can be searched.

Questions 39

Which feature in Splunk allows Event Breaking, Timestamp extractions, and any advanced configurations

found in props.conf to be validated all through the UI?

Options:
A.

Apps

B.

Search

C.

Data preview

D.

Forwarder inputs

Questions 40

Which is a valid stanza for a network input?

Options:
A.

[udp://172.16.10.1:9997]connection = dnssourcetype = dns

B.

[any://172.16.10.1:10001]connection_host = ipsourcetype = web

C.

[tcp://172.16.10.1:9997]connection_host = websourcetype = web

D.

[tcp://172.16.10.1:10001]connection_host = dnssourcetype = dns