Official Bank 0/202

Splunk Enterprise Certified Admin Exam (SPLK-1003) - Splunk Exam Questions

Last updated on June 20, 2026

97% Exam Compliance
202 Total Questions
1
Question
In inputs. conf, which stanza would mean Splunk was only reading one local file?
Options
A [monitor:/// opt/log/ crashlog/Jan27crash.txt]
B [read://opt/log/crashlog/Jan27crash.txt]
C [monitor::/ opt/log/crashlog/Jan27crash.txt]
D [monitor:/// opt/log/]
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

2
Question
A user is assigned two roles with the following search filters. What is the user's applied search filter?

Exhibit
Options
A Option A
B Option B
C Option D
D Option C
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

3
Question
Which of the following is accurate regarding the input phase?
Options
A Breaks data into events with timestamps.
B Performs character encoding.
C Applies event-level transformations.
D Fine-tunes metadata.
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

4
Question
The following stanza is active in indexes.conf: [cat_facts]
maxHotSpanSecs = 3600
frozenTimePeriodInSecs = 2630000
maxTota1DataSizeMB = 650000
All other related indexes.conf settings are default values.
If the event timestamp was 3739283 seconds ago, will it be searchable?
Options
A Yes, only if the bucket is still hot.
B No, because the index will have exceeded its maximum size.
C No, because the event time is greater than the retention time.
D Yes, only if the index size is also below 650000 MB.
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

5
Question
A configuration file in a deployed app needs to be directly edited. Which steps would ensure a successful deployment to clients?
Options
A Make the change in $SPLUNK HOME/etc/dep10yment apps/$appName/10ca1/ on the deployment server, and the change will be automatically sent to the deployment clients.
B Make the change in $SPLUNK HOME /etc/apps/$appname/local/ on any of the deployment clients, and then run the command . / splunk reload deploy-server to push that change to the deployment server.
C Make the change in $SPLUNK HOME/etc/apps/$appName/defau1t on the deployment server, and it will be distributed down to the clients' own local versions.
D Make the change in $SPLUNK HOME/etc/dep10yment apps/$appName/10ca1/ on the deployment server, and then run $SPLUNK HOME/bin/sp1unk reload deploy—server.
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

Finish Practice?

Are you sure you want to finish? This will end your practice session.