Splunk

SPLK-2001 practice test

Practice with 15 free Testara sample questions, or choose paid access to the full 21-question bank.

Provider
Splunk
Question bank
21
Free sample
15 questions
Publisher
Testara

About this practice material

This page covers Testara's practice question bank for SPLK-2001, a certification listed under Splunk. Questions use original, exam-style scenarios and are not questions from the official certification exam.

Testara is an independent practice platform and is not affiliated with, endorsed by, or authorized by Splunk. The certification credential is issued by Splunk, not Testara. Certification and provider names belong to their respective owners.

Start practicing

The guest demo does not save an attempt. Sign in before buying access.

Try 15 questions free

Available without signing in

Free sample questions

These 15 questions and their explanations are server-rendered so you can inspect the material before opening the interactive demo.

  1. Question 1 · 1

    Which of the following is true of a namespace?

    Choose one answer.

    • The namespace is a type of token filter.
    • The namespace includes an app attribute which cannot be a wildcard.
    • The namespace filters the knowledge objects returned by the REST API.
    • The namespace does not filter knowledge objects returned by the REST API.
  2. Question 2 · 1

    What application security best practices should be adhered to while developing an app for Splunk? (Select all that apply.)

    Choose all answers that apply.

    • Review the OWASP Top Ten List.
    • Store passwords in clear text in .conf files.
    • Review the OWASP Secure Coding Practices Quick Reference Guide.
    • Ensure that third-party libraries that the app depends on have no outstanding CVE vulnerabilities.
  3. Question 3 · 1

    How can hiding or showing a panel by clicking on a chart or a table on the same form be performed?

    Choose one answer.

    • By using vent drilldown.
    • By using workflow action.
    • By using contextual drilldown.
    • By using visualization drilldown.
  4. Question 4 · 1

    Which of the following are true of auto-refresh for dashboard panels? (Select all that apply.)

    Choose all answers that apply.

    • Applies to inline searches and saved searches.
    • Enabling auto-refresh for a report requires editing XML.
    • Post-processing searches are refreshed when their base searches are refreshed.
    • Each post-processing search using the same base search can have a different refresh time.
  5. Question 5 · 1

    Searching `index=_internal metrics | head 3` from Splunk Web returned the following events: 04-12-2018 18:39:43.514 +0200 INFO Metrics `" group=thruput, name=thruput, instantaneous_kbps=0.9651774014563425, instantaneous_eps=5.645638802094809, average_kbps=1.198995639527069, total_k_processed=2676, kb=29.91796875, ev=175, load_average=3.85888671875 04-12-2018 18:39:43.514 +0200 INFO Metrics `" group_thruput, name_syslog_output, instantaneous_kbps=0, instantaneous_eps_0, average_kbps=0, total_k_processed=0, kb=0, ev=0 04-12-2018 18:39:43.513 +0200 INFO Metrics `" group_thruput, name_index_thruput, instantaneous_kbps=0.9651773703189551, instantaneous_eps=4.87137960922438, average_kbps=1.1985932324065556, total_k_processed=2675, kb=29.91796875, ev=151 When the same search is required from a REST API call, which fields will be given? (Select all that apply.)

    Choose all answers that apply.

    • _raw
    • name
    • sourcetype
    • instantaneous_kbps
  6. Question 6 · 1

    Which of the following are requirements for arguments sent to the data/indexes endpoint? (Select all that apply.)

    Choose all answers that apply.

    • Be url-encoded.
    • Specify the datatype.
    • Include the bucket path.
    • Include the name argument.
  7. Question 7 · 1

    Which of the following formats are valid for a Splunk REST URI?

    Choose one answer.

    • host:port/endpoint
    • scheme://host/servicesNS/*/
    • $SPLUNK HOME/services/endpoint
    • scheme://host:port/services/endpoint
  8. Question 8 · 1

    Which HTTP Event Collector (HEC) endpoint should be used to collect data in the following format? {`message`:`Hello World`, `foo`:`bar`, `pony`:`buttercup`}

    Choose one answer.

    • data/inputs/http/{name}
    • services/collector/raw
    • services/collector
    • data/inputs/http
  9. Question 9 · 1

    Which of the following is a security best practice?

    Choose one answer.

    • Enable XSS.
    • Eliminate all escape characters.
    • Ensure the app passes App Certification.
    • Ensure components have no Common Vulnerabilities and Exposures (CVE) vulnerabilities.
  10. Question 10 · 1

    What predefined drilldown tokens are available specifically for trellis layouts? (Select all that apply.)

    Choose all answers that apply.

    • trellis.Xaxis
    • trellis.Yaxis
    • trellis.name
    • trellis.value
  11. Question 11 · 1

    How can event logs be collected from a remote Windows machine using a standard Splunk installation and no customization? (Select all that apply.)

    Choose all answers that apply.

    • By configuring a WMI input.
    • By using HTTP event collector.
    • By using a Windows heavy forwarder.
    • By using a Windows universal forwarder.
  12. Question 12 · 1

    To delete the record with a _key value of smith from the sales collection, a DELETE request should be sent to which REST endpoint?

    Choose one answer.

    • /storage/collections/sales/smith
    • /storage/kvstore/data/sales/smith
    • /storage/collections/data/sales/smith
    • /storage/kvstore/collections/sales/smith
  13. Question 13 · 1

    Which of the following statements describe an HEC token? (Select all that apply.)

    Choose all answers that apply.

    • Maps to a Splunk user.
    • Can be used to download data.
    • Is a GUID (globally unique identifier).
    • Can be created in Splunk Web or using REST endpoints.
  14. Question 14 · 1

    When the search/jobs REST endpoint is called to execute a search, what can be done to reduce the results size in the results? (Select all that apply.)

    Choose all answers that apply.

    • Use a generating search.
    • Remove unneeded fields.
    • Truncate the data, using selective functions.
    • Summarize data, using analytic commands.
  15. Question 15 · 1

    After updating a dashboard in myApp, a Splunk admin moves myApp to a different Splunk instance. After logging in to the new instance, the dashboard is not seen. What could have happened? (Select all that apply.)

    Choose all answers that apply.

    • The dashboard's permissions were set to private.
    • User role permissions are different on the new instance.
    • The admin deleted the myApp/local directory before packaging.
    • Changes were placed in: $SPLUNK_HOME/etc/apps/search/default/data/ui/nav

Each purchase applies to this certification. Prices are one-time payments, not monthly subscriptions.

Starter

$29 USD one time

Full access to one certification's question bank in standard practice mode for 60 days.

  • Full question bank for one certification
  • 60 days of access
  • Standard practice mode
  • Question notes and community discussions
  • Attempt scores and answer review

Professional

$49 USD one time

Full access to one certification's question bank, custom test controls and advanced analytics for 60 days.

  • Custom test builder
  • Timers and question selection
  • Randomized question and answer order
  • Advanced performance and weak-question analytics
  • Priority customer support
Try 15 questions free