Q1. Which of the following are required when defining an index in indexes. conf? (select all that apply)
A.coldPath
B. homePath
C. frozenPath
D. thawedPath
Correct Answer: A, B, D
Q2. Which Splunk component distributes apps and certain other configuration updates to search head cluster members?
A.Deployer
B. Cluster master
C. Deployment server
D. Search head cluster master
Correct Answer: C
Q3. What is the correct example to redact a plain-text password from raw events?
A.in props.conf: [identity] REGEX-redact_pw = s/password=([^,|/s]+)/ ####REACTED####/g
B. in props.conf: [identity] SEDCMD-redact_pw = s/password=([^,|/s]+)/ ####REACTED####/g
C. in transforms.conf: [identity] SEDCMD-redact_pw = s/password=([^,|/s]+)/ ####REACTED####/g
D. in transforms.conf: [identity] REGEX-redact_pw = s/password=([^,|/s]+)/ ####REACTED####/g
Correct Answer: B
Q4. Immediately after installation, what will a Universal Forwarder do first?
A.Automatically detect any indexers in its subnet and begin routing data.
B. Begin generating internal Splunk logs.
C. Begin reading local files on its server.
D. Send an email to the operator that the installation process has completed.
Correct Answer: B
Q5. What options are available when creating custom roles? (select all that apply)
A.Restrict search terms
B. Whitelist search terms
C. Limit the number of concurrent search jobs
D. Allow or restrict indexes that can be searched.
Correct Answer: A, C, D
$ 39
Reviews
There are no reviews yet.