100% satisfaction guarantee Immediately available after payment Both online and in PDF No strings attached 4.2 TrustPilot
logo-home
Exam (elaborations)

SPLUNK ENTERPRISE CERTIFIED ADMIN EXAM QUESTIONS AND ANSWERS

Rating
-
Sold
-
Pages
27
Grade
A+
Uploaded on
24-11-2025
Written in
2025/2026

SPLUNK ENTERPRISE CERTIFIED ADMIN EXAM QUESTIONS AND ANSWERS

Institution
SPLUNK
Course
SPLUNK










Whoops! We can’t load your doc right now. Try again or contact support.

Written for

Institution
SPLUNK
Course
SPLUNK

Document information

Uploaded on
November 24, 2025
Number of pages
27
Written in
2025/2026
Type
Exam (elaborations)
Contains
Questions & answers

Subjects

Content preview

SPLUNK ENTERPRISE CERTIFIED
ADMIN EXAM



Which setting in indexes.conf allows data retention to be controlled by time?

A. maxDaysToKeep
B. moveToFrozenAfter
C. maxDataRetentionTime
D. frozenTimePeriodInSecs - Correct Answers -frozenTimePeriodInSecs

The universal forwarder has which capabilities when sending data? (Choose all that
apply.)

A. Sending alerts
B. Compressing data
C. Obfuscating/hiding data
D. Indexer acknowledgement - Correct Answers -Compressing data
Indexer acknowledgement

In case of a conflict between a whitelist and a blacklist input setting, which one is used?

A. Blacklist
B. Whitelist
C. They cancel each other out.
D. Whichever is entered into the configuration first. - Correct Answers -Blacklist

In which Splunk configuration is the SEDCMD used?

A. props.conf
B. inputs.conf
C. indexes.conf
D. transforms.conf - Correct Answers -props.conf

Which of the following are supported configuration methods to add inputs on a
forwarder? (Choose all that apply.)

A. CLI
B. Edit inputs.conf
C. Edit forwarder.conf

,D. Forwarder Management - Correct Answers -CLI
Edit inputs.conf

Which parent directory contains the configuration files in Splunk?

A. $SPLUNK_HOME/etc
B. $SPLUNK_HOME/var
C. $SPLUNK_HOME/conf
D. $SPLUNK_HOME/default - Correct Answers -$SPLUNK_HOME/etc

Which forwarder type can parse data prior to forwarding?

A. Universal forwarder
B. Heaviest forwarder
C. Hyper forwarder
D. Heavy forwarder - Correct Answers -Heavy forwarder

Which Splunk component consolidates the individual results and prepares reports in a
distributed environment?

A. Indexers
B. Forwarder
C. Search head
D. Search peers - Correct Answers -Search head

Which Splunk component distributes apps and certain other configuration updates to
search head cluster members?

A. Deployer
B. Cluster master
C. Deployment server
D. Search head cluster master - Correct Answers -Deployer

Where should apps be located on the deployment server that the clients pull from?

A. $SPLUNK_HOME/etc/apps
B. $SPLUNK_HOME/etc/search
C. $SPLUNK_HOME/etc/master-apps
D. $SPLUNK_HOME/etc/deployment-apps - Correct Answers
-$SPLUNK_HOME/etc/deployment-apps

This file has been manually created on a universal forwarder:
/opt/splunkforwarder/etc/apps/my_TA/local/inputs.conf
[monitor:///var/log/messages]
sourcetype=syslog
index=syslog

, A new Splunk admin comes in and connects the universal forwarders to a deployment
server and deploys the same app with a new inputs.conf file:
/opt/splunk/etc/deployment-apps/my_TA/local/inputs.conf
[monitor:///var/log/maillog]
sourcetype=maillog
index=syslog
Which file is now monitored?

A. /var/log/messages
B. /var/log/maillog
C. /var/log/maillog and /var/log/messages
D. none of the above - Correct Answers -/var/log/maillog

In which phase of the index time process does the license metering occur?

A. Input phase
B. Parsing phase
C. Indexing phase
D. Licensing phase - Correct Answers -Indexing phase

You update a props.conf file while Splunk is running. You do not restart Splunk and you
run this command: splunk btool props list `"-debug. What will the output be?

A. A list of all the configurations on-disk that Splunk contains.
B. A verbose list of all configurations as they were when splunkd started.
C. A list of props.conf configurations as they are on-disk along with a file path from
which the configuration is located.
D. A list of the current running props.conf configurations along with a file path from
which the configuration was made. - Correct Answers -A list of props.conf configurations
as they are on-disk along with a file path from which the configuration is located.

When running the command shown below, what is the default path in which
deploymentserver.conf is created? splunk set deploy-poll deployServer:port

A. SPLUNK_HOME/etc/deployment
B. SPLUNK_HOME/etc/system/local
C. SPLUNK_HOME/etc/system/default
D. SPLUNK_HOME/etc/apps/deployment - Correct Answers
-SPLUNK_HOME/etc/system/local

The priority of layered Splunk configuration files depends on the file's:

A. Owner
B. Weight
C. Context
D. Creation time - Correct Answers -Context

Get to know the seller

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
millyphilip West Virginia University
View profile
Follow You need to be logged in order to follow users or courses
Sold
2808
Member since
3 year
Number of followers
1959
Documents
40668
Last sold
4 hours ago
white orchid store

EXCELLENCY IN ACCADEMIC MATERIALS ie exams, study guides, testbanks ,case, case study etc

3.7

534 reviews

5
234
4
83
3
103
2
31
1
83

Recently viewed by you

Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Frequently asked questions