Splunk SPLK-1005 Practice Exams
Last updated on Oct 06,2026- Exam Code: SPLK-1005
- Exam Name: Splunk Cloud Certified Admin
- Certification Provider: Splunk
- Latest update: Oct 06,2026
Question #31
Which of the following is true when integrating LDAP authentication?
- A . Splunk stores LDAP end user names and passwords on search heads.
- B . The mapping of LDAP groups to Splunk roles happens automatically.
- C . Splunk Cloud only supports Active Directory LDAP servers.
- D . New user data is cached the first time a user logs in.
Question #32
In Splunk terminology, what is an index?
- A . A data repository that contains raw, compressed data along with psidx files.
- B . A data repository that contains raw, compressed data along with tsidx files.
- C . A data repository that contains raw, uncompressed data along with psidx files.
- D . A data repository that contains raw, uncompressed data along with tsidx files.
Question #33
Which of the following are default Splunk Cloud user roles?
- A . must_delete, power, sc_admin
- B . power, user, admin
- C . apps, power, sc_admin
- D . can delete, users, admin
Question #34
Which of the following is not a path used by Splunk to execute scripts?
- A . SPLUNK_HOME/etc/system/bin
- B . SPLUNK HOME/etc/appa/<app name>/bin
- C . SPLUNKHOMS/ctc/scripts/local
- D . SPLUNK_HOME/bin/scripts
Question #35
When monitoring network inputs, there will be times when the forwarder is unable to send data to the indexers. Splunk uses a memory queue and a disk queue.
Which setting is used for the disk queue?
- A . queueSize
- B . maxQeueSize
- C . diskQiioiioiiizo
- D . persistentQueueSize
Question #36
Where does the regex replacement processor run?
- A . Merging pipeline
- B . Typing pipeline
- C . Index pipeline
- D . Parsing pipeline