Limited-Time Offer: Enjoy 50% Savings! - Ends In 0d 00h 00m 00s Coupon code: 50OFF
Free Exam Questions

SPLK-1005 Exam Questions & Answers

Splunk Cloud Certified Admin  •  Splunk

80 Questions 75 min Updated Sep 2026 99% Pass Rate
Get Full Access

100% money-back guarantee

Sample SPLK-1005 Questions

Practice with real exam-style questions, each with the verified correct answer and explanation.

Q1 MultipleChoice

Which of the following is a valid method to test if a forwarder can successfully send data to Splunk Cloud?

Correct Answer: B
Explanation:

Using the oneshot command allows a direct check for data reception in the cloud environment. Logs can be verified in the cloud after the forwarder sends them. [Reference: Splunk Docs on testing forwarder data inputs]

Q2 MultipleChoice

When adding a directory monitor and specifying a sourcetype explicitly, it applies to all files in the directory and subdirectories. If automatic sourcetyping is used, a user can selectively override it in which file on the forwarder?

Correct Answer: B
Explanation:

When a directory monitor is set up with automatic sourcetyping, a user can selectively override the sourcetype assignment by configuring the props.conf file on the forwarder. The props.conf file allows you to define how data should be parsed and processed, including assigning or overriding sourcetypes for specific data inputs.

Splunk Documentation Reference: props.conf configuration

Q3 MultipleChoice

Which of the following is not considered a best practice for the deployment server?

Correct Answer: D
Explanation:

In Splunk, it's considered best practice to create small, single-purpose deployment apps rather than large, multi-purpose ones. This approach ensures better manageability, easier updates, and clearer version control. Option D, which suggests creating large, multi-purpose deployment apps, is not a best practice.

Splunk Documentation Reference: Deployment Server Best Practices

Q4 MultipleChoice

What is the correct syntax to monitor /apache/too/logo, /apache/bor/logs, and /apache/bar/l/logo?

A)

B)

C)

D)

Correct Answer: B
Explanation:

In the context of Splunk, when configuring data inputs to monitor specific directories, the correct syntax must match the directory paths accurately and adhere to the format recognized by Splunk.

Option A: [monitor:///apache/*/logs] - This syntax would attempt to monitor all directories under /apache/ that contain the word logs, which is not what the question is asking. It is incorrect for the paths given in the question.

Option B: [monitor:///apache/foo/logs, /apache/bar/logs, /apache/bar/1/logs] - This syntax correctly lists the specific paths /apache/foo/logs, /apache/bar/logs, and /apache/bar/1/logs separately. This is the correct answer as it precisely matches the paths given in the question.

Option C: [monitor:///apache/.../logs] - The triple dots syntax (...) is used to match any subdirectories under /apache/. This would monitor all logs directories within any subdirectory structure under /apache/, which again, does not specifically match the paths given in the question.

Option D: [monitor:///apache/foo/logs, /apache/bar/logs, and /apache/bar/1/logs] - This syntax includes the word 'and', which is not valid in the Splunk monitor stanza. The syntax should list the paths separated by commas, without additional words.

Thus, Option B is the correct syntax to monitor the specified paths in Splunk.

For additional reference, you can check the official Splunk documentation on monitoring inputs which provides guidelines on how to configure monitoring of files and directories.

Q5 MultipleChoice

When monitoring directories that contain mixed file types, which setting should be omitted from inputs, conf and instead be overridden in propo.conf?

Correct Answer: A
Explanation:

When monitoring directories containing mixed file types, the sourcetype should typically be overridden in props.conf rather than defined in inputs.conf. This is because sourcetype is meant to classify the type of data being ingested, and when dealing with mixed file types, setting a single sourcetype in inputs.conf would not be effective for accurate data classification. Instead, you can use props.conf to define rules that apply different sourcetypes based on the file path, file name patterns, or other criteria. This allows for more granular and accurate assignment of sourcetypes, ensuring the data is properly parsed and indexed according to its type.

Splunk Cloud Reference: For further clarification, refer to Splunk's official documentation on configuring inputs and props, especially the sections discussing monitoring directories and configuring sourcetypes.

Source:

Splunk Docs: Monitor files and directories

Splunk Docs: Configure event line breaking and input settings with props.conf

Get access to all 80 verified questions with detailed answers.

Unlock All SPLK-1005 Questions

Frequently Asked Questions

The SPLK-1005 is the Splunk Cloud Certified Admin exam that validates your ability to administer Splunk Cloud environments. This certification demonstrates proficiency in managing users, implementing security, configuring data inputs, and maintaining Splunk Cloud instances.

While there are no strict prerequisites, Splunk recommends having practical experience administering Splunk Cloud environments and completing the Splunk Cloud Administrator course. It's also helpful to have foundational knowledge of Splunk fundamentals and basic system administration concepts.

The SPLK-1005 exam typically consists of 60 multiple-choice questions and you have 90 minutes to complete it. You need to achieve a passing score of approximately 70% to earn the certification.

The exam covers key administrative topics including user and role management, authentication and authorization, data input configuration, Splunk Cloud deployment architecture, monitoring and alerting, and cloud-specific administration tasks. It also includes knowledge of backup and recovery procedures and security best practices in Splunk Cloud.

Splunk offers official training courses, study guides, and practice exams to help you prepare for the SPLK-1005. Combining hands-on experience with Splunk Cloud, official Splunk training materials, and practice exams is the most effective way to prepare for this certification.
Exam Details
  • Exam CodeSPLK-1005
  • VendorSplunk
  • Total Questions80
  • Duration75 min
  • LanguageEnglish
  • Last UpdatedSep 4, 2026
4.9/5

Pass SPLK-1005 First Time

Get all 80 exam questions with verified answers and 90-day free updates.

Buy Now & Pass
  • PDF + Practice Test Bundle
  • 90-Day Free Updates
  • 100% Money-Back Guarantee
  • Instant Download
  • 24/7 Customer Support
99% Pass Rate Trusted by 50,000+ IT professionals