Key details for this exam, checked against the published exam outline
Each question shows the correct answer and an explanation of why it is right
Which of the following is a valid method to test if a forwarder can successfully send data to Splunk Cloud?
Using the oneshot command allows a direct check for data reception in the cloud environment. Logs can be verified in the cloud after the forwarder sends them. [Reference: Splunk Docs on testing forwarder data inputs]
What is the recommended approach to collect data from network devices?
The recommended approach to collect data from network devices is to use a Syslog server with a Universal Forwarder (UF) installed. The network devices send data to the Syslog server, which then forwards the data to Splunk Cloud using the Universal Forwarder. This method ensures reliable data ingestion and processing while maintaining flexibility in handling different types of network device data.
Splunk Documentation Reference: Best practices for getting data in
Which of the following is true when integrating LDAP authentication?
When integrating LDAP authentication with Splunk, new user data is cached the first time a user logs in. This means that Splunk does not store LDAP usernames and passwords; instead, it relies on the LDAP server for authentication. The mapping of LDAP groups to Splunk roles must be configured manually; it does not happen automatically. Additionally, Splunk Cloud supports various LDAP servers, not just Active Directory.
Splunk Documentation Reference: LDAP Authentication
Which of the following tasks is not managed by the Splunk Cloud administrator?
In Splunk Cloud, several administrative tasks are managed by the Splunk Cloud administrator, but certain tasks related to the underlying infrastructure and core software management are handled by Splunk itself.
B . Upgrading the indexer's Splunk software is the correct answer. Upgrading Splunk software on indexers is a task that is managed by Splunk's operations team, not by the Splunk Cloud administrator. The Splunk Cloud administrator handles tasks like forwarding events, managing knowledge objects, and creating users and roles, but the underlying software upgrades and maintenance are managed by Splunk as part of the managed service.
Splunk Documentation Reference:
Splunk Cloud Administration
What Splunk command will allow an administrator to view the runtime configuration instructions for a monitored file in Inputs. cont on the forwarders?
To view the runtime configuration instructions for a monitored file in inputs.conf on the forwarder, the correct command to use involves accessing the internal REST API that provides details on data inputs.
C . ./splunk _internal rest /services/data/inputs/monitor is the correct answer. This command uses Splunk's internal REST endpoint to retrieve information about monitored files, including their runtime configurations as defined in inputs.conf.
Splunk Documentation Reference:
Splunk REST API - Data Inputs
80 questions covering all exam domains, starting from $20
Exam domains verified against: Official Splunk SPLK-1005 exam guide, last checked September 2026.
Cloud topology and tasks managed by the Splunk cloud administrator. Focuses on primary differences between Splunk Cloud and Splunk Enterprise to understand platform-specific administration approaches.
Definition of a Splunk index and characteristics of indexes in cloud environments. Covers monitoring indexing activities and retrieving data from indexes.
Administration of Splunk user roles and responsibility assignments. Focuses on integrating Splunk with LDAP for enterprise authentication.
Sample question from this domain above: Q5
Configuration files and directories in Splunk environments. Covers configuration precedence and sub-topics related to index time and search time processes.
Splunk forwarder types and the role of forwarders in data ingestion. Configuration of a forwarder to Splunk Cloud and testing forwarder connections.
Splunk Deployment Server and the use of forwarder management. Configuration of forwarders as deployment clients and management through deployment apps.
Sample question from this domain above: Q4
Splunk process for inputting data and how data flows through Splunk. Creating file and directory monitor inputs to capture data from various sources.
Creating network inputs using TCP and UDP protocols. Creating basic scripted inputs and identifying Windows input types and their uses.
Default processing during the input phase. Configuration of input phase options such as source type fine-tuning and character set encoding.
Default processing during parsing and event line breaking optimization. How timestamps and time zones are extracted or assigned to events. Using data preview to validate event creation.
Data transformations and how they are invoked. Using transformations with props.conf and transforms.conf to modify raw data and SEDCMD for data manipulation.
Sample question from this domain above: Q2
Process for installing apps in Splunk Cloud. Understanding private apps and how they are managed within Splunk environments.
How to isolate problems before contacting Splunk Cloud Support. Defining the process and best practices for working with Splunk Cloud Support.
Common questions about the exam itself