
CiscoCertified Network Professional Security
Domain 3Objective 5
3.5 Configure Splunk to Ingest Cloud Logging and Monitoring Data from Other Security Solutions 350-701 Practice Questions (Page 1)
Part of the Cloud Security domain, which accounts for 15% of the 350-701 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–12 in this domain), expect 1–2 from this objective — we provide 24 practice questions to prepare you well beyond it. (estimate)
24questions here
5free pages
5concepts
15%of the exam
Questions 1–5
- 1
A security team needs to ingest AWS CloudTrail logs into Splunk. They have an existing Splunk Enterprise deployment on-premises and want to use the AWS add-on. The team has created an IAM role with the required permissions and configured the add-on to use that role. However, no data appears in Splunk. Which configuration step is most likely missing?
Select an answer first - 2
A company ingests Google Cloud Logging data into Splunk using the Google Cloud add-on. The logs contain a field called 'severity' with values like 'INFO', 'WARNING', and 'ERROR'. The security team wants to map these to Splunk's native severity levels (info, warn, error) for consistent dashboards. What is the most efficient way to achieve this?
Select an answer first - 3
Which Splunk feature is commonly used to receive logs from third-party security solutions that support HTTP-based event delivery?
Select an answer first - 4
Which Azure service provides a unified platform for collecting and analyzing logs and metrics from Azure resources?
Select an answer first - 5
A company uses Azure Monitor to collect activity logs from their Azure subscription. They want to forward these logs to Splunk for centralized security analysis. They have set up an Azure event hub and configured the diagnostic settings to stream the activity logs to the event hub. In Splunk, they have installed the Splunk Add-on for Microsoft Cloud Services and configured the input for Azure Event Hubs. However, no logs are appearing in Splunk. What is the most likely cause?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-701” is a trademark of its owner, used for identification only.