Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified Network Professional Security

Domain 3Objective 5

3.5 Configure Splunk to Ingest Cloud Logging and Monitoring Data from Other Security Solutions 350-701 Practice Questions (Page 4)

Part of the Cloud Security domain, which accounts for 15% of the 350-701 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–12 in this domain), expect 1–2 from this objective — we provide 24 practice questions to prepare you well beyond it. (estimate)

24questions here
5free pages
5concepts
15%of the exam

Questions 16–20

  1. 16expert · hard

    A company wants to ingest Azure Active Directory (Azure AD) logs into Splunk. They have configured the Splunk Add-on for Microsoft Cloud Services to use an Azure AD app registration with the required permissions. However, the add-on is unable to authenticate. What is the most likely cause?

    Select an answer first
  2. 17expert · hard

    A security team is ingesting logs from a custom security appliance into Splunk. The logs are in a key-value format, but the keys contain spaces (e.g., 'Source IP=192.168.1.1'). The team wants to extract these as fields. What is the best approach?

    Select an answer first
  3. 18application · medium

    A security operations center uses a third-party IDS/IPS that sends alerts via syslog. They want to ingest these alerts into Splunk for correlation with other security data. They have configured a Splunk universal forwarder to send syslog data to the indexer. The data is being received, but the events appear as a single large blob of text with no field extraction. What should they do to properly parse the IDS/IPS alerts?

    Select an answer first
  4. 19expert · hard

    A company wants to ingest Azure Monitor logs into Splunk. They have configured the Splunk Add-on for Microsoft Cloud Services to use an Azure event hub. The add-on is receiving data, but the events are not being parsed correctly — the fields are not being extracted. What is the most likely cause?

    Select an answer first
  5. 20application · medium

    A company uses a third-party SIEM that sends CEF-formatted logs to Splunk via syslog. The logs are being received, but the field extractions are not working correctly — the event is not being parsed into CEF fields. What should the administrator do to fix this?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-701” is a trademark of its owner, used for identification only.