Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Splunk logo

SplunkCloud Certified Admin

Domain 5Objective 3

Configure a Forwarder to Splunk Cloud CLOUD-CERTIFIED-ADMIN Practice Questions (Page 1)

Part of the Getting Data in Cloud domain, which accounts for 15% of the CLOUD-CERTIFIED-ADMIN exam. Splunk does not publish an official question count, but from its 75-minute exam (~30–50 total, ~5–8 in this domain), expect 1–2 from this objective — we provide 27 practice questions to prepare you well beyond it. (estimate)

27questions here
6free pages
8concepts
15%of the exam

Questions 1–5

  1. 1foundation · easy

    In inputs.conf, which stanza is used to monitor a file or directory for new data?

    Select an answer first
  2. 2application · easy

    A team needs to forward data from a server that also runs a Splunk search head. They want to minimize resource usage on this server while still sending data to Splunk Cloud. Which forwarder type should they use?

    Select an answer first
  3. 3application · medium

    An admin notices that a universal forwarder is not sending data to Splunk Cloud. The forwarder service is running, and the admin can ping the Splunk Cloud endpoint. What is the next best step to troubleshoot the issue?

    Select an answer first
  4. 4application · medium

    An organization has 200 universal forwarders deployed across multiple sites. They need to push a new app that configures a specific file input to all forwarders. The admin wants to manage this centrally without manually editing each forwarder. What should the admin do?

    Select an answer first
  5. 5application · medium

    A company requires that all data sent from their forwarders to Splunk Cloud be encrypted in transit. They are configuring a new universal forwarder. What must they ensure in the outputs.conf configuration?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Splunk. “CLOUD-CERTIFIED-ADMIN” is a trademark of its owner, used for identification only.