Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Splunk logo

SplunkCloud Certified Admin

Domain 11Objective 1

Explain How Data Transformations Are Defined and Invoked CLOUD-CERTIFIED-ADMIN Practice Questions (Page 1)

Part of the Manipulating Raw Data domain, which accounts for 10% of the CLOUD-CERTIFIED-ADMIN exam. Splunk does not publish an official question count, but from its 75-minute exam (~30–50 total, ~3–5 in this domain), expect 1–2 from this objective — we provide 18 practice questions to prepare you well beyond it. (estimate)

18questions here
4free pages
2concepts
10%of the exam

Questions 1–5

  1. 1expert · hard

    An admin has a sourcetype where a regex-based transformation is applied at index time. The admin needs to temporarily disable the transformation for troubleshooting without deleting the configuration. What is the best approach?

    Select an answer first
  2. 2application · medium

    A Splunk admin needs to mask credit card numbers in events from a payment application. The masking must happen before data is stored, so that raw events on disk never contain the full card number. Which approach should the admin use?

    Select an answer first
  3. 3foundation · easy

    In Splunk, what is the primary purpose of a data transformation?

    Select an answer first
  4. 4application · medium

    A team wants to enrich events with a field that is derived from a regex match on the raw event text. The field should be available in all searches without requiring a search-time command. Which method should the admin use?

    Select an answer first
  5. 5expert · hard

    An admin needs to apply a regex-based transformation to a sourcetype that is ingested by multiple forwarders. The transformation must be applied consistently regardless of which forwarder sends the data. Where should the transformation be configured?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Splunk. “CLOUD-CERTIFIED-ADMIN” is a trademark of its owner, used for identification only.