Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Splunk logo

SplunkCloud Certified Admin

Domain 11Objective 1

Explain How Data Transformations Are Defined and Invoked CLOUD-CERTIFIED-ADMIN Practice Questions (Page 3)

Part of the Manipulating Raw Data domain, which accounts for 10% of the CLOUD-CERTIFIED-ADMIN exam. Splunk does not publish an official question count, but from its 75-minute exam (~30–50 total, ~3–5 in this domain), expect 1–2 from this objective — we provide 18 practice questions to prepare you well beyond it. (estimate)

18questions here
4free pages
2concepts
10%of the exam

Questions 11–15

  1. 11foundation · easy

    How is a data transformation typically invoked at index time in Splunk?

    Select an answer first
  2. 12application · medium

    An admin wants to mask a sensitive pattern in events from a specific sourcetype. The masking should be applied only to new data being indexed, not to historical data. Which approach should be used?

    Select an answer first
  3. 13application · medium

    A team wants to extract a field from raw events at index time so that the field is available in all searches. The admin has defined the regex in transforms.conf. What is the next step to invoke the transformation?

    Select an answer first
  4. 14expert · hard

    An admin is configuring a transformation to extract a field from raw events. The admin wants the field to be available in all searches without requiring a search-time command. However, the admin also wants to be able to test the regex before applying it to production data. What is the best approach?

    Select an answer first
  5. 15application · medium

    An admin is troubleshooting why a regex-based transformation defined in transforms.conf is not being applied to a specific sourcetype. The admin has already confirmed that the regex works in a search. What is the most likely reason the transformation is not being invoked?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Splunk. “CLOUD-CERTIFIED-ADMIN” is a trademark of its owner, used for identification only.