
SplunkCloud Certified Admin
Domain 4Objective 1
Review Splunk Configuration Files and Directories CLOUD-CERTIFIED-ADMIN Practice Questions (Page 1)
Part of the Splunk Configuration Files domain, which accounts for 5% of the CLOUD-CERTIFIED-ADMIN exam. Splunk does not publish an official question count, but from its 75-minute exam (~30–50 total, ~2–3 in this domain), expect 1–1 from this objective — we provide 23 practice questions to prepare you well beyond it. (estimate)
23questions here
5free pages
5concepts
5%of the exam
Questions 1–5
- 1
An admin is planning to make a significant change to a props.conf file in an app's local directory. The change will affect multiple sourcetypes. The admin wants to minimize the risk of breaking existing functionality. Which approach is the most prudent?
Select an answer first - 2
An admin is creating a new app and needs to define which fields are extracted at index time for a custom sourcetype. The admin also needs to define a regex-based transformation to extract the fields. Which two configuration files must the admin create in the app's default directory?
Select an answer first - 3
Which of the following is a best practice when editing configuration files in Splunk?
Select an answer first - 4
A Splunk admin is troubleshooting why a search-time field extraction is not working for a specific user, even though it works for other users. The admin has verified that the extraction is defined in the app's default/props.conf. What is the most likely cause?
Select an answer first - 5
An admin is troubleshooting a configuration issue where a setting in an app's local/inputs.conf is not taking effect. The admin has confirmed that the file exists and is correctly formatted. Which btool command should the admin run to determine if the setting is being overridden by a higher-precedence configuration?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Splunk. “CLOUD-CERTIFIED-ADMIN” is a trademark of its owner, used for identification only.