
SplunkCloud Certified Admin
Domain 8Objective 5
Use the HTTP Event Collector (HEC) to Get Data into Splunk CLOUD-CERTIFIED-ADMIN Practice Questions (Page 6)
Part of the Network and Other Inputs domain, which accounts for 10% of the CLOUD-CERTIFIED-ADMIN exam. Splunk does not publish an official question count, but from its 75-minute exam (~30–50 total, ~3–5 in this domain), expect 1–1 from this objective — we provide 34 practice questions to prepare you well beyond it. (estimate)
34questions here
7free pages
9concepts
10%of the exam
Questions 26–30
- 26
Which HTTP method is used to send events to the HEC endpoint?
Select an answer first - 27
A company wants to send data from a legacy application that only supports HTTP (not HTTPS) to Splunk Cloud. The security team requires all data in transit to be encrypted. What is the best course of action?
Select an answer first - 28
An admin needs to create a HEC token for a team that sends data from multiple applications. The admin wants to restrict the token so it can only send to the 'main' index, but the team also needs to send data to the 'archive' index for long-term storage. The admin has decided to create two tokens. What is the most secure way to configure this?
Select an answer first - 29
An admin is setting up HEC for a new application. The application will send events with a sourcetype of 'app:custom'. The admin wants to ensure that this sourcetype is automatically recognized and parsed correctly. What is the most efficient way to achieve this?
Select an answer first - 30
How does gzip compression help when sending data to HEC?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Splunk. “CLOUD-CERTIFIED-ADMIN” is a trademark of its owner, used for identification only.