
SplunkCloud Certified Admin
Domain 11Objective 2
Use Transformations with Props.conf and Transforms.conf to Modify Raw Data CLOUD-CERTIFIED-ADMIN Practice Questions (Page 1)
Part of the Manipulating Raw Data domain, which accounts for 10% of the CLOUD-CERTIFIED-ADMIN exam. Splunk does not publish an official question count, but from its 75-minute exam (~30–50 total, ~3–5 in this domain), expect 1–2 from this objective — we provide 12 practice questions to prepare you well beyond it. (estimate)
12questions here
3free pages
7concepts
10%of the exam
Questions 1–5
- 1
Which Splunk command is commonly used to test a regex pattern before applying it in a transform?
Select an answer first - 2
Given the following props.conf stanza, which transform(s) will be applied to events matching this sourcetype? [apache_access] TRANSFORMS = clean, extract_ip
Select an answer first - 3
In a transform, what does SOURCE_KEY specify?
Select an answer first - 4
An admin configured a transform to extract a timestamp from raw events, but after indexing, the field is not populated. The regex works in a regex tester. What is the most likely reason the transform is not applied?
Select an answer first - 5
A transform is intended to extract a value from the `_meta` field. Which setting would achieve this?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Splunk. “CLOUD-CERTIFIED-ADMIN” is a trademark of its owner, used for identification only.