
SplunkCore Certified Advanced Power User
Domain 1Objective 2
String and Conditional Functions core-certified-advanced-power-user Practice Questions (Page 2)
Part of the Advanced Search Commands domain, which makes up ~19% of our current practice bank. Splunk does not publish an official question count, but from its 60-minute exam (~25–40 total, ~5–8 in this domain), expect 1–2 from this objective — we provide 16 practice questions to prepare you well beyond it. (estimate)
16questions here
4free pages
5concepts
Questions 6–10
- 6
Which conversion function would you use to convert a numeric field into a string so that it can be concatenated with other text in a search result?
Select an answer first - 7
Which conditional function returns the first non-null value from a list of arguments?
Select an answer first - 8
A Splunk admin is building a search that processes log messages. The 'message' field contains text, and the admin needs to create a 'severity' field based on keywords: 'CRITICAL' or 'FATAL' → 'High', 'ERROR' → 'Medium', 'WARNING' → 'Low', and anything else → 'Info'. The matching should be case-insensitive. Which search correctly implements this keyword-based classification?
Select an answer first - 9
A data analyst is working with JSON data stored in a field called 'payload'. The analyst needs to convert this JSON string to a format that can be used in further eval operations, such as extracting specific keys. Which function should the analyst use?
Select an answer first - 10
A Splunk analyst is working with a dataset that has two fields: 'primary_email' and 'backup_email'. The analyst needs to create a field 'effective_email' that uses primary_email if it exists, otherwise backup_email. If both are null, the field should be 'no_email'. Which eval expression correctly implements this logic?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Splunk. “core-certified-advanced-power-user” is a trademark of its owner, used for identification only.