Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Splunk logo

SplunkCore Certified User

Domain 7Objective 1

Describe Lookups SPLK-1001 Practice Questions (Page 3)

Part of the Creating and Using Lookups domain, which accounts for 6% of the SPLK-1001 exam. Splunk does not publish an official question count, but from its 60-minute exam (~25–40 total, ~2–2 in this domain), expect 1–1 from this objective — we provide 20 practice questions to prepare you well beyond it. (estimate)

20questions here
4free pages
4concepts
6%of the exam

Questions 11–15

  1. 11application · medium

    A Splunk admin needs to create a lookup that will be used to enrich events with a list of approved applications. The list is maintained in a CSV file and is updated weekly. Which lookup type should the admin use?

    Select an answer first
  2. 12foundation · easy

    In Splunk, what is the primary purpose of a lookup?

    Select an answer first
  3. 13foundation · easy

    A security analyst wants to add a 'severity' field to events based on the 'event_code' field. Which lookup use case does this represent?

    Select an answer first
  4. 14expert · hard

    A Splunk admin is troubleshooting a search that is not returning the expected 'owner' field after a lookup is applied. The lookup is defined correctly and the CSV file contains the owner information. What is the most likely cause of the missing field?

    Select an answer first
  5. 15foundation · easy

    When would you choose a dynamic lookup (KV store) over a static lookup (CSV file)?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Splunk. “SPLK-1001” is a trademark of its owner, used for identification only.