
SplunkCore Certified User
Domain 7Objective 1
Describe Lookups SPLK-1001 Practice Questions (Page 4)
Part of the Creating and Using Lookups domain, which accounts for 6% of the SPLK-1001 exam. Splunk does not publish an official question count, but from its 60-minute exam (~25–40 total, ~2–2 in this domain), expect 1–1 from this objective — we provide 20 practice questions to prepare you well beyond it. (estimate)
20questions here
4free pages
4concepts
6%of the exam
Questions 16–20
- 16
A Splunk admin has a CSV file containing IP-to-hostname mappings that is updated weekly by a separate team. The admin wants to use this file as a lookup. What must the admin do to make this file usable as a lookup in Splunk?
Select an answer first - 17
A Splunk user has a CSV file with employee IDs and their corresponding office locations. The user wants to add the office location to firewall logs that contain employee IDs. What is the correct way to use this CSV file as a lookup?
Select an answer first - 18
A security analyst frequently investigates failed login events. The raw events contain only a user ID (e.g., 'u1234'), but the analyst needs to see the employee's full name and department in every search result without manually joining data each time. What should the analyst configure to automatically enrich these events with the employee details?
Select an answer first - 19
Which of the following is a characteristic of a KV store lookup in Splunk?
Select an answer first - 20
Which of the following file types can be used as a lookup in Splunk?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to SPLK-1001
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Splunk. “SPLK-1001” is a trademark of its owner, used for identification only.