Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Splunk logo

SplunkCore Certified Power User

Domain 10Objective 1

Describe the Splunk CIM SPLK-1002 Practice Questions (Page 1)

Part of the Using the Common Information Model (CIM) Add-On domain, which accounts for 10% of the SPLK-1002 exam. Splunk does not publish an official question count, but from its 60-minute exam (~25–40 total, ~3–4 in this domain), expect 1–1 from this objective — we provide 27 practice questions to prepare you well beyond it. (estimate)

27questions here
6free pages
7concepts
10%of the exam

Questions 1–5

  1. 1application · medium

    A Splunk admin has just installed the Splunk CIM Add-On in a new environment. The admin wants to verify that the Add-On is providing the expected data models and tags. What is the most direct way to confirm this?

    Select an answer first
  2. 2application · medium

    A Splunk admin is ingesting Windows Security logs. The logs have a field 'EventCode' that indicates the type of event (e.g., 4624 for successful logon). The admin wants to use the CIM Authentication data model to search for successful logons. What must be configured for the 'EventCode' field to be used by the data model?

    Select an answer first
  3. 3application · medium

    A Splunk admin is setting up the CIM for the first time. They notice that some events have the correct fields but are not appearing in the data model searches. The admin has already installed the CIM Add-On. What is the most likely missing configuration?

    Select an answer first
  4. 4expert · hard

    A large enterprise has multiple Splunk environments (production and development). The security team uses the CIM in production for incident response. They are now planning to onboard a new data source (a custom IDS) that has a unique field structure. The team wants to ensure the new data is immediately searchable via the CIM in production without disrupting existing searches. What is the best approach?

    Select an answer first
  5. 5foundation · easy

    How does the CIM enable cross-source correlation and analysis?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Splunk. “SPLK-1002” is a trademark of its owner, used for identification only.