
SplunkCore Certified Power User
Domain 10Objective 1
Describe the Splunk CIM SPLK-1002 Practice Questions (Page 5)
Part of the Using the Common Information Model (CIM) Add-On domain, which accounts for 10% of the SPLK-1002 exam. Splunk does not publish an official question count, but from its 60-minute exam (~25–40 total, ~3–4 in this domain), expect 1–1 from this objective — we provide 27 practice questions to prepare you well beyond it. (estimate)
27questions here
6free pages
7concepts
10%of the exam
Questions 21–25
- 21
How do CIM tags facilitate the automatic mapping of data to the appropriate model?
Select an answer first - 22
What is the role of the Splunk CIM Add-On?
Select an answer first - 23
A company ingests proxy logs where the client IP is stored in a field named 'c_ip' and the destination URL is in 'cs_uri_path'. The security team wants to use the CIM Web data model to analyze this data. What is the role of CIM field extractions in this scenario?
Select an answer first - 24
Which of the following is an example of a CIM data model domain?
Select an answer first - 25
A security operations team ingests firewall logs from Palo Alto, Cisco ASA, and Check Point devices. They want to run a single search that correlates failed login attempts across all three sources without writing separate queries for each vendor's log format. Which approach best achieves this using the Splunk CIM?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Splunk. “SPLK-1002” is a trademark of its owner, used for identification only.