
SplunkCore Certified Power User
Domain 9Objective 2
Identify Data Model Attributes SPLK-1002 Practice Questions (Page 1)
Part of the Creating Data Models domain, which accounts for 10% of the SPLK-1002 exam. Splunk does not publish an official question count, but from its 60-minute exam (~25–40 total, ~3–4 in this domain), expect 1–1 from this objective — we provide 13 practice questions to prepare you well beyond it. (estimate)
13questions here
3free pages
5concepts
10%of the exam
Questions 1–5
- 1
A Splunk admin is designing a data model for a security operations team. The team wants to ensure that every event in the 'Authentication' dataset has a 'user' field, because their searches always filter on this field. However, they also want to allow events that do not have a 'source' field, as some authentication sources do not provide it. How should the admin define the 'user' and 'source' attributes?
Select an answer first - 2
A Splunk admin is designing a data model for a network monitoring system. The 'bytes_in' field is sometimes missing from events. The admin wants to run a search that calculates the average bytes_in for all events, but only for events that have the field. The admin wants to ensure that the data model does not exclude events that lack the field. What attribute type should be used for 'bytes_in'?
Select an answer first - 3
What does it mean when an attribute is marked as 'required' in a data model?
Select an answer first - 4
Which of the following is a property of an attribute in a Splunk data model?
Select an answer first - 5
Why is attribute inheritance useful in a Splunk data model?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Splunk. “SPLK-1002” is a trademark of its owner, used for identification only.