
SplunkCore Certified Power User
Domain 9Objective 2
Identify Data Model Attributes SPLK-1002 Practice Questions (Page 2)
Part of the Creating Data Models domain, which accounts for 10% of the SPLK-1002 exam. Splunk does not publish an official question count, but from its 60-minute exam (~25–40 total, ~3–4 in this domain), expect 1–1 from this objective — we provide 13 practice questions to prepare you well beyond it. (estimate)
13questions here
3free pages
5concepts
10%of the exam
Questions 6–10
- 6
A Splunk admin has created a data model for network traffic. The admin wants to run a search that uses the data model to find all events where the 'dest_port' attribute is equal to 443. Which search syntax correctly uses the data model attribute?
Select an answer first - 7
A Splunk admin is building a data model for sales transactions. The admin wants to define an attribute called 'amount' that represents the transaction amount. The admin also wants to ensure that the attribute is available in searches that use the data model. What is the primary purpose of defining this attribute in the data model?
Select an answer first - 8
What does it mean for an attribute to be multivalued in a Splunk data model?
Select an answer first - 9
A Splunk admin is creating a data model for application logs. The 'response_time' field is a numeric value that represents milliseconds. The admin wants to ensure that searches using the data model can perform statistical operations like average on this field. What should the admin set for the 'response_time' attribute?
Select an answer first - 10
A Splunk admin is creating a data model for authentication logs. The 'user' field can contain multiple values (e.g., when a single event records multiple failed login attempts). The admin wants to ensure that searches using the data model can return all values for the 'user' field. What property must be enabled for the 'user' attribute?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Splunk. “SPLK-1002” is a trademark of its owner, used for identification only.