Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Splunk logo

SplunkCore Certified Power User

Domain 10Objective 2

List the Knowledge Objects Included with the Splunk CIM Add-On SPLK-1002 Practice Questions (Page 1)

Part of the Using the Common Information Model (CIM) Add-On domain, which accounts for 10% of the SPLK-1002 exam. Splunk does not publish an official question count, but from its 60-minute exam (~25–40 total, ~3–4 in this domain), expect 1–1 from this objective — we provide 24 practice questions to prepare you well beyond it. (estimate)

24questions here
5free pages
6concepts
10%of the exam

Questions 1–5

  1. 1foundation · easy

    What is the structure of a CIM data model used for?

    Select an answer first
  2. 2application · medium

    An analyst is investigating a security incident and wants to search for all authentication-related events across their environment. They have the CIM Add-On installed. Which approach would be most efficient for this task?

    Select an answer first
  3. 3application · medium

    An administrator is troubleshooting why Windows Event Log data is not appearing in the CIM 'Windows' data model. The data is being indexed correctly and the CIM Add-On is installed. Which of the following is the most likely reason the data is not showing up in the data model?

    Select an answer first
  4. 4application · medium

    An organization is using the CIM Add-On to normalize web proxy logs. After enabling the relevant event types and tags, they notice that the 'src' field is not being populated in the Web data model. Which knowledge object from the CIM Add-On is most likely responsible for populating this field?

    Select an answer first
  5. 5application · medium

    A security analyst has ingested firewall logs into Splunk and wants to use the CIM Add-On to make the data searchable via the Network data model. The analyst has already installed the add-on. Which additional action is required to ensure the firewall data is properly mapped to the Network data model?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Splunk. “SPLK-1002” is a trademark of its owner, used for identification only.