Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Splunk logo

SplunkCore Certified Power User

Domain 10Objective 2

List the Knowledge Objects Included with the Splunk CIM Add-On SPLK-1002 Practice Questions (Page 2)

Part of the Using the Common Information Model (CIM) Add-On domain, which accounts for 10% of the SPLK-1002 exam. Splunk does not publish an official question count, but from its 60-minute exam (~25–40 total, ~3–4 in this domain), expect 1–1 from this objective — we provide 24 practice questions to prepare you well beyond it. (estimate)

24questions here
5free pages
6concepts
10%of the exam

Questions 6–10

  1. 6application · medium

    A security team wants to run a search that uses the CIM 'Network' data model to investigate DNS traffic. They have enabled the relevant event types and tags. What is the primary benefit of using the data model instead of searching the raw index directly?

    Select an answer first
  2. 7foundation · easy

    Which tag is used by the CIM Add-On to map authentication events to the Authentication data model?

    Select an answer first
  3. 8foundation · easy

    What is the primary purpose of the event types included in the Splunk CIM Add-On?

    Select an answer first
  4. 9application · medium

    A company is ingesting proxy logs from a vendor that uses a non-standard field name for the destination IP address. They want to use the CIM Web data model. What is the most appropriate way to handle this using the CIM Add-On?

    Select an answer first
  5. 10foundation · easy

    What is the purpose of the field extractions included in the CIM Add-On?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Splunk. “SPLK-1002” is a trademark of its owner, used for identification only.