
SplunkCore Certified Power User
Domain 10Objective 2
List the Knowledge Objects Included with the Splunk CIM Add-On SPLK-1002 Practice Questions (Page 3)
Part of the Using the Common Information Model (CIM) Add-On domain, which accounts for 10% of the SPLK-1002 exam. Splunk does not publish an official question count, but from its 60-minute exam (~25–40 total, ~3–4 in this domain), expect 1–1 from this objective — we provide 24 practice questions to prepare you well beyond it. (estimate)
24questions here
5free pages
6concepts
10%of the exam
Questions 11–15
- 11
A team is ingesting authentication logs from multiple sources (VPN, Active Directory, and Linux SSH). They want to use the CIM Authentication data model to search across all sources. What is the primary purpose of the CIM tags in this scenario?
Select an answer first - 12
A large enterprise has multiple Splunk environments (production, staging, and development). They have installed the CIM Add-On in all environments. In the production environment, they have enabled event types and tags for their firewall data, but the data is not appearing in the Network data model. In the staging environment, the same configuration works correctly. What is the most likely cause of this discrepancy?
Select an answer first - 13
A Splunk admin is working with the CIM Add-On and needs to enrich their endpoint data with additional context about process names. Which knowledge object included with the CIM Add-On would be most appropriate for this task?
Select an answer first - 14
A Splunk admin is working with the CIM Add-On and needs to troubleshoot why a specific event is not appearing in the 'Network' data model. They have verified that the event type is enabled and the tags are applied. What is the next most logical step to diagnose the issue?
Select an answer first - 15
What is the role of tags in the Splunk CIM Add-On?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Splunk. “SPLK-1002” is a trademark of its owner, used for identification only.