Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Splunk logo

SplunkCore Certified Power User

Domain 3Objective 5

Report on Transactions SPLK-1002 Practice Questions (Page 2)

Part of the Correlating Events domain, which accounts for 15% of the SPLK-1002 exam. Splunk does not publish an official question count, but from its 60-minute exam (~25–40 total, ~4–6 in this domain), expect 1–1 from this objective — we provide 19 practice questions to prepare you well beyond it. (estimate)

19questions here
4free pages
6concepts
15%of the exam

Questions 6–10

  1. 6foundation · easy

    What is the primary purpose of the transaction command in Splunk?

    Select an answer first
  2. 7foundation · easy

    What does the keepevicted option do in the transaction command?

    Select an answer first
  3. 8application · medium

    An analyst is using the transaction command and wants to see the number of events in each transaction. They also want to filter out transactions that have fewer than 3 events. Which approach should they take?

    Select an answer first
  4. 9application · medium

    After running a transaction command, an analyst wants to see the start time of each transaction. Which field should they use?

    Select an answer first
  5. 10expert · hard

    A security analyst is investigating a potential breach. They need to group all events related to a specific user session, but the session may have gaps of up to 10 minutes between events. They also want to see the total number of events in each session and the duration. Which transaction command should they use?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Splunk. “SPLK-1002” is a trademark of its owner, used for identification only.