
SplunkCore Certified Power User
Domain 10Objective 3
Use the CIM Add-On to Normalize Data SPLK-1002 Practice Questions (Page 1)
Part of the Using the Common Information Model (CIM) Add-On domain, which accounts for 10% of the SPLK-1002 exam. Splunk does not publish an official question count, but from its 60-minute exam (~25–40 total, ~3–4 in this domain), expect 1–1 from this objective — we provide 25 practice questions to prepare you well beyond it. (estimate)
25questions here
5free pages
6concepts
10%of the exam
Questions 1–5
- 1
A team is troubleshooting why events from a new data source are not appearing in the CIM Network Traffic data model. They have confirmed that the events are tagged correctly. What should they check next?
Select an answer first - 2
A company has multiple teams using Splunk with different data sources. They want to create a unified security dashboard that shows authentication and network traffic events. The teams have different field names for similar data. What is the best way to achieve this?
Select an answer first - 3
A security analyst wants to correlate authentication events from Windows, Linux, and VPN logs in a single search. How does the CIM Add-On help achieve this?
Select an answer first - 4
When configuring a new data input for firewall logs, what is the recommended approach to ensure the data is normalized by the CIM Add-On?
Select an answer first - 5
An administrator has enabled Data Model acceleration for the CIM Authentication data model. What is the primary benefit of this action?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Splunk. “SPLK-1002” is a trademark of its owner, used for identification only.