Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Splunk logo

SplunkCore Certified Power User

Domain 10Objective 3

Use the CIM Add-On to Normalize Data SPLK-1002 Practice Questions (Page 2)

Part of the Using the Common Information Model (CIM) Add-On domain, which accounts for 10% of the SPLK-1002 exam. Splunk does not publish an official question count, but from its 60-minute exam (~25–40 total, ~3–4 in this domain), expect 1–1 from this objective — we provide 25 practice questions to prepare you well beyond it. (estimate)

25questions here
5free pages
6concepts
10%of the exam

Questions 6–10

  1. 6application · medium

    A company ingests firewall logs from a vendor that uses the field 'source_ip'. The CIM Network Traffic data model expects 'src_ip'. The team has created a field alias in the CIM Add-On. What is the result?

    Select an answer first
  2. 7foundation · easy

    A search using the Authentication data model returns no results, but the underlying events exist. What is the most likely cause?

    Select an answer first
  3. 8expert · hard

    An organization is ingesting data from a new security appliance. The data has a unique source type. The team wants to use the CIM Endpoint data model. They have created a field alias for the process name field. What else must they do to ensure the events are normalized?

    Select an answer first
  4. 9application · medium

    An analyst is investigating a security incident and wants to use the CIM Endpoint data model to search for process execution events. Which component of the data model should the analyst use to ensure they are searching the correct events?

    Select an answer first
  5. 10foundation · easy

    Which of the following is a key CIM data model used for analyzing security-related events?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Splunk. “SPLK-1002” is a trademark of its owner, used for identification only.