
SplunkCore Certified Power User
Domain 10Objective 3
Use the CIM Add-On to Normalize Data SPLK-1002 Practice Questions (Page 3)
Part of the Using the Common Information Model (CIM) Add-On domain, which accounts for 10% of the SPLK-1002 exam. Splunk does not publish an official question count, but from its 60-minute exam (~25–40 total, ~3–4 in this domain), expect 1–1 from this objective — we provide 25 practice questions to prepare you well beyond it. (estimate)
25questions here
5free pages
6concepts
10%of the exam
Questions 11–15
- 11
A team is troubleshooting why events from a new data source are not appearing in the CIM Authentication data model. They have confirmed that the events are tagged correctly, the source type is correct, and the field aliases are defined. What is the next step to diagnose the issue?
Select an answer first - 12
A company has multiple teams using Splunk for different purposes (security, IT operations). Each team has its own field naming conventions. The leadership wants to enable cross-team searches and dashboards. What is the best approach?
Select an answer first - 13
What is the primary purpose of the Splunk Common Information Model (CIM) Add-On?
Select an answer first - 14
Which search would you use to verify that events are correctly tagged for the Authentication data model?
Select an answer first - 15
An analyst is verifying that events from a new data source are correctly normalized. They run a search against the CIM Network Traffic data model and see that the src_ip field is populated, but the dest_ip field is empty for some events. The raw data contains a field named 'destination_ip'. What is the most likely cause?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Splunk. “SPLK-1002” is a trademark of its owner, used for identification only.