
SplunkCore Certified Power User
Domain 10Objective 3
Use the CIM Add-On to Normalize Data SPLK-1002 Practice Questions (Page 4)
Part of the Using the Common Information Model (CIM) Add-On domain, which accounts for 10% of the SPLK-1002 exam. Splunk does not publish an official question count, but from its 60-minute exam (~25–40 total, ~3–4 in this domain), expect 1–1 from this objective — we provide 25 practice questions to prepare you well beyond it. (estimate)
25questions here
5free pages
6concepts
10%of the exam
Questions 16–20
- 16
An analyst wants to search for authentication events across multiple data sources using the CIM Authentication data model. Which search syntax should they use?
Select an answer first - 17
What must be configured on incoming data to ensure the CIM Add-On can normalize it correctly?
Select an answer first - 18
What is the purpose of Data Model acceleration in the context of the CIM Add-On?
Select an answer first - 19
During normalization, what is applied to an event to indicate that it belongs to a specific CIM data model?
Select an answer first - 20
A security team ingests firewall logs from multiple vendors. Each vendor uses different field names for source IP (e.g., src_ip, SourceAddress, SRC). The team wants to run a single search that works across all vendors. What is the most efficient way to achieve this?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Splunk. “SPLK-1002” is a trademark of its owner, used for identification only.