Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Splunk logo

SplunkEnterprise Certified Admin

Domain 1Objective 4

Describe Splunk Configuration Directory Structure SPLK-1003 Practice Questions (Page 5)

Part of the Splunk Administration and Configuration domain, which makes up ~31% of our current practice bank. Splunk does not publish an official question count, but from its 60-minute exam (~25–40 total, ~8–12 in this domain), expect 1–2 from this objective — we provide 26 practice questions to prepare you well beyond it. (estimate)

26questions here
6free pages
8concepts

Questions 21–25

  1. 21foundation · easy

    Which statement correctly describes how Splunk merges configuration from multiple directories?

    Select an answer first
  2. 22foundation · easy

    Where are user-specific configurations stored in Splunk?

    Select an answer first
  3. 23expert · hard

    A Splunk admin has an app with a props.conf in its default directory that sets a specific sourcetype parsing rule. An admin override in the app's local directory sets a different rule. A user has also set a rule in their personal app's local directory. Which rule is effective for that user?

    Select an answer first
  4. 24application · medium

    An admin installs an app and needs to make a change to a configuration file that will persist across app upgrades. The admin wants to ensure the change is not overwritten when the app is updated. Which directory should the admin place the modified file in?

    Select an answer first
  5. 25application · medium

    An admin is writing a deployment script that must reference the Splunk installation directory in a platform-independent way. The script needs to locate the main configuration directory where system-level settings are stored. Which path should the script use?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Splunk. “SPLK-1003” is a trademark of its owner, used for identification only.