Free SPLK-1004 Sample Questions — Splunk Core Certified Advanced Power User

Free SPLK-1004 sample questions for the Splunk Core Certified Advanced Power User exam. No account required: study at your own pace.

Want an interactive quiz? Take the full SPLK-1004 practice test

Looking for more? Click here to get the full PDF with 69+ practice questions for $10 for offline study and deeper preparation.

Question 1

Which of the following are potential string results returned by the typeof function?

  • A. True, False, Unknown
  • B. Number, String, Bool
  • C. Number, String, Null
  • D. Field, Value, Lookup
Show Answer
Correct Answer:
B. Number, String, Bool
Question 2

What capability does a power user need to create a Log Event alert action?

  • A. edit_search_server
  • B. edit_udp
  • C. edit_tcp
  • D. edit_alerts
Show Answer
Correct Answer:
C. edit_tcp
Question 3

What file types does Splunk use to define geospatial lookups?

  • A. GPX or GML files
  • B. TXT files
  • C. KMZ or KML files
  • D. CSV files
Show Answer
Correct Answer:
C. KMZ or KML files
Question 4

What is an example of the simple XML syntax for a base search and its post-process search?

  • A. <search id="myBaseSearch">, <search base="myBaseSearch">
  • B. <search globalsearch="myBaseSearch">, <search globalsearch>
  • C. <panel id="myBaseSearch">, <panel base="myBaseSearch">
  • D. <search id="myGlobalSearch">, <search base="myBaseSearch">
Show Answer
Correct Answer:
A. <search id="myBaseSearch">, <search base="myBaseSearch">
Question 5

How can the Inspect button be disabled on a dashboard panel?

  • A. Set inspect.link.disabled to 1
  • B. Set link.inspect.visible to 0
  • C. Set link.inspect.Search.visible to 0
  • D. Set link.search.disabled to 1
Show Answer
Correct Answer:
C. Set link.inspect.Search.visible to 0
Question 6

What type of drilldown passes a value from a user click into another dashboard or external page?

  • A. Visualization
  • B. Event
  • C. Dynamic
  • D. Contextual
Show Answer
Correct Answer:
C. Dynamic
Question 7

What is the value of base lispy in the Search Job Inspector for the search index=sales clientip=170.192.178.10?

  • A. [ index::sales 192 AND 10 AND 178 AND 170 ]
  • B. [ index::sales AND 469 10 702 390 ]
  • C. [ 192 AND 10 AND 178 AND 170 index::sales ]
  • D. [ AND 10 170 178 192 index::sales ]
Show Answer
Correct Answer:
D. [ AND 10 170 178 192 index::sales ]
Question 8

How is regex passed to the makemv command?

  • A. makemv must be preceded by the erex command
  • B. It is specified by the delim argument
  • C. It is specified by the tokenizer argument
  • D. makemv must be preceded by the rex command
Show Answer
Correct Answer:
C. It is specified by the tokenizer argument
Question 9

Where does the output of an append command appear in the search results?

  • A. Added as a column to the right of the search results
  • B. Added as a column to the left of the search results
  • C. Added to the beginning of the search results
  • D. Added to the end of the search results
Show Answer
Correct Answer:
D. Added to the end of the search results
Question 10

Which of the following is not a common default time field?

  • A. date_zone
  • B. date_minute
  • C. date_year
  • D. date_day
Show Answer
Correct Answer:
D. date_day
Question 11

Where can wildcards be used in the tstats command?

  • A. No wildcards can be used with tstats
  • B. In the where clause
  • C. In the from clause
  • D. In the by clause
Show Answer
Correct Answer:
B. In the where clause
Question 12

Which of the following functions' primary purpose is to convert epoch time to a string format?

  • A. tostring
  • B. strptime
  • C. tonumber
  • D. strftime
Show Answer
Correct Answer:
D. strftime
Question 13

Which of the following best describes the process for tokenizing event data?

  • A. The event data is broken up by values in the punct field
  • B. The event data is broken up by major breakers and then broken up further by minor breakers
  • C. The event data is broken up by a series of user-defined regex patterns
  • D. The event data has all punctuation stripped out and is then space delimited
Show Answer
Correct Answer:
B. The event data is broken up by major breakers and then broken up further by minor breakers
Question 14

Which syntax is used when referencing multiple CSS files in a view?

  • A. <dashboard stylesheet="custom.css, userapps.css">
  • B. <dashboard style="custom.css, userapps.css">
  • C. <dashboard stylesheet=custom.css stylesheet=userapps.css>
  • D. <dashboard stylesheet="custom.css | userapps.css">
Show Answer
Correct Answer:
A. <dashboard stylesheet="custom.css, userapps.css">
Question 15

Which statement about tsidx files is accurate?

  • A. Splunk updates tsidx files every 30 minutes
  • B. Splunk removes outdated tsidx files every 5 minutes
  • C. tsidx file consists of a lexicon and a posting list
  • D. Each bucket in each index may contain only one tsidx file
Show Answer
Correct Answer:
C. tsidx file consists of a lexicon and a posting list

Aced these? Get the Full Exam

Download the complete SPLK-1004 study bundle with 69+ questions in a single printable PDF.