Labour Day Special Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: netbudy65

SPLK-2001 Splunk Certified Developer Exam Questions and Answers

Questions 4

Which of the following formats are valid for a Splunk REST URI?

Options:

A.

host:port/endpoint

B.

scheme://host/servicesNS/*/

C.

$SPLUNK HOME/services/endpoint

D.

scheme://host:port/services/endpoint

Buy Now
Questions 5

Which of the following is a security best practice?

Options:

A.

Enable XSS.

B.

Eliminate all escape characters.

C.

Ensure the app passes App Certification.

D.

Ensure components have no Common Vulnerabilities and Exposures (CVE) vulnerabilities.

Buy Now
Questions 6

What must be done when calling the service NS endpoint?

Options:

A.

Authenticate with an admin user.

B.

Specify the user and app context in the URI.

C.

Authenticate with the user of the required context.

D.

Pass the user and app context in the request payload.

Buy Now
Questions 7

When the search/jobs REST endpoint is called to execute a search, what can be done to reduce the results size in the results? (Select all that apply.)

Options:

A.

Use a generating search.

B.

Remove unneeded fields.

C.

Truncate the data, using selective functions.

D.

Summarize data, using analytic commands.

Buy Now
Questions 8

Which of the following Simple XML elements configure panel link buttons? (Select all that apply.)

Options:

A.

Open In Search

B.

C.

D.

Buy Now
Questions 9

For a KV store, a lookup stanza in the transforms.conf file must contain which of the following? (Select all that apply.)

Options:

A.

collection

B.

fields_list

C.

external_type

D.

internal_type

Buy Now
Questions 10

Which of the following log files contains logs that are most relevant to Splunk Web?

Options:

A.

audit.log

B.

metrics.log

C.

splunkd.log

D.

web_service.log

Buy Now
Questions 11

Suppose the following query in a Simple XML dashboard returns a table including hyperlinks:

index news sourcetype web_proxy | table sourcetype title link

Which of the following is a valid dynamic drilldown element to allow a user of the dashboard to visit the hyperlinks contained in the link field?

Options:

A.

B.

$$row.link$$

C.

$row.link|n$

Buy Now
Questions 12

When output_mode is not used, which element of a feed is a human readable name for a returned entry?

Options:

A.

Author

B.

Title

C.

Link

D.

Id

Buy Now
Questions 13

A fellow Splunk administrator is reviewing an app that has been downloaded from splunkbase and deployed in an organization. The admin has e-mailed the following configuration snippet with a brief note that says “fix the permissions”.

In what configuration file should the snippet be placed?

[]

access = read : [ * ], write : [ admin ] export - system

(Assume that $APP_HOME refers to the path that the app is installed, e.g. $SPLUNK_HOME/etc/apps/)

Options:

A.

$APP_HOME/default/app.conf

B.

$APP_HOME/local/default.meta

C.

$APP_HOME/metadata/local.meta

D.

$SPLUNK_HOME/etc/system/local/server.conf

Buy Now
Questions 14

A KV store collection can be associated with a namespace for which of the following users?

Options:

A.

Nobody

B.

Users in the admin role.

C.

Users in the admin and power roles.

D.

Users in the admin, power, and splunk-system-user roles.

Buy Now
Questions 15

A user wants to add the token $token_name$ to a dashboard for use in a drilldown. Which token filter encodes URL values?

Options:

A.

$$token_name$$

B.

$token_name|h$

C.

$token_name|n$

D.

$token_name|u$

Buy Now
Questions 16

Which of the following are characteristics of an add-on? (Select all that apply.)

Options:

A.

Requires navigation file.

B.

Occupies a unique namespace within Splunk.

C.

Can depend on add-ons for correct operation.

D.

Contains technology or components not intended for reuse by other apps.

Buy Now
Questions 17

Which of the following is an example of a Splunk KV store use case? (Select all that apply.)

Options:

A.

Stores checkpoint data for modular inputs.

B.

Tracks workflow in an incident-review system.

C.

Indexes metrics data from remote HTTP sources.

D.

Stores application state as a user interacts with an app.

Buy Now
Questions 18

Assuming permissions are set appropriately, which REST endpoint path can be used by someone with a power user role to access information about mySearch, a saved search owned by someone with a user role?

Options:

A.

/servicesNS/-/data/saved/searches/mySearch

B.

/servicesNS/object/saved/searches/mySearch

C.

/servicesNS/search/saved/searches/mySearch

D.

/servicesNS/-/search/saved/searches/mySearch

Buy Now
Questions 19

Consider the following Python code snippet used in a Splunk add-on:

if not os.path.exists(full_path): self.doAction(full_path, header) else: f = open (full_path) oldORnew = f.readline().split(“,”) f.close()

An attacker could create a denial of service by causing an error in either the open() or readline()

commands. What type of vulnerability is this?

Options:

A.

CWE-693: Protection Mechanism Failure

B.

CWE-562: Return of Stack Variable Address

C.

CWE-404: Improper Resource Shutdown or Release

D.

CWE-636: Not Failing Securely (‘Failing Open’)

Buy Now
Questions 20

What application security best practices should be adhered to while developing an app for Splunk? (Select all that apply.)

Options:

A.

Review the OWASP Top Ten List.

B.

Store passwords in clear text in .conf files.

C.

Review the OWASP Secure Coding Practices Quick Reference Guide.

D.

Ensure that third-party libraries that the app depends on have no outstanding CVE vulnerabilities.

Buy Now
Questions 21

Which of the following ensures that quotation marks surround the value referenced by the token?

Options:

A.

$token_name|s$

B.

“$token_name$”

C.

($token_name$)

D.

\“$token_name$\”

Buy Now
Exam Code: SPLK-2001
Exam Name: Splunk Certified Developer Exam
Last Update: May 5, 2024
Questions: 70

PDF + Testing Engine

$130

Testing Engine

$95

PDF (Q&A)

$80