SPLK-1005 — Splunk Cloud Certified Admin
Splunk

Splunk Cloud Certified Admin (SPLK-1005) Practice Questions

★★★★★ 5.0 101 verified reviews
119 questions
June 17, 2026 updated
✓ Online quiz simulator

Domain coverage

  • Splunk Cloud Overview & Architecture (10%)
  • Index Management & Data Retention (15%)
  • Users, Roles, and Cloud Authentication (15%)
  • Cloud Configuration Controls & App Vetting (15%)
  • Forwarder Configuration & Token Management (15%)
  • Getting Data In - Data Inputs Detail (15%)
  • Event Parsing & Data Preview (15%)

Sample Questions (12 of 119 shown)

Q1 Working with Splunk Cloud Support
How is indexed data typically removed in a Splunk Cloud environment?
  1. By editing rawdata files directly
  2. By working with Splunk Cloud Support or index retention policies
  3. By running the delete command locally
  4. Through manual index file cleanup
✓ Correct Answer: b
In Splunk Cloud, data removal is managed through support tickets or by configuring index retention policies (frozen buckets).
Q2 Working with Splunk Cloud Support
Which would always require raising a support ticket in Splunk Cloud?
  1. Capacity or configuration changes.
  2. Search does not return expected results.
  3. A user is unable to log in.
  4. Data is not indexed.
✓ Correct Answer: A
Any modifications in capacity or configurations within Splunk Cloud require an official support ticket.
Q3 Working with Splunk Cloud Support
Which of the following issues would require a Splunk Cloud Support ticket?
  1. A user forgot their password.
  2. Adding a new index or changing index retention settings.
  3. Creating a new search.
  4. Modifying a dashboard.
✓ Correct Answer: B
Index-related changes like adding indexes or modifying retention policies require a support ticket in Splunk Cloud.
Q4 Working with Splunk Cloud Support
Before contacting Splunk Cloud Support about a search performance issue, what should the administrator do?
  1. Restart the Splunk Cloud stack.
  2. Gather relevant diagnostic information including search job inspector data.
  3. Reinstall the search head.
  4. Delete and recreate the search.
✓ Correct Answer: B
Administrators should gather diagnostic information (search job inspector, _internal logs) before contacting support.
Q5 Working with Splunk Cloud Support
What information should be included when submitting a Splunk Cloud Support ticket for data ingestion issues?
  1. The name of the person reporting the issue.
  2. Forwarder logs, inputs configuration, and the specific data sources affected.
  3. The company's billing information.
  4. The administrator's resume.
✓ Correct Answer: B
Forwarder logs, inputs configuration, and data source details help support diagnose ingestion issues.
Q6 Working with Splunk Cloud Support
When reporting a performance issue to Splunk Cloud Support, which tool provides the most relevant diagnostic data?
  1. The Cloud Monitoring Console
  2. Splunk Web search interface
  3. Splunk CLI
  4. Windows Event Viewer
✓ Correct Answer: A
The Cloud Monitoring Console provides dashboards and diagnostic data essential for troubleshooting.
Q7 Manipulating Raw Data
When using INGEST_EVAL in props.conf, what is its primary purpose?
  1. To evaluate search-time field extractions.
  2. To perform index-time field evaluations and transformations using expressions.
  3. To evaluate dashboard performance.
  4. To evaluate user permissions.
✓ Correct Answer: B
INGEST_EVAL allows index-time field evaluation and transformation using eval-like expressions.
Q8 Manipulating Raw Data
What is the purpose of the WRITE_META setting in props.conf?
  1. To write metadata fields to the indexed data.
  2. To create metadata backup files.
  3. To write custom metadata to external systems.
  4. To display metadata in search results.
✓ Correct Answer: A
WRITE_META in props.conf allows writing custom metadata to indexed events during the parsing phase.
Q9 Parsing Phase and Data Preview
During the parsing phase, what happens after events are created?
  1. They are stored in the index immediately.
  2. Timestamps are extracted and assigned to each event.
  3. They are compressed for storage.
  4. They are forwarded to search heads.
✓ Correct Answer: B
After event creation during parsing, Splunk identifies and extracts timestamps to assign to each event.
Q10 Parsing Phase and Data Preview
What is the function of the TZ setting in props.conf?
  1. To specify the time zone for timestamp interpretation.
  2. To set the display time zone for search results.
  3. To convert timestamps from UTC to local time.
  4. To configure daylight saving time rules.
✓ Correct Answer: A
The TZ setting in props.conf specifies the time zone to use when interpreting timestamps for a sourcetype.
Q11 Network and Other Inputs
What is the purpose of the HEC indexer acknowledgment feature in Splunk Cloud?
  1. To confirm that HEC events were received and indexed.
  2. To provide a receipt for billing purposes.
  3. To validate HEC token authenticity.
  4. To track API usage.
✓ Correct Answer: A
HEC indexer acknowledgment confirms that events sent via HEC were successfully received and indexed.
Q12 Network and Other Inputs
What is the default HEC port in Splunk Cloud?
  1. 443
  2. 8088
  3. 8443
  4. 8099
✓ Correct Answer: B
The default HEC port in Splunk Cloud is 8088 for HTTP and 443 can be configured for HTTPS.

You've viewed 3 of 119 questions. Start the free practice exam to answer all questions with instant feedback.

Exam overview

Aspiring Splunk Cloud administrators turn to the Splunk Cloud Certified Admin (SPLK-1005) certification to validate their expertise in cloud-specific data onboarding, forwarder configuration, and authentication management. Administered by Splunk through Pearson VUE, this 75-minute exam requires an active Splunk Core Certified Power User (SPLK-1002) certification as a formal prerequisite and focuses entirely on cloud platform administration rather than on-premise Enterprise management.

Candidates must complete either the Splunk Cloud Administration training path (lecture plus hands-on labs) or the Transitioning to Splunk Cloud course (for certified Enterprise Admins pivoting to cloud) on the STEP portal. A minimum of 3 to 6 months of daily hands-on experience provisioning users, onboarding data sources, and managing apps within a Splunk Cloud Platform stack is strongly recommended, alongside thorough study of the Splunk Cloud Admin Manual, Getting Data In Manual, and Vetting Splunk Apps Guide.

The SPLK-1005 blueprint covers 7 equally weighted domains (each at 15%, except Cloud Overview & Architecture at 10%). Key technical areas include cloud architecture vs. on-prem distinctions with data tier isolation and retention rules, SSO/SAML configuration with Okta and Azure AD including native authentication fallback behavior, the automated app vetting process for private custom apps, Universal Forwarder credential package deployment, HTTP Event Collector (HEC) endpoint and token management, cloud storage integrations like AWS S3 inputs, and event parsing via the Data Preview engine with props.conf timestamp and line-break rules.

For candidates preparing for the SPLK-1005 exam, our practice materials cover all 7 domains in the same proportions as the real test — from Splunk Cloud Overview with managed architecture vs. on-prem differences through Index Management with retention and data sizing restrictions, Users/Roles/Cloud Authentication with SSO (SAML/Okta/Azure AD) and native fallback mechanics, Cloud Configuration Controls with .conf file isolation limits and the app vetting system, Forwarder Configuration with the dynamic Universal Forwarder credentials package, Getting Data In with HEC endpoints, tokens, and AWS S3 integration, and Event Parsing with the Data Preview engine and props.conf timestamp configuration. Each online practice question includes a detailed answer explanation that walks through the cloud-specific administrative reasoning, while the downloadable PDF packages the same question bank for offline review during commutes or in environments without stable internet.

Start your free SPLK-1005 practice test today and gain confidence managing Splunk Cloud architecture, authentication, and data onboarding.

Official Exam Domains & Weighting

To successfully pass the SPLK-1005 exam, candidates must master the following core domains:
  • Domain 1: Splunk Cloud Overview & Architecture (10%)
Covers distinguishing managed cloud architecture vs. on-prem setups, understanding Splunk Service Details and tenant responsibilities, and navigating data tier isolation and basic data retention rules.
  • Domain 2: Index Management & Data Retention (15%)
Focuses on creating and configuring cloud index spaces via Splunk Web UI, managing index data storage with sizing restrictions and retirement properties, and navigating data self-storage export rules and settings.
  • Domain 3: Users, Roles, and Cloud Authentication (15%)
Tests managing native Splunk Cloud users with custom capability scopes, implementing single sign-on (SSO) using SAML providers (Okta, Azure AD), and tracking behavior and concurrency exceptions of native vs. external authorization types.
  • Domain 4: Cloud Configuration Controls & App Vetting (15%)
Addresses understanding cloud .conf file isolation restrictions (admin-configurable vs. Splunk Support only), installing apps via Splunkbase or the automated private app upload vetting system, and troubleshooting application blockage and compatibility errors.
  • Domain 5: Forwarder Configuration & Token Management (15%)
Covers configuring Universal Forwarders to securely send traffic into Splunk Cloud, downloading and maintaining the dynamic Splunk Cloud forwarder credentials package, and configuring index routing targets and outputs.
  • Domain 6: Getting Data In - Data Inputs Detail (15%)
Explains setting up HTTP Event Collector (HEC) endpoints with token generation and payload balancing, plus configuring cloud file monitor streams, scripted inputs, and cloud storage integrations (e.g., AWS S3 inputs).
  • Domain 7: Event Parsing & Data Preview (15%)
Addresses utilizing the web UI Data Preview engine to parse raw formatting logs before committing, and determining timestamp processing patterns (props.conf logic), line breaks, and event break segmentation rules.

What Our Customers Say 101 verified reviews

5.0 ★★★★★ Based on 101 reviews
★★★★★★
After failing SPLK-1005 twice, these practice questions helped me finally pass. The detailed answer explanations are gold.
— Michael T.
★★★★★
Passed SPLK-1005 with flying colors thanks to these practice exams. The questions are harder than the real thing, which is exactly what you want.
— Lisa G.
★★★★★
Got 856 out of 900 on the SPLK-1005 exam. This question bank was my primary study resource. Highly recommend.
— Alyssa D.
★★★★★★
The SPLK-1005 explanations are where this really stands out. Not just which answer is right but WHY the others are wrong.
— Aria H.
★★★★★
My colleague recommended this for SPLK-1005 and I’m glad I listened. Passed on my first go after two weeks of solid study.
— Logan T.
★★★★★
I had almost given up on SPLK-1005 after failing twice. These questions pinpointed exactly what I was missing. Third time’s the charm!
— Noah S.

Log in to rate this exam and leave a review.

Submitted for moderation before publishing. Keep it helpful and respectful.

Frequently Asked Questions

File access limitations. In Enterprise Admin, you have direct CLI/root access to edit files like indexes.conf or inputs.conf. In Splunk Cloud Admin, you are barred from CLI access and must use the Splunk Web UI or the cloud app ingestion framework. Our practice questions include scenario-based exercises that test this cloud vs. on-prem distinction.

When configuring SAML or LDAP on Splunk Cloud, native Splunk authentication remains active as a fallback mechanic, ensuring administrators can still log in using local break-glass credentials if the corporate Identity Provider (IdP) goes down. Our practice materials include SSO fallback scenarios with Okta and Azure AD configurations.

Splunk Cloud enforces a strict auto-vetting process. Any custom app must pass through the automated cloud vetting engine to verify no security risks, illegal directory scripts, or malicious .conf parameters exist. Apps that fail cannot be pushed live until fixed. Our practice sets include app vetting workflow questions.

You download a pre-packaged Splunk Cloud Forwarder Credentials app from your cloud instance rather than manually writing SSL certificate paths. Installing this app on your Universal Forwarders automatically applies the secure outbound certificates, routing addresses, and ports needed to reach your cloud endpoint. Our practice questions cover credential package deployment scenarios.

Our mock exam covers all 7 domains with the same weight distribution as the real test — from cloud architecture vs. on-prem distinctions and data tier isolation through SSO/SAML authentication with Okta/Azure AD, automated app vetting workflows, Universal Forwarder credentials package deployment, HEC endpoint and token configuration, AWS S3 input setup, and Data Preview engine parsing with props.conf timestamp rules. Each question includes a detailed cloud-admin reasoning explanation.

Yes. The downloadable PDF contains the same question bank as the online version, including answer explanations covering cloud architecture and data tier isolation, SSO/SAML configuration with native fallback, .conf file restrictions and app vetting procedures, forwarder credentials package deployment, HEC endpoint management with token balancing, AWS S3 input configuration, and Data Preview/props.conf event break segmentation. It is designed for offline study without an internet connection.

Candidates frequently report Cloud Configuration Controls & App Vetting (15%) as the most challenging due to nuanced .conf file restriction rules and the automated vetting criteria. SSO/SAML authentication (15%) is also cited for its IdP fallback mechanics and multiple-provider configuration scenarios. Our practice questions include focused drills on these high-difficulty areas.