SPLK1002 Splunk Core Certified Power User Free Practice Test — 30 Questions

30 questions · Full explanations · No account required

Free
Question 1 of 30

A Splunk Power User is investigating a sudden surge in authentication failures detected on a Tuesday morning. Initial observations indicate that the majority of these failures are originating from the `192.168.10.0/24` subnet, a segment typically used for administrative workstations and known for stable, low-volume login activity. The user needs to confirm this anomaly and pinpoint the exact source IPs within the subnet exhibiting the most unusual behavior, while ensuring the search remains performant and provides context against normal operational patterns. Which of the following search strategies is most appropriate for this investigation?

Execute a search that counts failed login events from the `192.168.10.0/24` subnet, calculates the historical average and standard deviation of these failures for hourly intervals, and then identifies sources exceeding a statistically significant threshold above their normal rate.
Perform a broad search across all indices for any event containing the string "failed login" and manually correlate the results with known IP address ranges for the `192.168.10.0/24` subnet.
Utilize a `tstats` command to retrieve all authentication events within the last 24 hours, filter by `src_ip_subnet=192.168.10.0/24`, and then manually sort the results by the frequency of failed login attempts.
Create a Splunk alert that triggers on any failed login event originating from the `192.168.10.0/24` subnet, regardless of historical context or volume, to immediately flag all such occurrences.

About the SPLK1002 Splunk Core Certified Power User Certification

These free practice questions are designed to help you assess your readiness for the SPLK1002 Splunk Core Certified Power User exam by Other. Each question comes with a detailed explanation to reinforce the correct concept. For a complete exam preparation experience with hundreds of questions, spaced-repetition study tools, and full exam simulations, explore our premium access.