Courseiva

SPLK-1003 · domain

User And Authentication Management

Practise Splunk Enterprise Certified Admin (SPLK-1003) (SPLK-1003) User And Authentication Management practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

33 questions9 easy14 medium10 hard

Focused practice

Practice User And Authentication Management questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about User And Authentication Management

User And Authentication Management questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common User And Authentication Management exam traps

  • Answering from memory before reading the full scenario.
  • Missing a constraint such as cost, availability, security, scope or command context.
  • Choosing a broad answer when the question asks for the most specific fix.
  • Ignoring why the wrong options are tempting.

Question index

All User And Authentication Management questions (33)

Click any question to see the full explanation, or start a practice session above.

1

Which THREE of the following are true about the 'can_delete' capability?

Medium
2

A user inherits roles 'RoleA' and 'RoleB'. 'RoleA' has 'srchIndexesAllowed' set to 'index1' and 'RoleB' has it set to 'index2'. What indexes can the user access?

Hard
3

Which configuration file is used to map LDAP groups to Splunk roles?

Medium
4

If you want to use SAML authentication, which component must be configured as the 'Service Provider'?

Hard
5

An administrator needs to ensure that users from an LDAP group 'Splunk_Power_Users' are automatically assigned the 'power' role in Splunk. Where is this mapping configured?

Medium
6

Which TWO of the following are true regarding Role Inheritance?

Medium
7

What is the effect of setting 'allow_debug' to false in a role?

Easy
8

You are troubleshooting an issue where a user cannot view a specific dashboard. The user has the 'user' role. What is the most likely cause?

Hard
9

Which capability is required for a user to see the 'Settings' menu in Splunk Web?

Easy
10

Which TWO items are contained within an 'authorize.conf' role stanza?

Medium
11

Which TWO of the following describe the 'admin' role?

Easy
12

Which THREE capabilities are typically assigned to a 'Power User'?

Hard
13

An administrator wants to ensure that a specific role cannot search over a time range greater than 24 hours. Where is this limit configured?

Hard
14

How can an administrator monitor failed login attempts for a specific user?

Medium
15

Which TWO items are managed within the 'Access Controls' menu in Splunk Web?

Easy
16

Which THREE parameters must be exchanged between Splunk and an Identity Provider for SAML to work?

Hard
17

Which THREE of these represent common issues when troubleshooting LDAP authentication?

Hard
18

Which TWO of the following are valid ways to authenticate users in Splunk?

Medium
19

Which user account is created by default and intended for administrative use, which should have its default password changed immediately?

Medium
20

If a user is assigned two roles, 'RoleA' and 'RoleB', and 'RoleA' has 'rtsearch' enabled while 'RoleB' has 'rtsearch' disabled, what is the user's effective capability for real-time searches?

Hard
21

What is the purpose of the 'srchFilter' attribute in a role definition?

Medium
22

What happens to a local user account if the underlying LDAP group they belong to is deleted?

Medium
23

Which TWO settings are commonly required when configuring an LDAP strategy?

Medium
24

You are configuring SAML authentication and need to map the 'email' attribute from the Identity Provider to the Splunk 'realName' field. Where do you configure this?

Hard
25

What is the default role assigned to a new user account if no other role is specified?

Easy
26

What happens to a user's session if their role is modified while they are logged in?

Easy
27

You need to restrict a specific user from accessing the 'internal' index even though their assigned role has access to all indexes. How do you implement this restriction?

Medium
28

You need to enable multi-factor authentication (MFA) for your Splunk instance. Where is this usually integrated?

Medium
29

Which menu path in Splunk Web is used to manage existing user roles?

Easy
30

Which of the following is a 'capability' in Splunk?

Easy
31

Which file stores the definitions of roles and their associated capabilities?

Easy
32

If you want to prevent a user from using the 'delete' command, which capability must be removed from their assigned role?

Medium
33

When configuring 'LDAP Strategy', what is the purpose of the 'User Base DN'?

Hard

Frequently asked questions

What does the User And Authentication Management domain cover on the SPLK-1003 exam?
User And Authentication Management questions test whether you can apply the concept in context, not just recognise a definition.
How many questions are in this domain?
This page lists all 33 User And Authentication Management questions in the SPLK-1003 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only User And Authentication Management questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
splunk-admin SPLUNK-ADMIN user and authentication management Practice Questions