SPLK-1003 · domain
User And Authentication Management
Practise Splunk Enterprise Certified Admin (SPLK-1003) (SPLK-1003) User And Authentication Management practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.
Focused practice
Practice User And Authentication Management questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about User And Authentication Management
User And Authentication Management questions test whether you can apply the concept in context, not just recognise a definition.
How the topic appears in realistic exam-style scenarios.
Which detail in the question changes the correct answer.
How to eliminate plausible but wrong options.
How to connect the question back to the wider exam objective.
Watch out for
Common User And Authentication Management exam traps
- ▸Answering from memory before reading the full scenario.
- ▸Missing a constraint such as cost, availability, security, scope or command context.
- ▸Choosing a broad answer when the question asks for the most specific fix.
- ▸Ignoring why the wrong options are tempting.
Question index
All User And Authentication Management questions (33)
Click any question to see the full explanation, or start a practice session above.
Which THREE of the following are true about the 'can_delete' capability?
Medium2A user inherits roles 'RoleA' and 'RoleB'. 'RoleA' has 'srchIndexesAllowed' set to 'index1' and 'RoleB' has it set to 'index2'. What indexes can the user access?
Hard3Which configuration file is used to map LDAP groups to Splunk roles?
Medium4If you want to use SAML authentication, which component must be configured as the 'Service Provider'?
Hard5An administrator needs to ensure that users from an LDAP group 'Splunk_Power_Users' are automatically assigned the 'power' role in Splunk. Where is this mapping configured?
Medium6Which TWO of the following are true regarding Role Inheritance?
Medium7What is the effect of setting 'allow_debug' to false in a role?
Easy8You are troubleshooting an issue where a user cannot view a specific dashboard. The user has the 'user' role. What is the most likely cause?
Hard9Which capability is required for a user to see the 'Settings' menu in Splunk Web?
Easy10Which TWO items are contained within an 'authorize.conf' role stanza?
Medium11Which TWO of the following describe the 'admin' role?
Easy12Which THREE capabilities are typically assigned to a 'Power User'?
Hard13An administrator wants to ensure that a specific role cannot search over a time range greater than 24 hours. Where is this limit configured?
Hard14How can an administrator monitor failed login attempts for a specific user?
Medium15Which TWO items are managed within the 'Access Controls' menu in Splunk Web?
Easy16Which THREE parameters must be exchanged between Splunk and an Identity Provider for SAML to work?
Hard17Which THREE of these represent common issues when troubleshooting LDAP authentication?
Hard18Which TWO of the following are valid ways to authenticate users in Splunk?
Medium19Which user account is created by default and intended for administrative use, which should have its default password changed immediately?
Medium20If a user is assigned two roles, 'RoleA' and 'RoleB', and 'RoleA' has 'rtsearch' enabled while 'RoleB' has 'rtsearch' disabled, what is the user's effective capability for real-time searches?
Hard21What is the purpose of the 'srchFilter' attribute in a role definition?
Medium22What happens to a local user account if the underlying LDAP group they belong to is deleted?
Medium23Which TWO settings are commonly required when configuring an LDAP strategy?
Medium24You are configuring SAML authentication and need to map the 'email' attribute from the Identity Provider to the Splunk 'realName' field. Where do you configure this?
Hard25What is the default role assigned to a new user account if no other role is specified?
Easy26What happens to a user's session if their role is modified while they are logged in?
Easy27You need to restrict a specific user from accessing the 'internal' index even though their assigned role has access to all indexes. How do you implement this restriction?
Medium28You need to enable multi-factor authentication (MFA) for your Splunk instance. Where is this usually integrated?
Medium29Which menu path in Splunk Web is used to manage existing user roles?
Easy30Which of the following is a 'capability' in Splunk?
Easy31Which file stores the definitions of roles and their associated capabilities?
Easy32If you want to prevent a user from using the 'delete' command, which capability must be removed from their assigned role?
Medium33When configuring 'LDAP Strategy', what is the purpose of the 'User Base DN'?
HardOther domains
All SPLK-1003 exam domains
Frequently asked questions
- What does the User And Authentication Management domain cover on the SPLK-1003 exam?
- User And Authentication Management questions test whether you can apply the concept in context, not just recognise a definition.
- How many questions are in this domain?
- This page lists all 33 User And Authentication Management questions in the SPLK-1003 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only User And Authentication Management questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.