Courseiva
User And Authentication ManagementmediumMultiple ChoiceObjective-mapped

SPLK-1003 User And Authentication Management Practice Question

You need to restrict a specific user from accessing the 'internal' index even though their assigned role has access to all indexes. How do you implement this restriction?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Create a new role with 'srchIndexesAllowed' excluding 'internal' and assign this role to the user.

You must create a new role that explicitly excludes the 'internal' index in the 'srchIndexesAllowed' field and assign it to the user.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Use a 'blacklist' in authorize.conf for the specific user.

    Why it's wrong here

    Splunk does not support per-user blacklists for indexes in authorize.conf.

  • Modify the user's account and set the indexes access to 'none'.

    Why it's wrong here

    This would remove access to all indexes.

  • Set the 'allow_index_access' capability to false for the user.

    Why it's wrong here

    This capability does not exist in Splunk.

  • Create a new role with 'srchIndexesAllowed' excluding 'internal' and assign this role to the user.

    Why this is correct

    Roles allow for granular control of index access via the 'srchIndexesAllowed' attribute.

About these practice questions

Courseiva writes every SPLK-1003 question from scratch — 202 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed August 2026 · checked against the official Splunk exam blueprint

This SPLK-1003 practice question is part of Courseiva's free Splunk certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SPLK-1003 exam.