SPLK-1002 Advanced Visualization and Lookups Practice Question
A SOC manager wants to plot locations of security incidents on a map using latitude and longitude fields. Which visualization type should be used in a Splunk dashboard?
⚠ Common exam trap
Splunk often tests the distinction between cluster maps (point-based) and choropleth maps (region-based), leading candidates to mistakenly choose choropleth when they see 'map' and 'latitude/longitude' in the same question.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Cluster map
A cluster map is the correct choice because it is specifically designed to plot individual geographic coordinates (latitude/longitude) as points on a map, and it automatically groups nearby points into clusters to improve readability when many incidents are present. In Splunk, the cluster map visualization uses the `geostats` command or directly ingests lat/lng fields to render markers, making it ideal for showing security incident locations without requiring predefined region boundaries.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Cluster map
Why this is correct
Cluster map visualizes point data on a map.
- ✗
Choropleth map
Why it's wrong here
Choropleth maps show regions, not individual points.
- ✗
Pie chart
Why it's wrong here
Pie chart shows proportions, not geographic distribution.
- ✗
Scatter chart
Why it's wrong here
Scatter chart does not use geospatial coordinates.
Go deeper
Related to this question
About these practice questions
One of 475 original SPLK-1002 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SPLK-1002 practice question is part of Courseiva's free Splunk certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SPLK-1002 exam.