Exam SPLK-3003 All QuestionsBrowse all questions from this exam
Question 43

A customer wants to migrate from using Splunk local accounts to use Active Directory with LDAP for their Splunk user accounts instead. Which configuration files must be modified to connect to an Active Directory LDAP provider?

    Correct Answer: B

    To connect Splunk to an Active Directory LDAP provider, you need to modify both the authentication.conf and ldap.conf files. The authentication.conf file is necessary for configuring authentication methods and settings, while the ldap.conf file is needed specifically for setting LDAP-related configurations. The authorize.conf file is not needed in this scenario as it is used for role-based access control but not for initial LDAP connection setup.

Discussion
RedtonyeahOption: C

C is OK

SasnycoNOption: C

Answer is "C"

wiz386Option: D

should be D

hpbdcbOption: C

crystal clear

HamiltonianOption: C

They are only specifying the connection to the LDAP server and nothing about role mappings. Thus: C

Danny52Option: B

It is B

chuchoneitor

Wrong, in the worts case should be D because you need to map the roles. But as I understood they are talking about authentication only so I would rather C in this case.

LearningDani

Role mapping is also done in authentication.conf. So no need to touch the authorize.conf -> C

pbandj12

D is the answer, B is super wrong

pbandj12

Sorry I meant, C!!!!!