Exam SPLK-1002 All QuestionsBrowse all questions from this exam
Question 63

Which of the following data models are included in the Splunk Common Information Model (CIM) add-on? (Choose all that apply.)

    Correct Answer: A, B, C

    The Splunk Common Information Model (CIM) add-on includes several data models to standardize data for various use cases. Alerts, Email, and Databases are specific data models covered under CIM. User permissions, although relevant in other contexts, is not one of the data models specified by the CIM add-on based on the available documentation.

Discussion
allansidOptions: ABC

Alerts Application State Authentication Certificates Change Change Analysis CIM Validation (S.o.S) Databases Data Loss Prevention Email Endpoint Event Signatures Interprocess Messaging Intrusion Detection Inventory Java Virtual Machines (JVM) Malware Network Resolution (DNS) Network Sessions Network Traffic Performance Splunk Audit Logs Ticket Management Updates Vulnerabilities Web

SartarusOptions: ABC

ABC its correct

adamscaOptions: ABC

ABC correct

mardaOptions: ABC

ABC - P273

Kool_KidOptions: ABC

A,B,C. Slides page 273.

IxlJustinlxlOptions: ABC

ABC as per this link: https://conf.splunk.com/files/2017/slides/the-power-of-data-normalization-a-look-at-cim-under-the-hood.pdf