SPLK-1003 Exam QuestionsBrowse all questions from this exam

SPLK-1003 Exam - Question 3


In case of a conflict between a whitelist and a blacklist input setting, which one is used?

Show Answer
Correct Answer: A

In case of a conflict between a whitelist and a blacklist input setting, the blacklist is used. This is because blacklist entries are typically given higher priority to prevent unintended or potentially harmful data from being processed, ensuring more stringent control over what is excluded.

Discussion

8 comments
Sign in to comment
newroseOption: A
Nov 30, 2020

"It is not necessary to define both an allow list and a deny list in a configuration stanza. The settings are independent. If you do define both filters and a file matches them both, Splunk Enterprise does not index that file, as the blacklist filter overrides the whitelist filter." Source: https://docs.splunk.com/Documentation/Splunk/8.1.0/Data/Whitelistorblacklistspecificincomingdata

KobiOption: A
Mar 1, 2021

Blacklist Overides Whitelist

BengieQuesadaOption: A
Aug 11, 2021

A is correct Data Admin slide 123

ApisOption: A
Dec 30, 2021

A is correct

emlchOption: A
Sep 5, 2022

In case of a conflict the blacklist prevails

Praf7Option: A
Nov 15, 2020

A. Blacklist

ZeusPOption: A
May 25, 2021

Blacklist always overrides Whitelist

yybbbOption: A
Jan 30, 2024

A. blacklist