Exam SPLK-1001 All QuestionsBrowse all questions from this exam
Question 108

How many main user roles do you have in Splunk?

    Correct Answer: B

    In Splunk, there are four main user roles: admin, power, user, and can_delete. The admin role has the most capabilities assigned, the power role can edit shared objects and perform advanced tasks, the user role can create and edit their own saved searches, and the can_delete role allows users to delete by keyword. Therefore, the correct answer is 4.

Discussion
tashahunOption: B

B is correct https://docs.splunk.com/Documentation/Splunk/8.2.0/Admin/Aboutusersandroles admin -- this role has the most capabilities assigned to it. power -- this role can edit all shared objects (saved searches, etc) and alerts, tag events, and other similar tasks. user -- this role can create and edit its own saved searches, run searches, edit its own preferences, create and edit event types, and other similar tasks. can_delete -- This role allows the user to delete by keyword. This capability is necessary when using the delete search operator

Alex_Cyber_SecOption: D

Answer is D There are 3 main user roles: Power, Admin, User

SecurityPaulOption: D

User, Power and Admin are the three main user roles. https://docs.splunk.com/Documentation/Splunk/8.2.0/Admin/Aboutusersandroles