Everyone studies differently, so ActualCollection offers the Splunk Cloud Certified Admin prep material in three formats: a printable PDF, a desktop test engine for Windows, and an online test engine that runs in any browser. All three carry the same 102 practice questions.
Splunk SPLK-1005 Exam Overview:
| Certification Vendor: | Splunk |
|---|---|
| Exam Name: | Splunk Cloud Certified Admin |
| Exam Number: | SPLK-1005 |
| Available Languages: | English |
| Related Certifications: | Splunk Core Certified Power User |
| Certificate Validity Period: | 3 years |
| Exam Price: | $130 USD |
| Exam Duration: | 75 minutes |
| Passing Score: | 700/1000 |
| Real Exam Qty: | 60 |
| Exam Format: | Scenario-based, Multiple-choice, Multiple-response |
| Recommended Training: | Splunk Cloud Certified Admin Learning Path |
| Exam Registration: | Pearson VUE Registration |
| Sample Questions: | ![]() |
| Exam Way: | Online proctored or onsite at Pearson VUE test centers |
| Pre Condition: | Splunk Core Certified Power User certification recommended; 6+ months hands-on experience with Splunk Cloud |
| Official Syllabus URL: | https://www.splunk.com/en_us/training/certification-track/splunk-cloud-certified-admin.html |
Splunk SPLK-1005 Exam Syllabus Topics:
| Section | Weight | Objectives |
|---|---|---|
| Topic 1: Parsing and Data Preview | 10% | - Data preview and validation - Event line breaking and timestamp configuration - Default parsing process |
| Topic 2: Configuration Files and Settings | 10% | - Configuration file structure and precedence - Managing cloud-compatible configurations - Validation and troubleshooting |
| Topic 3: Forwarder Management | 5% | - Deployment Server and deployment clients - Forwarder types and deployment - Managing forwarders via deployment apps |
| Topic 4: Monitor Inputs | 15% | - File and directory monitoring inputs - Data ingestion process - Input configuration and settings |
| Topic 5: Monitoring and Troubleshooting | 10% | - Common issues and resolution - Log and error analysis - System health and performance monitoring |
| Topic 6: User Authentication and Authorization | 10% | - User account management - LDAP and SSO integration - Role-based access control |
| Topic 7: Data Manipulation | 10% | - Event processing and enrichment - Field extraction and transformation - Raw data modification |
| Topic 8: Network and Other Inputs | 10% | - TCP and UDP network inputs - Windows-specific inputs - Input tuning and optional settings - Scripted inputs |
| Topic 9: Applications and Add-ons | 5% | - Installing and managing apps - Splunk Cloud supported add-ons |
| Topic 10: Index Management | 5% | - Data retention and storage management - Understanding indexes in Splunk Cloud - Index creation, configuration and monitoring |
| Topic 11: Splunk Cloud Overview | 5% | - Cloud topology and architecture - Differences between Splunk Cloud and Splunk Enterprise - Administrator roles and responsibilities |
| Topic 12: Working with Splunk Cloud Support | 5% | - Support process and engagement - Collecting diagnostic information |
Answers Every SPLK-1005 Candidate Should Read First
The Splunk Cloud Certified Admin exam is the official Splunk test registered under exam code SPLK-1005. Passing it earns you the Splunk Cloud Certified Admin certification, a credential at the Professional level. It is also linked to the related certification: Splunk Core Certified Power User. Splunk exams are valued because they test job-ready skills, so a passing score here carries real weight on a resume.
The Splunk Cloud Certified Admin exam includes 60 questions to be completed within 75 minutes. Do the pacing math before exam day: with that many items on the clock, you need a steady rhythm and the discipline to flag a hard question and move on instead of stalling. Two or three full timed sessions with the ActualCollection test engine will show you exactly what that pace feels like, so time pressure stops being a factor on the real day.
To pass the Splunk Cloud Certified Admin exam you need 700/1000, and the official registration fee is $130 USD. A retake is not discounted: a failed attempt means paying the full $130 USD again, so treat your first sitting as the expensive one. A sensible rule is to book your seat only after you are scoring comfortably above the passing mark on the ActualCollection practice tests, not just squeaking past it once.
Splunk Core Certified Power User certification recommended; 6+ months hands-on experience with Splunk Cloud
Eligibility rules do change from time to time, so confirm the current requirements before you register on the official exam page.
Registration for the Splunk Cloud Certified Admin exam goes through the official channels below.
As for the delivery format, the exam is taken Online proctored or onsite at Pearson VUE test centers.
Splunk points candidates toward the following training options for Splunk Cloud Certified Admin.
Course work builds the foundation; question practice makes it stick. The 102 practice questions in the ActualCollection SPLK-1005 package let you rehearse each topic under exam-style pressure before the real thing.
Yes. ActualCollection offers a free PDF demo of the Splunk Cloud Certified Admin material so you can judge the question quality and format before spending anything. After purchase, your license includes 365 days of free updates, and if you want to keep receiving updates after that period, renewals are available at a 50% discount.
If you take the Splunk Cloud Certified Admin exam within 60 days of your purchase and do not pass, ActualCollection backs you with a 100% money-back guarantee. The claim must match the exam your product covers: attempts taken within 3 days of purchase are not eligible (that is too little preparation time), and neither are downloaded-but-unused products, free materials, or expired orders. The candidate name must match the payer name, and you need to submit a scanned enrollment slip plus the official Score Report PDF within 2 days of the exam; claims are processed within 7 days. Prefer not to refund? You can swap instead and receive two other exam products of equal value for free while keeping the update service on your original purchase.
Delivery itself is instant: your files are downloadable right away and emailed to you within one minute of payment. If nothing arrives within 2 hours, contact customer service. There is no limit on how many computers you may install the software on.
The official Splunk Cloud Certified Admin syllabus is organized into 12 domains. Key areas include Applications and Add-ons (5%), Splunk Cloud Overview (5%), and Index Management (5%). The complete, up-to-date topic list appears in the exam topics section above; work through it line by line and flag anything you cannot yet explain in your own words.
Splunk Cloud Certified Admin Sample Questions:
Question 1
Which Splunk Cloud feature primarily provides centralized operational dashboards for distributed infrastructure monitoring activities?
A. Search Head clustering authenticates users and distributes application packages toward enterprise endpoints continuously.
B. Universal Forwarders synchronize indexed events and retention settings across cloud storage infrastructures automatically.
C. Monitoring Console displays deployment health metrics and distributed search performance information centrally.
D. Deployment Server permanently stores archived security logs for forensic investigations across enterprises globally.
Question 2
A customer wants to mask unstructured data before sending it to Splunk Cloud. Where should SEBCMD be configured for this?
A. transforms, cent on a Splunk Cloud indexer.
B. props. conf on a Splunk Cloud search head,
C. props.conf on a Heavy Forwarder.
D. props. conf- on a Universal Forwarder.
Question 3
How are HTTP Event Collector (HEC) tokens configured in a managed Splunk Cloud environment?
A. A token is generated when configuring a HEC input, which should be provided to the application developers.
B. Open a support case for each new data input and a token will be provided.
C. Any token will be accepted by HEC, the data may just end up in the wrong index.
D. Obtain a token from the organization's application developers and apply it in Settings > Data Inputs > HTTP Event Collector > New Token.
Question 4
Which of the following are valid settings for file and directory monitor inputs?
A. host, index, directory, host_regex, host_segment
B. host, index, source_length, _TCP_Routing, host_segment
C. host, index, sourcetype, _TCP_Routing, host_regex, host_segment
D. host, index, sourcetype, _UDP_Routing, host_regex, host_segment
Question 5
Which of the following would always require raising a support ticket?
A. A user is unable to log into Splunk Cloud.
B. Search does not return expected results in Splunk Cloud.
C. Data is not indexed in Splunk Cloud.
D. Capacity or configuration changes in Splunk Cloud.
Solutions:
| Question 1 Answer: C | Question 2 Answer: C | Question 3 Answer: A | Question 4 Answer: C | Question 5 Answer: D |






1180 Customer Reviews
