Splunk SPLK-1005 Question Answer
By default, which of the following capabilities are granted to the sc_admin role?
indexes_edit, edit___token, admin_all_objects, delete_by_keyword
indexes_edit, fsh_manage, acs_conf, list_indexesdiscovert
indexes_edit, fsh_manage, admin_all_objects can_delete
indexes_edit, edit_token_http, admin _all objects, edit limits_conf
By default, the sc_admin role in Splunk Cloud is granted several important capabilities, including:
indexes_edit: The ability to create, edit, and manage indexes.
fsh_manage: Manage full-stack monitoring integrations.
admin_all_objects: Full administrative control over all objects in Splunk.
can_delete: The ability to delete events using the delete command.
Option C correctly lists these default capabilities for the sc_admin role.
Splunk Documentation Reference: User roles and capabilities
TESTED 11 Jul 2025
Copyright © 2014-2025 ACE4Sure. All Rights Reserved