SPLK-2002(205Q) · Question #193
(When planning user management for a new Splunk deployment, which task can be disregarded?)
The correct answer is C. Determine the number of users present in Splunk log events. According to the Splunk Enterprise User Authentication and Authorization Guide, effective user management during deployment planning involves identifying how users will authenticate (native, LDAP, or SAML) and defining what roles and capabilities they will need to perform their…
Question
(When planning user management for a new Splunk deployment, which task can be disregarded?)
Options
- AIdentify users authenticating with Splunk native authentication.
- BIdentify users authenticating with Splunk using LDAP or SAML.
- CDetermine the number of users present in Splunk log events.
- DDetermine the capabilities users need within the Splunk environment.
How the community answered
(43 responses)- A2% (1)
- B16% (7)
- C72% (31)
- D9% (4)
Explanation
According to the Splunk Enterprise User Authentication and Authorization Guide, effective user management during deployment planning involves identifying how users will authenticate (native, LDAP, or SAML) and defining what roles and capabilities they will need to perform their tasks. However, counting or analyzing the number of users who appear in Splunk log events (Option C) is not part of user management planning. This metric relates to audit and monitoring, not access provisioning or role assignment. A proper user management plan should address: Authentication method selection (native, LDAP, or SAML). User mapping and provisioning workflows from existing identity stores. Role-based access control (RBAC) - assigning users appropriate permissions via Splunk roles and Administrative governance - ensuring access policies align with compliance requirements. Determining the number of users visible in log events provides no operational value when planning Splunk authentication or authorization architecture. Therefore, this task can be safely disregarded during initial planning. - User Authentication and Authorization in Splunk Enterprise - Configuring LDAP and SAML Authentication - Managing Users, Roles, and Capabilities - Splunk Deployment Planning Manual - Security and Access Control Planning
Topics
Community Discussion
No community discussion yet for this question.