Splunk Core Certified Advanced Power User — Question 173
In which scenario would a Splunk Administrator want to enable data integrity check when creating an index?
Answer options
- A. To ensure that hot buckets are still open for writers and have not been forced to roll to a cold state.
- B. To ensure that configuration files have not been tampered with for auditing and/or legal purposes.
- C. To ensure that user passwords have not been tampered with for auditing and/or legal purposes.
- D. To ensure that data has not been tampered with for auditing and/or legal purposes.
Correct answer: D
Explanation
The correct answer is D because enabling data integrity checks ensures that the data remains unchanged, which is essential for accurate auditing and compliance. Options A, B, and C pertain to different aspects of system integrity and security but do not directly relate to the integrity of the data itself.