Labour Day Special 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: exams65

Splunk Enterprise Certified Architect Question and Answers

Splunk Enterprise Certified Architect

Last Update May 2, 2024
Total Questions : 160

We are offering FREE SPLK-2002 Splunk exam questions. All you do is to just go and sign up. Give your details, prepare SPLK-2002 free exam questions and then go for complete pool of Splunk Enterprise Certified Architect test questions that will help you more.

SPLK-2002 pdf

SPLK-2002 PDF

$35  $99.99
SPLK-2002 Engine

SPLK-2002 Testing Engine

$42  $119.99
SPLK-2002 PDF + Engine

SPLK-2002 PDF + Testing Engine

$56  $159.99
Questions 1

Which two sections can be expanded using the Search Job Inspector?

Options:

A.  

Execution costs.

B.  

Saved search history.

C.  

Search job properties.

D.  

Optimization suggestions.

Discussion 0
Questions 2

Which props.conf setting has the least impact on indexing performance?

Options:

A.  

SHOULD_LINEMERGE

B.  

TRUNCATE

C.  

CHARSET

D.  

TIME_PREFIX

Discussion 0
Questions 3

In an existing Splunk environment, the new index buckets that are created each day are about half the size of the incoming data. Within each bucket, about 30% of the space is used for rawdata and about 70% for index files.

What additional information is needed to calculate the daily disk consumption, per indexer, if indexer clustering is implemented?

Options:

A.  

Total daily indexing volume, number of peer nodes, and number of accelerated searches.

B.  

Total daily indexing volume, number of peer nodes, replication factor, and search factor.

C.  

Total daily indexing volume, replication factor, search factor, and number of search heads.

D.  

Replication factor, search factor, number of accelerated searches, and total disk size across cluster.

Discussion 0
Questions 4

Which Splunk internal index contains license-related events?

Options:

A.  

_audit

B.  

_license

C.  

_internal

D.  

_introspection

Discussion 0
Questions 5

What information is written to the __introspection log file?

Options:

A.  

File monitor input configurations.

B.  

File monitor checkpoint offset.

C.  

User activities and knowledge objects.

D.  

KV store performance.

Discussion 0
Questions 6

In the deployment planning process, when should a person identify who gets to see network data?

Options:

A.  

Deployment schedule

B.  

Topology diagramming

C.  

Data source inventory

D.  

Data policy definition

Discussion 0
Questions 7

Search dashboards in the Monitoring Console indicate that the distributed deployment is approaching its capacity. Which of the following options will provide the most search performance improvement?

Options:

A.  

Replace the indexer storage to solid state drives (SSD).

B.  

Add more search heads and redistribute users based on the search type.

C.  

Look for slow searches and reschedule them to run during an off-peak time.

D.  

Add more search peers and make sure forwarders distribute data evenly across all indexers.

Discussion 0
Questions 8

When configuring a Splunk indexer cluster, what are the default values for replication and search factor?

Options:

A.  

replication_factor = 2search_factor = 2

B.  

replication_factor = 2search factor = 3

C.  

replication_factor = 3search_factor = 2

D.  

replication_factor = 3search factor = 3

Discussion 0
Questions 9

When Splunk indexes data in a non-clustered environment, what kind of files does it create by default?

Options:

A.  

Index and .tsidx files.

B.  

Rawdata and index files.

C.  

Compressed and .tsidx files.

D.  

Compressed and meta data files.

Discussion 0
Questions 10

To optimize the distribution of primary buckets; when does primary rebalancing automatically occur? (Select all that apply.)

Options:

A.  

Rolling restart completes.

B.  

Master node rejoins the cluster.

C.  

Captain joins or rejoins cluster.

D.  

A peer node joins or rejoins the cluster.

Discussion 0
Questions 11

As of Splunk 9.0, which index records changes to . conf files?

Options:

A.  

_configtracker

B.  

_introspection

C.  

_internal

D.  

_audit

Discussion 0
Questions 12

Of the following types of files within an index bucket, which file type may consume the most disk?

Options:

A.  

Rawdata

B.  

Bloom filter

C.  

Metadata (.data)

D.  

Inverted index (.tsidx)

Discussion 0
Questions 13

Where does the Splunk deployer send apps by default?

Options:

A.  

etc/slave-apps//default

B.  

etc/deploy-apps//default

C.  

etc/apps//default

D.  

etc/shcluster//default

Discussion 0
Questions 14

How does the average run time of all searches relate to the available CPU cores on the indexers?

Options:

A.  

Average run time is independent of the number of CPU cores on the indexers.

B.  

Average run time decreases as the number of CPU cores on the indexers decreases.

C.  

Average run time increases as the number of CPU cores on the indexers decreases.

D.  

Average run time increases as the number of CPU cores on the indexers increases.

Discussion 0
Questions 15

Which of the following is an indexer clustering requirement?

Options:

A.  

Must use shared storage.

B.  

Must reside on a dedicated rack.

C.  

Must have at least three members.

D.  

Must share the same license pool.

Discussion 0
Questions 16

In a four site indexer cluster, which configuration stores two searchable copies at the origin site, one searchable copy at site2, and a total of four searchable copies?

Options:

A.  

site_search_factor = origin:2, site1:2, total:4

B.  

site_search_factor = origin:2, site2:1, total:4

C.  

site_replication_factor = origin:2, site1:2, total:4

D.  

site_replication_factor = origin:2, site2:1, total:4

Discussion 0
Questions 17

Which of the following use cases would be made possible by multi-site clustering? (select all that apply)

Options:

A.  

Use blockchain technology to audit search activity from geographically dispersed data centers.

B.  

Enable a forwarder to send data to multiple indexers.

C.  

Greatly reduce WAN traffic by preferentially searching assigned site (search affinity).

D.  

Seamlessly route searches to a redundant site in case of a site failure.

Discussion 0
Questions 18

Which of the following is true for indexer cluster knowledge bundles?

Options:

A.  

Only app-name/local is pushed.

B.  

app-name/default and app-name/local are merged before pushing.

C.  

Only app-name/default is pushed.

D.  

app-name/default and app-name/local are pushed without change.

Discussion 0
Questions 19

Which server.conf attribute should be added to the master node's server.conf file when decommissioning a site in an indexer cluster?

Options:

A.  

site_mappings

B.  

available_sites

C.  

site_search_factor

D.  

site_replication_factor

Discussion 0
Questions 20

What is a Splunk Job? (Select all that apply.)

Options:

A.  

A user-defined Splunk capability.

B.  

Searches that are subjected to some usage quota.

C.  

A search process kicked off via a report or an alert.

D.  

A child OS process manifested from the splunkd process.

Discussion 0
Questions 21

Which of the following items are important sizing parameters when architecting a Splunk environment? (select all that apply)

Options:

A.  

Number of concurrent users.

B.  

Volume of incoming data.

C.  

Existence of premium apps.

D.  

Number of indexes.

Discussion 0
Questions 22

If there is a deployment server with many clients and one deployment client is not updating apps, which of the following should be done first?

Options:

A.  

Choose a longer phone home interval for all of the deployment clients.

B.  

Increase the number of CPU cores for the deployment server.

C.  

Choose a corrective action based on the splunkd. log of the deployment client.

D.  

Increase the amount of memory for the deployment server.

Discussion 0
Questions 23

Users who receive a link to a search are receiving an "Unknown sid" error message when they open the link.

Why is this happening?

Options:

A.  

The users have insufficient permissions.

B.  

An add-on needs to be updated.

C.  

The search job has expired.

D.  

One or more indexers are down.

Discussion 0
Questions 24

Which Splunk internal field can confirm duplicate event issues from failed file monitoring?

Options:

A.  

_time

B.  

_indextime

C.  

_index_latest

D.  

latest

Discussion 0
Questions 25

Which instance can not share functionality with the deployer?

Options:

A.  

Search head cluster member

B.  

License master

C.  

Master node

D.  

Monitoring Console (MC)

Discussion 0
Questions 26

Data for which of the following indexes will count against an ingest-based license?

Options:

A.  

summary

B.  

main

C.  

_metrics

D.  

_introspection

Discussion 0
Questions 27

Which of the following should be done when installing Enterprise Security on a Search Head Cluster? (Select all that apply.)

Options:

A.  

Install Enterprise Security on the deployer.

B.  

Install Enterprise Security on a staging instance.

C.  

Copy the Enterprise Security configurations to the deployer.

D.  

Use the deployer to deploy Enterprise Security to the cluster members.

Discussion 0
Questions 28

Which of the following tasks should the architect perform when building a deployment plan? (Select all that apply.)

Options:

A.  

Use case checklist.

B.  

Install Splunk apps.

C.  

Inventory data sources.

D.  

Review network topology.

Discussion 0
Questions 29

New data has been added to a monitor input file. However, searches only show older data.

Which splunkd. log channel would help troubleshoot this issue?

Options:

A.  

Modularlnputs

B.  

TailingProcessor

C.  

ChunkedLBProcessor

D.  

ArchiveProcessor

Discussion 0
Questions 30

Which of the following Splunk deployments has the recommended minimum components for a high-availability search head cluster?

Options:

A.  

2 search heads, 1 deployer, 2 indexers

B.  

3 search heads, 1 deployer, 3 indexers

C.  

1 search head, 1 deployer, 3 indexers

D.  

2 search heads, 1 deployer, 3 indexers

Discussion 0
Questions 31

Which of the following can a Splunk diag contain?

Options:

A.  

Search history, Splunk users and their roles, running processes, indexed data

B.  

Server specs, current open connections, internal Splunk log files, index listings

C.  

KV store listings, internal Splunk log files, search peer bundles listings, indexed data

D.  

Splunk platform configuration details, Splunk users and their roles, current open connections, index listings

Discussion 0
Questions 32

Because Splunk indexing is read/write intensive, it is important to select the appropriate disk storage solution for each deployment. Which of the following statements is accurate about disk storage?

Options:

A.  

High performance SAN should never be used.

B.  

Enable NFS for storing hot and warm buckets.

C.  

The recommended RAID setup is RAID 10 (1 + 0).

D.  

Virtualized environments are usually preferred over bare metal for Splunk indexers.

Discussion 0
Questions 33

What information is needed about the current environment before deploying Splunk? (select all that apply)

Options:

A.  

List of vendors for network devices.

B.  

Overall goals for the deployment.

C.  

Key users.

D.  

Data sources.

Discussion 0
Questions 34

By default, what happens to configurations in the local folder of each Splunk app when it is deployed to a search head cluster?

Options:

A.  

The local folder is copied to the local folder on the search heads.

B.  

The local folder is merged into the default folder and deployed to the search heads.

C.  

Only certain . conf files in the local folder are deployed to the search heads.

D.  

The local folder is ignored and only the default folder is copied to the search heads.

Discussion 0
Questions 35

In search head clustering, which of the following methods can you use to transfer captaincy to a different member? (Select all that apply.)

Options:

A.  

Use the Monitoring Console.

B.  

Use the Search Head Clustering settings menu from Splunk Web on any member.

C.  

Run the splunk transfer shcluster-captain command from the current captain.

D.  

Run the splunk transfer shcluster-captain command from the member you would like to become the captain.

Discussion 0
Questions 36

A customer currently has many deployment clients being managed by a single, dedicated deployment server. The customer plans to double the number of clients.

What could be done to minimize performance issues?

Options:

A.  

Modify deploymentclient. conf to change from a Pull to Push mechanism.

B.  

Reduce the number of apps in the Manager Node repository.

C.  

Increase the current deployment client phone home interval.

D.  

Decrease the current deployment client phone home interval.

Discussion 0
Questions 37

What types of files exist in a bucket within a clustered index? (select all that apply)

Options:

A.  

Inside a replicated bucket, there is only rawdata.

B.  

Inside a searchable bucket, there is only tsidx.

C.  

Inside a searchable bucket, there is tsidx and rawdata.

D.  

Inside a replicated bucket, there is both tsidx and rawdata.

Discussion 0
Questions 38

If .delta replication fails during knowledge bundle replication, what is the fall-back method for Splunk?

Options:

A.  

.Restart splunkd.

B.  

.delta replication.

C.  

.bundle replication.

D.  

Restart mongod.

Discussion 0
Questions 39

A Splunk deployment is being architected and the customer will be using Splunk Enterprise Security (ES) and Splunk IT Service Intelligence (ITSI). Through data onboarding and sizing, it is determined that over 200 discrete KPIs will be tracked by ITSI and 1TB of data per day by ES. What topology ensures a scalable and performant deployment?

Options:

A.  

Two search heads, one for ITSI and one for ES.

B.  

Two search head clusters, one for ITSI and one for ES.

C.  

One search head cluster with both ITSI and ES installed.

D.  

One search head with both ITSI and ES installed.

Discussion 0
Questions 40

On search head cluster members, where in $splunk_home does the Splunk Deployer deploy app content by default?

Options:

A.  

etc/apps/

B.  

etc/slave-apps/

C.  

etc/shcluster/

D.  

etc/deploy-apps/

Discussion 0
Questions 41

The guidance Splunk gives for estimating size on for syslog data is 50% of original data size. How does this divide between files in the index?

Options:

A.  

rawdata is: 10%, tsidx is: 40%

B.  

rawdata is: 15%, tsidx is: 35%

C.  

rawdata is: 35%, tsidx is: 15%

D.  

rawdata is: 40%, tsidx is: 10%

Discussion 0
Questions 42

A customer is migrating 500 Universal Forwarders from an old deployment server to a new deployment server, with a different DNS name. The new deployment server is configured and running.

The old deployment server deployed an app containing an updated deploymentclient.conf file to all forwarders, pointing them to the new deployment server. The app was successfully deployed to all 500 forwarders.

Why would all of the forwarders still be phoning home to the old deployment server?

Options:

A.  

There is a version mismatch between the forwarders and the new deployment server.

B.  

The new deployment server is not accepting connections from the forwarders.

C.  

The forwarders are configured to use the old deployment server in $SPLUNK_HOME/etc/system/local.

D.  

The pass4SymmKey is the same on the new deployment server and the forwarders.

Discussion 0
Questions 43

A Splunk architect has inherited the Splunk deployment at Buttercup Games and end users are complaining that the events are inconsistently formatted for a web source. Further investigation reveals that not all weblogs flow through the same infrastructure: some of the data goes through heavy forwarders and some of the forwarders are managed by another department.

Which of the following items might be the cause of this issue?

Options:

A.  

The search head may have different configurations than the indexers.

B.  

The data inputs are not properly configured across all the forwarders.

C.  

The indexers may have different configurations than the heavy forwarders.

D.  

The forwarders managed by the other department are an older version than the rest.

Discussion 0
Questions 44

Which of the following server. conf stanzas indicates the Indexer Discovery feature has not been fully configured (restart pending) on the Master Node?

A)

B)

C)

D)

Options:

A.  

Option A

B.  

Option B

C.  

Option C

D.  

Option D

Discussion 0
Questions 45

When should a Universal Forwarder be used instead of a Heavy Forwarder?

Options:

A.  

When most of the data requires masking.

B.  

When there is a high-velocity data source.

C.  

When data comes directly from a database server.

D.  

When a modular input is needed.

Discussion 0
Questions 46

Which of the following would be the least helpful in troubleshooting contents of Splunk configuration files?

Options:

A.  

crash logs

B.  

search.log

C.  

btool output

D.  

diagnostic logs

Discussion 0
Questions 47

Which of the following statements describe search head clustering? (Select all that apply.)

Options:

A.  

A deployer is required.

B.  

At least three search heads are needed.

C.  

Search heads must meet the high-performance reference server requirements.

D.  

The deployer must have sufficient CPU and network resources to process service requests and push configurations.

Discussion 0
Questions 48

When should a dedicated deployment server be used?

Options:

A.  

When there are more than 50 search peers.

B.  

When there are more than 50 apps to deploy to deployment clients.

C.  

When there are more than 50 deployment clients.

D.  

When there are more than 50 server classes.

Discussion 0