Big Cyber Monday Sale 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: exams65

ExamsBrite Dumps

Splunk Enterprise Certified Architect Question and Answers

Splunk Enterprise Certified Architect

Last Update Dec 7, 2025
Total Questions : 202

We are offering FREE SPLK-2002 Splunk exam questions. All you do is to just go and sign up. Give your details, prepare SPLK-2002 free exam questions and then go for complete pool of Splunk Enterprise Certified Architect test questions that will help you more.

SPLK-2002 pdf

SPLK-2002 PDF

$36.75  $104.99
SPLK-2002 Engine

SPLK-2002 Testing Engine

$43.75  $124.99
SPLK-2002 PDF + Engine

SPLK-2002 PDF + Testing Engine

$57.75  $164.99
Questions 1

Users who receive a link to a search are receiving an "Unknown sid" error message when they open the link.

Why is this happening?

Options:

A.  

The users have insufficient permissions.

B.  

An add-on needs to be updated.

C.  

The search job has expired.

D.  

One or more indexers are down.

Discussion 0
Questions 2

A customer has a four site indexer cluster. The customer has requirements to store five copies of searchable data, with one searchable copy of data at the origin site, and one searchable copy at the disaster recovery site (site4).

Which configuration meets these requirements?

Options:

A.  

site_replication_factor = origin:2, site4:l, total:3

B.  

site_replication_factor = origin:l, site4:l, total:5

C.  

site_search_factor = origin:2, site4:l, total:3

D.  

site search factor = origin:1, site4:l, total:5

Discussion 0
Questions 3

Which of the following will cause the greatest reduction in disk size requirements for a cluster of N indexers running Splunk Enterprise Security?

Options:

A.  

Setting the cluster search factor to N-1.

B.  

Increasing the number of buckets per index.

C.  

Decreasing the data model acceleration range.

D.  

Setting the cluster replication factor to N-1.

Discussion 0
Questions 4

Which of the following describe migration from single-site to multisite index replication?

Options:

A.  

A master node is required at each site.

B.  

Multisite policies apply to new data only.

C.  

Single-site buckets instantly receive the multisite policies.

D.  

Multisite total values should not exceed any single-site factors.

Discussion 0
Questions 5

Which of the following strongly impacts storage sizing requirements for Enterprise Security?

Options:

A.  

The number of scheduled (correlation) searches.

B.  

The number of Splunk users configured.

C.  

The number of source types used in the environment.

D.  

The number of Data Models accelerated.

Discussion 0
Questions 6

Which two sections can be expanded using the Search Job Inspector?

Options:

A.  

Execution costs.

B.  

Saved search history.

C.  

Search job properties.

D.  

Optimization suggestions.

Discussion 0
Questions 7

Which Splunk component is mandatory when implementing a search head cluster?

Options:

A.  

Captain Server

B.  

Deployer

C.  

Cluster Manager

D.  

RAFT Server

Discussion 0
Questions 8

Which of the following items are important sizing parameters when architecting a Splunk environment? (select all that apply)

Options:

A.  

Number of concurrent users.

B.  

Volume of incoming data.

C.  

Existence of premium apps.

D.  

Number of indexes.

Discussion 0
Questions 9

When planning a search head cluster, which of the following is true?

Options:

A.  

All search heads must use the same operating system.

B.  

All search heads must be members of the cluster (no standalone search heads).

C.  

The search head captain must be assigned to the largest search head in the cluster.

D.  

All indexers must belong to the underlying indexer cluster (no standalone indexers).

Discussion 0
Questions 10

(If the maxDataSize attribute is set to auto_high_volume in indexes.conf on a 64-bit operating system, what is the maximum hot bucket size?)

Options:

A.  

4 GB

B.  

750 MB

C.  

10 GB

D.  

1 GB

Discussion 0
Questions 11

What information is written to the __introspection log file?

Options:

A.  

File monitor input configurations.

B.  

File monitor checkpoint offset.

C.  

User activities and knowledge objects.

D.  

KV store performance.

Discussion 0
Questions 12

On search head cluster members, where in $splunk_home does the Splunk Deployer deploy app content by default?

Options:

A.  

etc/apps/

B.  

etc/slave-apps/

C.  

etc/shcluster/

D.  

etc/deploy-apps/

Discussion 0
Questions 13

How does the average run time of all searches relate to the available CPU cores on the indexers?

Options:

A.  

Average run time is independent of the number of CPU cores on the indexers.

B.  

Average run time decreases as the number of CPU cores on the indexers decreases.

C.  

Average run time increases as the number of CPU cores on the indexers decreases.

D.  

Average run time increases as the number of CPU cores on the indexers increases.

Discussion 0
Questions 14

When implementing KV Store Collections in a search head cluster, which of the following considerations is true?

Options:

A.  

The KV Store Primary coordinates with the search head cluster captain when collection content changes.

B.  

The search head cluster captain is also the KV Store Primary when collection content changes.

C.  

The KV Store Collection will not allow for changes to content if there are more than 50 search heads in the cluster.

D.  

Each search head in the cluster independently updates its KV store collection when collection content changes.

Discussion 0
Questions 15

(What command will decommission a search peer from an indexer cluster?)

Options:

A.  

splunk disablepeer --enforce-counts

B.  

splunk decommission —enforce-counts

C.  

splunk offline —enforce-counts

D.  

splunk remove cluster-peers —enforce-counts

Discussion 0
Questions 16

Which of the following statements describe search head clustering? (Select all that apply.)

Options:

A.  

A deployer is required.

B.  

At least three search heads are needed.

C.  

Search heads must meet the high-performance reference server requirements.

D.  

The deployer must have sufficient CPU and network resources to process service requests and push configurations.

Discussion 0
Questions 17

When Splunk indexes data in a non-clustered environment, what kind of files does it create by default?

Options:

A.  

Index and .tsidx files.

B.  

Rawdata and index files.

C.  

Compressed and .tsidx files.

D.  

Compressed and meta data files.

Discussion 0
Questions 18

In splunkd. log events written to the _internal index, which field identifies the specific log channel?

Options:

A.  

component

B.  

source

C.  

sourcetype

D.  

channel

Discussion 0
Questions 19

To expand the search head cluster by adding a new member, node2, what first step is required?

Options:

A.  

splunk bootstrap shcluster-config -mgmt_uri https://node2:8089 -replication_port 9200 -secret supersecretkey

B.  

splunk init shcluster-config -master_uri https://node2:8089 -replication_port 9200 -secret supersecretkey

C.  

splunk init shcluster-config -mgmt_uri https://node2:8089 -replication_port 9200 -secret supersecretkey

D.  

splunk add shcluster-member -new_member_uri https://node2:8089 -replication_port 9200 -secret supersecretkey

Discussion 0
Questions 20

(How can a Splunk admin control the logging level for a specific search to get further debug information?)

Options:

A.  

Configure infocsv_log_level = DEBUG in limits.conf.

B.  

Insert | noop log_debug=* after the base search.

C.  

Open the Search Job Inspector in Splunk Web and modify the log level.

D.  

Use Settings > Server settings > Server logging in Splunk Web.

Discussion 0
Questions 21

In a four site indexer cluster, which configuration stores two searchable copies at the origin site, one searchable copy at site2, and a total of four searchable copies?

Options:

A.  

site_search_factor = origin:2, site1:2, total:4

B.  

site_search_factor = origin:2, site2:1, total:4

C.  

site_replication_factor = origin:2, site1:2, total:4

D.  

site_replication_factor = origin:2, site2:1, total:4

Discussion 0
Questions 22

Which of the following is unsupported in a production environment?

Options:

A.  

Cluster Manager can run on the Monitoring Console instance in smaller environments.

B.  

Search Head Cluster Deployer can run on the Monitoring Console instance in smaller environments.

C.  

Search heads in a Search Head Cluster can run on virtual machines.

D.  

Indexers in an indexer cluster can run on virtual machines.

Discussion 0
Questions 23

A customer has a multisite cluster with site1 and site2 configured. They want to configure search heads in these sites to get search results only from data stored on their local sites. Which step prevents this behavior?

Options:

A.  

Set site=site0 in the [general] stanza of server.conf on the search head.

B.  

Configure site_search_factor = site1:1, total:2.

C.  

Implement only two indexers per site.

D.  

Configure site_search_factor = site1:2, total:3.

Discussion 0
Questions 24

Determining data capacity for an index is a non-trivial exercise. Which of the following are possible considerations that would affect daily indexing volume? (select all that apply)

Options:

A.  

Average size of event data.

B.  

Number of data sources.

C.  

Peak data rates.

D.  

Number of concurrent searches on data.

Discussion 0
Questions 25

To optimize the distribution of primary buckets; when does primary rebalancing automatically occur? (Select all that apply.)

Options:

A.  

Rolling restart completes.

B.  

Master node rejoins the cluster.

C.  

Captain joins or rejoins cluster.

D.  

A peer node joins or rejoins the cluster.

Discussion 0
Questions 26

(The performance of a specific search is performing poorly. The search must run over All Time and is expected to have very few results. Analysis shows that the search accesses a very large number of buckets in a large index. What step would most significantly improve the performance of this search?)

Options:

A.  

Increase the disk I/O hardware performance.

B.  

Increase the number of indexing pipelines.

C.  

Set indexed_realtime_use_by_default = true in limits.conf.

D.  

Change this to a real-time search using an All Time window.

Discussion 0
Questions 27

Which of the following can a Splunk diag contain?

Options:

A.  

Search history, Splunk users and their roles, running processes, indexed data

B.  

Server specs, current open connections, internal Splunk log files, index listings

C.  

KV store listings, internal Splunk log files, search peer bundles listings, indexed data

D.  

Splunk platform configuration details, Splunk users and their roles, current open connections, index listings

Discussion 0
Questions 28

(When determining where a Splunk forwarder is trying to send data, which of the following searches can provide assistance?)

Options:

A.  

index=_internal sourcetype=internal metrics destHost | dedup destHost

B.  

index=_internal sourcetype=splunkd metrics inputHost | dedup inputHost

C.  

index=_metrics sourcetype=splunkd metrics destHost | dedup destHost

D.  

index=_internal sourcetype=splunkd metrics destHost | dedup destHost

Discussion 0
Questions 29

A search head cluster member contains the following in its server .conf. What is the Splunk server name of this member?

Options:

A.  

node1

B.  

shc4

C.  

idxc2

D.  

node3

Discussion 0
Questions 30

Search dashboards in the Monitoring Console indicate that the distributed deployment is approaching its capacity. Which of the following options will provide the most search performance improvement?

Options:

A.  

Replace the indexer storage to solid state drives (SSD).

B.  

Add more search heads and redistribute users based on the search type.

C.  

Look for slow searches and reschedule them to run during an off-peak time.

D.  

Add more search peers and make sure forwarders distribute data evenly across all indexers.

Discussion 0
Questions 31

Which Splunk tool offers a health check for administrators to evaluate the health of their Splunk deployment?

Options:

A.  

btool

B.  

DiagGen

C.  

SPL Clinic

D.  

Monitoring Console

Discussion 0
Questions 32

Which of the following options in limits, conf may provide performance benefits at the forwarding tier?

Options:

A.  

Enable the indexed_realtime_use_by_default attribute.

B.  

Increase the maxKBps attribute.

C.  

Increase the parallellngestionPipelines attribute.

D.  

Increase the max_searches per_cpu attribute.

Discussion 0
Questions 33

Which of the following should be included in a deployment plan?

Options:

A.  

Business continuity and disaster recovery plans.

B.  

Current logging details and data source inventory.

C.  

Current and future topology diagrams of the IT environment.

D.  

A comprehensive list of stakeholders, either direct or indirect.

Discussion 0
Questions 34

Splunk configuration parameter settings can differ between multiple .conf files of the same name contained within different apps. Which of the following directories has the highest precedence?

Options:

A.  

System local directory.

B.  

System default directory.

C.  

App local directories, in ASCII order.

D.  

App default directories, in ASCII order.

Discussion 0
Questions 35

When using ingest-based licensing, what Splunk role requires the license manager to scale?

Options:

A.  

Search peers

B.  

Search heads

C.  

There are no roles that require the license manager to scale

D.  

Deployment clients

Discussion 0
Questions 36

What is needed to ensure that high-velocity sources will not have forwarding delays to the indexers?

Options:

A.  

Increase the default value of sessionTimeout in server, conf.

B.  

Increase the default limit for maxKBps in limits.conf.

C.  

Decrease the value of forceTimebasedAutoLB in outputs. conf.

D.  

Decrease the default value of phoneHomelntervallnSecs in deploymentclient .conf.

Discussion 0
Questions 37

Which of the following security options must be explicitly configured (i.e. which options are not enabled by default)?

Options:

A.  

Data encryption between Splunk Web and splunkd.

B.  

Certificate authentication between forwarders and indexers.

C.  

Certificate authentication between Splunk Web and search head.

D.  

Data encryption for distributed search between search heads and indexers.

Discussion 0
Questions 38

Which of the following are true statements about Splunk indexer clustering?

Options:

A.  

All peer nodes must run exactly the same Splunk version.

B.  

The master node must run the same or a later Splunk version than search heads.

C.  

The peer nodes must run the same or a later Splunk version than the master node.

D.  

The search head must run the same or a later Splunk version than the peer nodes.

Discussion 0
Questions 39

Which of the following most improves KV Store resiliency?

Options:

A.  

Decrease latency between search heads.

B.  

Add faster storage to the search heads to improve artifact replication.

C.  

Add indexer CPU and memory to decrease search latency.

D.  

Increase the size of the Operations Log.

Discussion 0
Questions 40

(Which of the following is a valid way to determine if a new bundle push will trigger a rolling restart?)

Options:

A.  

splunk show cluster-bundle-status

B.  

splunk apply cluster-bundle

C.  

splunk validate cluster-bundle —check-restart

D.  

splunk apply cluster-bundle —validate-bundle

Discussion 0
Questions 41

A customer has installed a 500GB Enterprise license. They also purchased and installed a 300GB, no enforcement license on the same license master. How much data can the customer ingest before the search is locked out?

Options:

A.  

300GB. After this limit, the search is locked out.

B.  

500G

B.  

After this limit, the search is locked out.

C.  

800GB. After this limit, the search is locked out.

D.  

Search is not locked out. Violations are still recorded.

Discussion 0
Questions 42

(Which command is used to initially add a search head to a single-site indexer cluster?)

Options:

A.  

splunk edit cluster-config -mode searchhead -manager_uri https://10.0.0.1:8089 -secret changeme

B.  

splunk edit cluster-config -mode peer -manager_uri https://10.0.0.1:8089 -secret changeme

C.  

splunk add cluster-manager -manager_uri https://10.0.0.1:8089 -secret changeme

D.  

splunk add cluster-manager -mode searchhead -manager_uri https://10.0.0.1:8089 -secret changeme

Discussion 0
Questions 43

By default, what happens to configurations in the local folder of each Splunk app when it is deployed to a search head cluster?

Options:

A.  

The local folder is copied to the local folder on the search heads.

B.  

The local folder is merged into the default folder and deployed to the search heads.

C.  

Only certain . conf files in the local folder are deployed to the search heads.

D.  

The local folder is ignored and only the default folder is copied to the search heads.

Discussion 0
Questions 44

(When planning user management for a new Splunk deployment, which task can be disregarded?)

Options:

A.  

Identify users authenticating with Splunk native authentication.

B.  

Identify users authenticating with Splunk using LDAP or SAML.

C.  

Determine the number of users present in Splunk log events.

D.  

Determine the capabilities users need within the Splunk environment.

Discussion 0
Questions 45

(What are the possible values for the mode attribute in server.conf for a Splunk server in the [clustering] stanza?)

Options:

A.  

[clustering] mode = peer

B.  

[clustering] mode = searchhead

C.  

[clustering] mode = deployer

D.  

[clustering] mode = manager

Discussion 0
Questions 46

The frequency in which a deployment client contacts the deployment server is controlled by what?

Options:

A.  

polling_interval attribute in outputs.conf

B.  

phoneHomeIntervalInSecs attribute in outputs.conf

C.  

polling_interval attribute in deploymentclient.conf

D.  

phoneHomeIntervalInSecs attribute in deploymentclient.conf

Discussion 0
Questions 47

A three-node search head cluster is skipping a large number of searches across time. What should be done to increase scheduled search capacity on the search head cluster?

Options:

A.  

Create a job server on the cluster.

B.  

Add another search head to the cluster.

C.  

server.conf captain_is_adhoc_searchhead = true.

D.  

Change limits.conf value for max_searches_per_cpu to a higher value.

Discussion 0
Questions 48

Which of the following tasks should the architect perform when building a deployment plan? (Select all that apply.)

Options:

A.  

Use case checklist.

B.  

Install Splunk apps.

C.  

Inventory data sources.

D.  

Review network topology.

Discussion 0
Questions 49

How can internal logging levels in a Splunk environment be changed to troubleshoot an issue? (select all that apply)

Options:

A.  

Use the Monitoring Console (MC).

B.  

Use Splunk command line.

C.  

Use Splunk Web.

D.  

Edit log-local. cfg.

Discussion 0
Questions 50

(Based on the data sizing and retention parameters listed below, which of the following will correctly calculate the index storage required?)

• Daily rate = 20 GB / day

• Compress factor = 0.5

• Retention period = 30 days

• Padding = 100 GB

Options:

A.  

(20 * 30 + 100) * 0.5 = 350 GB

B.  

20 / 0.5 * 30 + 100 = 1300 GB

C.  

20 * 0.5 * 30 + 100 = 400 GB

D.  

20 * 30 + 100 = 700 GB

Discussion 0
Questions 51

When should a Universal Forwarder be used instead of a Heavy Forwarder?

Options:

A.  

When most of the data requires masking.

B.  

When there is a high-velocity data source.

C.  

When data comes directly from a database server.

D.  

When a modular input is needed.

Discussion 0
Questions 52

In which phase of the Splunk Enterprise data pipeline are indexed extraction configurations processed?

Options:

A.  

Input

B.  

Search

C.  

Parsing

D.  

Indexing

Discussion 0
Questions 53

A Splunk instance has the following settings in SPLUNK_HOME/etc/system/local/server.conf:

[clustering]

mode = master

replication_factor = 2

pass4SymmKey = password123

Which of the following statements describe this Splunk instance? (Select all that apply.)

Options:

A.  

This is a multi-site cluster.

B.  

This cluster's search factor is 2.

C.  

This Splunk instance needs to be restarted.

D.  

This instance is missing the master_uri attribute.

Discussion 0
Questions 54

A customer currently has many deployment clients being managed by a single, dedicated deployment server. The customer plans to double the number of clients.

What could be done to minimize performance issues?

Options:

A.  

Modify deploymentclient. conf to change from a Pull to Push mechanism.

B.  

Reduce the number of apps in the Manager Node repository.

C.  

Increase the current deployment client phone home interval.

D.  

Decrease the current deployment client phone home interval.

Discussion 0
Questions 55

metrics. log is stored in which index?

Options:

A.  

main

B.  

_telemetry

C.  

_internal

D.  

_introspection

Discussion 0
Questions 56

In a distributed environment, knowledge object bundles are replicated from the search head to which location on the search peer(s)?

Options:

A.  

SPLUNK_HOME/var/lib/searchpeers

B.  

SPLUNK_HOME/var/log/searchpeers

C.  

SPLUNK_HOME/var/run/searchpeers

D.  

SPLUNK_HOME/var/spool/searchpeers

Discussion 0
Questions 57

Consider a use case involving firewall data. There is no Splunk-supported Technical Add-On, but the vendor has built one. What are the items that must be evaluated before installing the add-on? (Select all that apply.)

Options:

A.  

Identify number of scheduled or real-time searches.

B.  

Validate if this Technical Add-On enables event data for a data model.

C.  

Identify the maximum number of forwarders Technical Add-On can support.

D.  

Verify if Technical Add-On needs to be installed onto both a search head or indexer.

Discussion 0
Questions 58

A Splunk user successfully extracted an ip address into a field called src_ip. Their colleague cannot see that field in their search results with events known to have src_ip. Which of the following may explain the problem? (Select all that apply.)

Options:

A.  

The field was extracted as a private knowledge object.

B.  

The events are tagged as communicate, but are missing the network tag.

C.  

The Typing Queue, which does regular expression replacements, is blocked.

D.  

The colleague did not explicitly use the field in the search and the search was set to Fast Mode.

Discussion 0
Questions 59

Users are asking the Splunk administrator to thaw recently-frozen buckets very frequently. What could the Splunk administrator do to reduce the need to thaw buckets?

Options:

A.  

Change f rozenTimePeriodlnSecs to a larger value.

B.  

Change maxTotalDataSizeMB to a smaller value.

C.  

Change maxHotSpanSecs to a larger value.

D.  

Change coldToFrozenDir to a different location.

Discussion 0
Questions 60

What does setting site=site0 on all Search Head Cluster members do in a multi-site indexer cluster?

Options:

A.  

Disables search site affinity.

B.  

Sets all members to dynamic captaincy.

C.  

Enables multisite search artifact replication.

D.  

Enables automatic search site affinity discovery.

Discussion 0