Pass the Splunk Splunk Enterprise Certified Admin SPLK-1003 Questions and answers with CertsForce

Viewing page 1 out of 6 pages
Viewing questions 1-10 out of questions
Questions # 1:

Which of the following is a benefit of distributed search?

Options:

A.

Peers run search in sequence.


B.

Peers run search in parallel.


C.

Resilience from indexer failure.


D.

Resilience from search head failure.


Expert Solution
Questions # 2:

What is required when adding a native user to Splunk? (select all that apply)

Options:

A.

Password


B.

Username


C.

Full Name


D.

Default app


Expert Solution
Questions # 3:

When using license pools, volume allocations apply to which Splunk components?

Options:

A.

Indexers


B.

Indexes


C.

Heavy Forwarders


D.

Search Heads


Expert Solution
Questions # 4:

Which forwarder is recommended by Splunk to use in a production environment?

Options:

A.

Heavy forwarder


B.

SSL forwarder


C.

Lightweight forwarder


D.

Universal forwarder


Expert Solution
Questions # 5:

Consider a company with a Splunk distributed environment in production. The Compliance Department wants to start using Splunk; however, they want to ensure that no one can see their reports or any other knowledge objects. Which Splunk Component can be added to implement this policy for the new team?

Options:

A.

Indexer


B.

Deployment server


C.

Universal forwarder


D.

Search head


Expert Solution
Questions # 6:

What hardware attribute would need to be changed to increase the number of simultaneous searches (ad-hoc and scheduled) on a single search head?

Options:

A.

Disk


B.

CPUs


C.

Memory


D.

Network interface cards


Expert Solution
Questions # 7:

During search time, which directory of configuration files has the highest precedence?

Options:

A.

$SFLUNK_KOME/etc/system/local


B.

$SPLUNK_KCME/etc/system/default


C.

$SPLUNK_HCME/etc/apps/app1/local


D.

$SPLUNK HCME/etc/users/admin/local


Expert Solution
Questions # 8:

An admin is running the latest version of Splunk with a 500 GB license. The current daily volume of new data

is 300 GB per day. To minimize license issues, what is the best way to add 10 TB of historical data to the

index?

Options:

A.

Buy a bigger Splunk license.


B.

Add 2.5 TB each day for the next 5 days.


C.

Add all 10 TB in a single 24 hour period.


D.

Add 200 GB of historical data each day for 50 days.


Expert Solution
Questions # 9:

Which of the following must be done to define user permissions when integrating Splunk with LDAP?

Options:

A.

Map Users


B.

Map Groups


C.

Map LDAP Inheritance


D.

Map LDAP to Active Directory


Expert Solution
Questions # 10:

Which artifact is required in the request header when creating an HTTP event?

Options:

A.

ackID


B.

Token


C.

Manifest


D.

Host name


Expert Solution
Viewing page 1 out of 6 pages
Viewing questions 1-10 out of questions