Pass the Splunk Splunk Enterprise Certified Architect SPLK-2002 Questions and answers with CertsForce

Viewing page 2 out of 5 pages
Viewing questions 11-20 out of questions
Questions # 11:

As a best practice, where should the internal licensing logs be stored?

Options:

A.

Indexing layer.


B.

License server.


C.

Deployment layer.


D.

Search head layer.


Expert Solution
Questions # 12:

Which Splunk Enterprise offering has its own license?

Options:

A.

Splunk Cloud Forwarder


B.

Splunk Heavy Forwarder


C.

Splunk Universal Forwarder


D.

Splunk Forwarder Management


Expert Solution
Questions # 13:

Splunk configuration parameter settings can differ between multiple .conf files of the same name contained within different apps. Which of the following directories has the highest precedence?

Options:

A.

System local directory.


B.

System default directory.


C.

App local directories, in ASCII order.


D.

App default directories, in ASCII order.


Expert Solution
Questions # 14:

To optimize the distribution of primary buckets; when does primary rebalancing automatically occur? (Select all that apply.)

Options:

A.

Rolling restart completes.


B.

Master node rejoins the cluster.


C.

Captain joins or rejoins cluster.


D.

A peer node joins or rejoins the cluster.


Expert Solution
Questions # 15:

Of the following types of files within an index bucket, which file type may consume the most disk?

Options:

A.

Rawdata


B.

Bloom filter


C.

Metadata (.data)


D.

Inverted index (.tsidx)


Expert Solution
Questions # 16:

In splunkd. log events written to the _internal index, which field identifies the specific log channel?

Options:

A.

component


B.

source


C.

sourcetype


D.

channel


Expert Solution
Questions # 17:

Which command should be run to re-sync a stale KV Store member in a search head cluster?

Options:

A.

splunk clean kvstore -local


B.

splunk resync kvstore -remote


C.

splunk resync kvstore -local


D.

splunk clean eventdata -local


Expert Solution
Questions # 18:

Because Splunk indexing is read/write intensive, it is important to select the appropriate disk storage solution for each deployment. Which of the following statements is accurate about disk storage?

Options:

A.

High performance SAN should never be used.


B.

Enable NFS for storing hot and warm buckets.


C.

The recommended RAID setup is RAID 10 (1 + 0).


D.

Virtualized environments are usually preferred over bare metal for Splunk indexers.


Expert Solution
Questions # 19:

Which of the following statements describe a Search Head Cluster (SHC) captain? (Select all that apply.)

Options:

A.

Is the job scheduler for the entire SHC.


B.

Manages alert action suppressions (throttling).


C.

Synchronizes the member list with the KV store primary.


D.

Replicates the SHC's knowledge bundle to the search peers.


Expert Solution
Questions # 20:

Which of the following is an indexer clustering requirement?

Options:

A.

Must use shared storage.


B.

Must reside on a dedicated rack.


C.

Must have at least three members.


D.

Must share the same license pool.


Expert Solution
Viewing page 2 out of 5 pages
Viewing questions 11-20 out of questions