Pass the Splunk Splunk Enterprise Certified Architect SPLK-2002 Questions and answers with CertsForce

Viewing page 3 out of 5 pages
Viewing questions 21-30 out of questions
Questions # 21:

Which of the following statements describe search head clustering? (Select all that apply.)

Options:

A.

A deployer is required.


B.

At least three search heads are needed.


C.

Search heads must meet the high-performance reference server requirements.


D.

The deployer must have sufficient CPU and network resources to process service requests and push configurations.


Expert Solution
Questions # 22:

Indexing is slow and real-time search results are delayed in a Splunk environment with two indexers and one search head. There is ample CPU and memory available on the indexers. Which of the following is most likely to improve indexing performance?

Options:

A.

Increase the maximum number of hot buckets in indexes.conf


B.

Increase the number of parallel ingestion pipelines in server.conf


C.

Decrease the maximum size of the search pipelines in limits.conf


D.

Decrease the maximum concurrent scheduled searches in limits.conf


Expert Solution
Questions # 23:

Other than high availability, which of the following is a benefit of search head clustering?

Options:

A.

Allows indexers to maintain multiple searchable copies of all data.


B.

Input settings are synchronized between search heads.


C.

Fewer network ports are required to be opened between search heads.


D.

Automatic replication of user knowledge objects.


Expert Solution
Questions # 24:

A search head cluster member contains the following in its server .conf. What is the Splunk server name of this member?

Question # 24

Options:

A.

node1


B.

shc4


C.

idxc2


D.

node3


Expert Solution
Questions # 25:

When using ingest-based licensing, what Splunk role requires the license manager to scale?

Options:

A.

Search peers


B.

Search heads


C.

There are no roles that require the license manager to scale


D.

Deployment clients


Expert Solution
Questions # 26:

Which of the following strongly impacts storage sizing requirements for Enterprise Security?

Options:

A.

The number of scheduled (correlation) searches.


B.

The number of Splunk users configured.


C.

The number of source types used in the environment.


D.

The number of Data Models accelerated.


Expert Solution
Questions # 27:

What is the logical first step when starting a deployment plan?

Options:

A.

Inventory the currently deployed logging infrastructure.


B.

Determine what apps and use cases will be implemented.


C.

Gather statistics on the expected adoption of Splunk for sizing.


D.

Collect the initial requirements for the deployment from all stakeholders.


Expert Solution
Questions # 28:

An index has large text log entries with many unique terms in the raw data. Other than the raw data, which index components will take the most space?

Options:

A.

Index files (*. tsidx files).


B.

Bloom filters (bloomfilter files).


C.

Index source metadata (sources.data files).


D.

Index sourcetype metadata (SourceTypes. data files).


Expert Solution
Questions # 29:

Users are asking the Splunk administrator to thaw recently-frozen buckets very frequently. What could the Splunk administrator do to reduce the need to thaw buckets?

Options:

A.

Change f rozenTimePeriodlnSecs to a larger value.


B.

Change maxTotalDataSizeMB to a smaller value.


C.

Change maxHotSpanSecs to a larger value.


D.

Change coldToFrozenDir to a different location.


Expert Solution
Questions # 30:

Which Splunk server role regulates the functioning of indexer cluster?

Options:

A.

Indexer


B.

Deployer


C.

Master Node


D.

Monitoring Console


Expert Solution
Viewing page 3 out of 5 pages
Viewing questions 21-30 out of questions