Pre-Winter Sale Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: pass65

Pass the Splunk Splunk Enterprise Certified Architect SPLK-2002 Questions and answers with CertsForce

Viewing page 4 out of 6 pages
Viewing questions 31-40 out of questions
Questions # 31:

(What is the expected performance reduction when architecting Splunk in a virtualized environment instead of a physical environment?)

Options:

A.

Up to 15%


B.

Between 20% and 45%


C.

0


D.

0.5


Expert Solution
Questions # 32:

Which of the following strongly impacts storage sizing requirements for Enterprise Security?

Options:

A.

The number of scheduled (correlation) searches.


B.

The number of Splunk users configured.


C.

The number of source types used in the environment.


D.

The number of Data Models accelerated.


Expert Solution
Questions # 33:

To optimize the distribution of primary buckets; when does primary rebalancing automatically occur? (Select all that apply.)

Options:

A.

Rolling restart completes.


B.

Master node rejoins the cluster.


C.

Captain joins or rejoins cluster.


D.

A peer node joins or rejoins the cluster.


Expert Solution
Questions # 34:

(What command will decommission a search peer from an indexer cluster?)

Options:

A.

splunk disablepeer --enforce-counts


B.

splunk decommission —enforce-counts


C.

splunk offline —enforce-counts


D.

splunk remove cluster-peers —enforce-counts


Expert Solution
Questions # 35:

By default, what happens to configurations in the local folder of each Splunk app when it is deployed to a search head cluster?

Options:

A.

The local folder is copied to the local folder on the search heads.


B.

The local folder is merged into the default folder and deployed to the search heads.


C.

Only certain . conf files in the local folder are deployed to the search heads.


D.

The local folder is ignored and only the default folder is copied to the search heads.


Expert Solution
Questions # 36:

The guidance Splunk gives for estimating size on for syslog data is 50% of original data size. How does this divide between files in the index?

Options:

A.

rawdata is: 10%, tsidx is: 40%


B.

rawdata is: 15%, tsidx is: 35%


C.

rawdata is: 35%, tsidx is: 15%


D.

rawdata is: 40%, tsidx is: 10%


Expert Solution
Questions # 37:

Which of the following is a way to exclude search artifacts when creating a diag?

Options:

A.

SPLUNK_HOME/bin/splunk diag --exclude


B.

SPLUNK_HOME/bin/splunk diag --debug --refresh


C.

SPLUNK_HOME/bin/splunk diag --disable=dispatch


D.

SPLUNK_HOME/bin/splunk diag --filter-searchstrings


Expert Solution
Questions # 38:

If there is a deployment server with many clients and one deployment client is not updating apps, which of the following should be done first?

Options:

A.

Choose a longer phone home interval for all of the deployment clients.


B.

Increase the number of CPU cores for the deployment server.


C.

Choose a corrective action based on the splunkd. log of the deployment client.


D.

Increase the amount of memory for the deployment server.


Expert Solution
Questions # 39:

(Which of the following is a benefit of using SmartStore?)

Options:

A.

Automatic selection of replication and search factors.


B.

Separating storage from compute.


C.

Knowledge Object replication.


D.

Cluster Manager is no longer required.


Expert Solution
Questions # 40:

Of the following types of files within an index bucket, which file type may consume the most disk?

Options:

A.

Rawdata


B.

Bloom filter


C.

Metadata (.data)


D.

Inverted index (.tsidx)


Expert Solution
Viewing page 4 out of 6 pages
Viewing questions 31-40 out of questions