Pass the Splunk Splunk Enterprise Certified Architect SPLK-2002 Questions and answers with CertsForce

Viewing page 4 out of 5 pages
Viewing questions 31-40 out of questions
Questions # 31:

When should multiple search pipelines be enabled?

Options:

A.

Only if disk IOPS is at 800 or better.


B.

Only if there are fewer than twelve concurrent users.


C.

Only if running Splunk Enterprise version 6.6 or later.


D.

Only if CPU and memory resources are significantly under-utilized.


Expert Solution
Questions # 32:

Where does the Splunk deployer send apps by default?

Options:

A.

etc/slave-apps/<app-name>/default


B.

etc/deploy-apps/<app-name>/default


C.

etc/apps/<appname>/default


D.

etc/shcluster/<app-name>/default


Expert Solution
Questions # 33:

A search head cluster with a KV store collection can be updated from where in the KV store collection?

Options:

A.

The search head cluster captain.


B.

The KV store primary search head.


C.

Any search head except the captain.


D.

Any search head in the cluster.


Expert Solution
Questions # 34:

Splunk Enterprise platform instrumentation refers to data that the Splunk Enterprise deployment logs in the _introspection index. Which of the following logs are included in this index? (Select all that apply.)

Options:

A.

audit.log


B.

metrics.log


C.

disk_objects.log


D.

resource_usage.log


Expert Solution
Questions # 35:

Splunk Enterprise performs a cyclic redundancy check (CRC) against the first and last bytes to prevent the same file from being re-indexed if it is rotated or renamed. What is the number of bytes sampled by default?

Options:

A.

128


B.

512


C.

256


D.

64


Expert Solution
Questions # 36:

A Splunk instance has the following settings in SPLUNK_HOME/etc/system/local/server.conf:

[clustering]

mode = master

replication_factor = 2

pass4SymmKey = password123

Which of the following statements describe this Splunk instance? (Select all that apply.)

Options:

A.

This is a multi-site cluster.


B.

This cluster's search factor is 2.


C.

This Splunk instance needs to be restarted.


D.

This instance is missing the master_uri attribute.


Expert Solution
Questions # 37:

Search dashboards in the Monitoring Console indicate that the distributed deployment is approaching its capacity. Which of the following options will provide the most search performance improvement?

Options:

A.

Replace the indexer storage to solid state drives (SSD).


B.

Add more search heads and redistribute users based on the search type.


C.

Look for slow searches and reschedule them to run during an off-peak time.


D.

Add more search peers and make sure forwarders distribute data evenly across all indexers.


Expert Solution
Questions # 38:

Which command is used for thawing the archive bucket?

Options:

A.

Splunk collect


B.

Splunk convert


C.

Splunk rebuild


D.

Splunk dbinspect


Expert Solution
Questions # 39:

In which phase of the Splunk Enterprise data pipeline are indexed extraction configurations processed?

Options:

A.

Input


B.

Search


C.

Parsing


D.

Indexing


Expert Solution
Questions # 40:

The frequency in which a deployment client contacts the deployment server is controlled by what?

Options:

A.

polling_interval attribute in outputs.conf


B.

phoneHomeIntervalInSecs attribute in outputs.conf


C.

polling_interval attribute in deploymentclient.conf


D.

phoneHomeIntervalInSecs attribute in deploymentclient.conf


Expert Solution
Viewing page 4 out of 5 pages
Viewing questions 31-40 out of questions