Pre-Winter Sale Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: pass65

Pass the Splunk Splunk Enterprise Certified Architect SPLK-2002 Questions and answers with CertsForce

Viewing page 5 out of 6 pages
Viewing questions 41-50 out of questions
Questions # 41:

In which phase of the Splunk Enterprise data pipeline are indexed extraction configurations processed?

Options:

A.

Input


B.

Search


C.

Parsing


D.

Indexing


Expert Solution
Questions # 42:

Which command will permanently decommission a peer node operating in an indexer cluster?

Options:

A.

splunk stop -f


B.

splunk offline -f


C.

splunk offline --enforce-counts


D.

splunk decommission --enforce counts


Expert Solution
Questions # 43:

(A customer has converted a CSV lookup to a KV Store lookup. What must be done to make it available for an automatic lookup?)

Options:

A.

Add the repFactor=true attribute in collections.conf.


B.

Add the replicate=true attribute in lookups.conf.


C.

Add the replicate=true attribute in collections.conf.


D.

Add the repFactor=true attribute in lookups.conf.


Expert Solution
Questions # 44:

(A customer has a Splunk Enterprise deployment and wants to collect data from universal forwarders. What is the best step to secure log traffic?)

Options:

A.

Create signed SSL certificates and use them to encrypt data between the forwarders and indexers.


B.

Use the Splunk provided SSL certificates to encrypt data between the forwarders and indexers.


C.

Ensure all forwarder traffic is routed through a web application firewall (WAF).


D.

Create signed SSL certificates and use them to encrypt data between the search heads and indexers.


Expert Solution
Questions # 45:

Which command should be run to re-sync a stale KV Store member in a search head cluster?

Options:

A.

splunk clean kvstore -local


B.

splunk resync kvstore -remote


C.

splunk resync kvstore -local


D.

splunk clean eventdata -local


Expert Solution
Questions # 46:

When designing the number and size of indexes, which of the following considerations should be applied?

Options:

A.

Expected daily ingest volume, access controls, number of concurrent users


B.

Number of installed apps, expected daily ingest volume, data retention time policies


C.

Data retention time policies, number of installed apps, access controls


D.

Expected daily ingest volumes, data retention time policies, access controls


Expert Solution
Questions # 47:

Which Splunk tool offers a health check for administrators to evaluate the health of their Splunk deployment?

Options:

A.

btool


B.

DiagGen


C.

SPL Clinic


D.

Monitoring Console


Expert Solution
Questions # 48:

When troubleshooting monitor inputs, which command checks the status of the tailed files?

Options:

A.

splunk cmd btool inputs list | tail


B.

splunk cmd btool check inputs layer


C.

curl https://serverhost:8089/services/admin/inputstatus/TailingProcessor:FileStatus


D.

curl https://serverhost:8089/services/admin/inputstatus/TailingProcessor:Tailstatus


Expert Solution
Questions # 49:

Which of the following is unsupported in a production environment?

Options:

A.

Cluster Manager can run on the Monitoring Console instance in smaller environments.


B.

Search Head Cluster Deployer can run on the Monitoring Console instance in smaller environments.


C.

Search heads in a Search Head Cluster can run on virtual machines.


D.

Indexers in an indexer cluster can run on virtual machines.


Expert Solution
Questions # 50:

(The performance of a specific search is performing poorly. The search must run over All Time and is expected to have very few results. Analysis shows that the search accesses a very large number of buckets in a large index. What step would most significantly improve the performance of this search?)

Options:

A.

Increase the disk I/O hardware performance.


B.

Increase the number of indexing pipelines.


C.

Set indexed_realtime_use_by_default = true in limits.conf.


D.

Change this to a real-time search using an All Time window.


Expert Solution
Viewing page 5 out of 6 pages
Viewing questions 41-50 out of questions