New Year Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: simple70

Pass the Splunk Splunk Enterprise Certified Architect SPLK-2002 Questions and answers with CertsForce

Viewing page 5 out of 6 pages
Viewing questions 41-50 out of questions
Questions # 41:

Splunk Enterprise performs a cyclic redundancy check (CRC) against the first and last bytes to prevent the same file from being re-indexed if it is rotated or renamed. What is the number of bytes sampled by default?

Options:

A.

128


B.

512


C.

256


D.

64


Expert Solution
Questions # 42:

(A customer has converted a CSV lookup to a KV Store lookup. What must be done to make it available for an automatic lookup?)

Options:

A.

Add the repFactor=true attribute in collections.conf.


B.

Add the replicate=true attribute in lookups.conf.


C.

Add the replicate=true attribute in collections.conf.


D.

Add the repFactor=true attribute in lookups.conf.


Expert Solution
Questions # 43:

(A customer has a Splunk Enterprise deployment and wants to collect data from universal forwarders. What is the best step to secure log traffic?)

Options:

A.

Create signed SSL certificates and use them to encrypt data between the forwarders and indexers.


B.

Use the Splunk provided SSL certificates to encrypt data between the forwarders and indexers.


C.

Ensure all forwarder traffic is routed through a web application firewall (WAF).


D.

Create signed SSL certificates and use them to encrypt data between the search heads and indexers.


Expert Solution
Questions # 44:

In search head clustering, which of the following methods can you use to transfer captaincy to a different member? (Select all that apply.)

Options:

A.

Use the Monitoring Console.


B.

Use the Search Head Clustering settings menu from Splunk Web on any member.


C.

Run the splunk transfer shcluster-captain command from the current captain.


D.

Run the splunk transfer shcluster-captain command from the member you would like to become the captain.


Expert Solution
Questions # 45:

What does setting site=site0 on all Search Head Cluster members do in a multi-site indexer cluster?

Options:

A.

Disables search site affinity.


B.

Sets all members to dynamic captaincy.


C.

Enables multisite search artifact replication.


D.

Enables automatic search site affinity discovery.


Expert Solution
Questions # 46:

As a best practice, where should the internal licensing logs be stored?

Options:

A.

Indexing layer.


B.

License server.


C.

Deployment layer.


D.

Search head layer.


Expert Solution
Questions # 47:

(A customer has an environment with a Search Head Cluster and an indexer cluster. They are troubleshooting license usage data, including indexed volume in bytes per pool, index, host, sourcetype, and source. Where should the license_usage.log file be retrieved from in this environment?)

Options:

A.

Cluster Manager and Search Head Cluster Deployer


B.

License Manager


C.

Search Head Cluster Deployer only


D.

All indexers


Expert Solution
Questions # 48:

In an indexer cluster, what tasks does the cluster manager perform? (select all that apply)

Options:

A.

Generates and maintains the list of primary searchable buckets.


B.

If Indexer Discovery is enabled, provides the list of available peer nodes to forwarders.


C.

Ensures all peer nodes are always using the same version of Splunk.


D.

Distributes app bundles to peer nodes.


Expert Solution
Questions # 49:

(How can a Splunk admin control the logging level for a specific search to get further debug information?)

Options:

A.

Configure infocsv_log_level = DEBUG in limits.conf.


B.

Insert | noop log_debug=* after the base search.


C.

Open the Search Job Inspector in Splunk Web and modify the log level.


D.

Use Settings > Server settings > Server logging in Splunk Web.


Expert Solution
Questions # 50:

What is the algorithm used to determine captaincy in a Splunk search head cluster?

Options:

A.

Raft distributed consensus.


B.

Rapt distributed consensus.


C.

Rift distributed consensus.


D.

Round-robin distribution consensus.


Expert Solution
Viewing page 5 out of 6 pages
Viewing questions 41-50 out of questions