Pass the Splunk Splunk Core Certified Consultant SPLK-3003 Questions and answers with CertsForce

Viewing page 2 out of 3 pages
Viewing questions 11-20 out of questions
Questions # 11:

A customer wants to migrate from using Splunk local accounts to use Active Directory with LDAP for their Splunk user accounts instead. Which configuration files must be modified to connect to an Active Directory LDAP provider?

Options:

A.

authentication.conf, authorize.conf, ldap.conf


B.

authentication.conf, ldap.conf


C.

authentication.conf


D.

authorize.conf, authentication.conf


Expert Solution
Questions # 12:

What is the default push mode for a search head cluster deployer app configuration bundle?

Options:

A.

full


B.

merge_to_default


C.

default_only


D.

local_only


Expert Solution
Questions # 13:

What should be considered when running the following CLI commands with a goal of accelerating an index cluster migration to new hardware?

Question # 13

Options:

A.

Data ingestion rate


B.

Network latency and storage IOPS


C.

Distance and location


D.

SSL data encryption


Expert Solution
Questions # 14:

The data in Splunk is now subject to auditing and compliance controls. A customer would like to ensure that at least one year of logs are retained for both Windows and Firewall events. What data retention controls must be configured?

Options:

A.

maxTotalDataSizeMB and frozenTimePeriodInSecs


B.

coldToFrozenDir and coldToFrozenScript


C.

Splunk Volume and maxTotalDataSizMB


D.

Splunk Volume and frozenTimePeriodInSecs


Expert Solution
Questions # 15:

A customer is migrating their existing Splunk Indexer from an old set of hardware to a new set of indexers. What is the earliest method to migrate the system?

Options:

A.

1. Add new indexers to the cluster as peers, in the same site (if needed).

2.Ensure new indexers receive common configuration.

3.Decommission old indexers (one at a time) to allow time for CM to fix/migrate buckets to new hardware.

4.Remove all the old indexers from the CM’s list.


B.

1. Add new indexers to the cluster as peers, to a new site.

2.Ensure new indexers receive common configuration from the CM.

3.Decommission old indexers (one at a time) to allow time for CM to fix/migrate buckets to new hardware.

4.Remove all the old indexers from the CM’s list.


C.

1. Add new indexers to the cluster as peers, in the same site.

2.Update the replication factor by +1 to Instruct the cluster to start replicating to new peers.

3.Allow time for CM to fix/migrate buckets to new hardware.

4.Remove all the old indexers from the CM’s list.


D.

1. Add new indexers to the cluster as new site.

2.Update cluster master (CM) server.conf to include the new available site.

3.Allow time for CM to fix/migrate buckets to new hardware.

4.Remove the old indexers from the CM’s list.


Expert Solution
Questions # 16:

The universal forwarder (UF) should be used whenever possible, as it is smaller and more efficient. In which of the following scenarios would a heavy forwarder (HF) be a more appropriate choice?

Options:

A.

When a predictable version of Python is required.


B.

When filtering 10%–15% of incoming events.


C.

When monitoring a log file.


D.

When running a script.


Expert Solution
Questions # 17:

A customer is using regex to whitelist access logs and secure logs from a web server, but only the access logs are being ingested. Which troubleshooting resource would provide insight into why the secure logs are not being ingested?

Options:

A.

list monitor


B.

oneshot


C.

btprobe


D.

tailingprocessor


Expert Solution
Questions # 18:

In an environment that has Indexer Clustering, the Monitoring Console (MC) provides dashboards to monitor environment health. As the environment grows over time and new indexers are added, which steps would ensure the MC is aware of the additional indexers?

Options:

A.

No changes are necessary, the Monitoring Console has self-configuration capabilities.


B.

Using the MC setup UI, review and apply the changes.


C.

Remove and re-add the cluster master from the indexer clustering UI page to add new peers, then apply the changes under the MC setup UI.


D.

Each new indexer needs to be added using the distributed search UI, then settings must be saved under the MC setup UI.


Expert Solution
Questions # 19:

Where does the bloom filter reside?

Options:

A.

$SPLUNK_HOME/var/lib/splunk/indexfoo/db/db_1553504858_1553504507_8


B.

$SPLUNK_HOME/var/lib/splunk/indexfoo/db/db_1553504858_1553504507_8/*.tsidx


C.

$SPLUNK_HOME/var/lib/splunk/fishbucket


D.

$SPLUNK_HOME/var/lib/splunk/indexfoo/db/db_1553504858_1553504507_8/rawdata


Expert Solution
Questions # 20:

A working search head cluster has been set up and used for 6 months with just the native/local Splunk user authentication method. In order to integrate the search heads with an external Active Directory server using LDAP, which of the following statements represents the most appropriate method to deploy the configuration to the servers?

Options:

A.

Configure the integration in a base configuration app located in shcluster-apps directory on the search head deployer, then deploy the configuration to the search heads using the splunk apply shcluster- bundle command.


B.

Log onto each search using a command line utility. Modify the authentication.conf and

authorize.conf files in a base configuration app to configure the integration.


C.

Configure the LDAP integration on one Search Head using the Settings > Access Controls > Authentication Method and Settings > Access Controls > Roles Splunk UI menus. The configuration setting will replicate to the other nodes in the search head cluster eliminating the need to do this on the other search heads.


D.

On each search head, login and configure the LDAP integration using the Settings > Access Controls > Authentication Method and Settings > Access Controls > Roles Splunk UI menus.


Expert Solution
Viewing page 2 out of 3 pages
Viewing questions 11-20 out of questions