Big 11.11 Sale 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: sale65best

Free Splunk SPLK-2002 Practice Exam with Questions & Answers | Set: 3

Questions 21

Which of the following server. conf stanzas indicates the Indexer Discovery feature has not been fully configured (restart pending) on the Master Node?

A)

SPLK-2002 Question 21

B)

SPLK-2002 Question 21

C)

SPLK-2002 Question 21

D)

SPLK-2002 Question 21

Options:
A.

Option A

B.

Option B

C.

Option C

D.

Option D

Splunk SPLK-2002 Premium Access
Questions 22

Determining data capacity for an index is a non-trivial exercise. Which of the following are possible considerations that would affect daily indexing volume? (select all that apply)

Options:
A.

Average size of event data.

B.

Number of data sources.

C.

Peak data rates.

D.

Number of concurrent searches on data.

Questions 23

Which of the following will cause the greatest reduction in disk size requirements for a cluster of N indexers running Splunk Enterprise Security?

Options:
A.

Setting the cluster search factor to N-1.

B.

Increasing the number of buckets per index.

C.

Decreasing the data model acceleration range.

D.

Setting the cluster replication factor to N-1.

Questions 24

What log file would you search to verify if you suspect there is a problem interpreting a regular expression in a monitor stanza?

Options:
A.

btool.log

B.

metrics.log

C.

splunkd.log

D.

tailing_processor.log

Questions 25

Which of the following is true for indexer cluster knowledge bundles?

Options:
A.

Only app-name/local is pushed.

B.

app-name/default and app-name/local are merged before pushing.

C.

Only app-name/default is pushed.

D.

app-name/default and app-name/local are pushed without change.

Questions 26

A Splunk deployment is being architected and the customer will be using Splunk Enterprise Security (ES) and Splunk IT Service Intelligence (ITSI). Through data onboarding and sizing, it is determined that over 200 discrete KPIs will be tracked by ITSI and 1TB of data per day by ES. What topology ensures a scalable and performant deployment?

Options:
A.

Two search heads, one for ITSI and one for ES.

B.

Two search head clusters, one for ITSI and one for ES.

C.

One search head cluster with both ITSI and ES installed.

D.

One search head with both ITSI and ES installed.

Questions 27

(Which of the following is not facilitated by the deployer?)

Options:
A.

Replication of knowledge objects.

B.

Deployment of baseline app configurations.

C.

Distribute non-replicated, non-runtime configuration updates.

D.

Migration of app and user configurations into the search head cluster.

Questions 28

(What is the best way to configure and manage receiving ports for clustered indexers?)

Options:
A.

Use Splunk Web to create the receiving port on each peer node.

B.

Define the receiving port in /etc/deployment-apps/cluster-app/local/inputs.conf and deploy it to the peer nodes.

C.

Run the splunk enable listen command on each peer node.

D.

Define the receiving port in /etc/manager-apps/_cluster/local/inputs.conf and push it to the peer nodes.

Questions 29

Which of the following is true regarding Splunk Enterprise's performance? (Select all that apply.)

Options:
A.

Adding search peers increases the maximum size of search results.

B.

Adding RAM to existing search heads provides additional search capacity.

C.

Adding search peers increases the search throughput as the search load increases.

D.

Adding search heads provides additional CPU cores to run more concurrent searches.

Questions 30

(A customer has converted a CSV lookup to a KV Store lookup. What must be done to make it available for an automatic lookup?)

Options:
A.

Add the repFactor=true attribute in collections.conf.

B.

Add the replicate=true attribute in lookups.conf.

C.

Add the replicate=true attribute in collections.conf.

D.

Add the repFactor=true attribute in lookups.conf.