Spring Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70track

Free Splunk SPLK-2002 Practice Exam with Questions & Answers | Set: 4

Questions 31

A multi-site indexer cluster can be configured using which of the following? (Select all that apply.)

Options:
A.

Via Splunk Web.

B.

Directly edit SPLUNK_HOME/etc./system/local/server.conf

C.

Run a Splunk edit cluster-config command from the CLI.

D.

Directly edit SPLUNK_HOME/etc/system/default/server.conf

Splunk SPLK-2002 Premium Access
Questions 32

What information is needed about the current environment before deploying Splunk? (select all that apply)

Options:
A.

List of vendors for network devices.

B.

Overall goals for the deployment.

C.

Key users.

D.

Data sources.

Questions 33

Which of the following options can improve reliability of syslog delivery to Splunk? (Select all that apply.)

Options:
A.

Use TCP syslog.

B.

Configure UDP inputs on each Splunk indexer to receive data directly.

C.

Use a network load balancer to direct syslog traffic to active backend syslog listeners.

D.

Use one or more syslog servers to persist data with a Universal Forwarder to send the data to Splunk indexers.

Questions 34

Splunk Enterprise performs a cyclic redundancy check (CRC) against the first and last bytes to prevent the same file from being re-indexed if it is rotated or renamed. What is the number of bytes sampled by default?

Options:
A.

128

B.

512

C.

256

D.

64

Questions 35

(What command will decommission a search peer from an indexer cluster?)

Options:
A.

splunk disablepeer --enforce-counts

B.

splunk decommission —enforce-counts

C.

splunk offline —enforce-counts

D.

splunk remove cluster-peers —enforce-counts

Questions 36

Which of the following is true regarding Splunk Enterprise's performance? (Select all that apply.)

Options:
A.

Adding search peers increases the maximum size of search results.

B.

Adding RAM to existing search heads provides additional search capacity.

C.

Adding search peers increases the search throughput as the search load increases.

D.

Adding search heads provides additional CPU cores to run more concurrent searches.

Questions 37

When converting from a single-site to a multi-site cluster, what happens to existing single-site clustered buckets?

Options:
A.

They will continue to replicate within the origin site and age out based on existing policies.

B.

They will maintain replication as required according to the single-site policies, but never age out.

C.

They will be replicated across all peers in the multi-site cluster and age out based on existing policies.

D.

They will stop replicating within the single-site and remain on the indexer they reside on and age out according to existing policies.

Questions 38

How does the average run time of all searches relate to the available CPU cores on the indexers?

Options:
A.

Average run time is independent of the number of CPU cores on the indexers.

B.

Average run time decreases as the number of CPU cores on the indexers decreases.

C.

Average run time increases as the number of CPU cores on the indexers decreases.

D.

Average run time increases as the number of CPU cores on the indexers increases.

Questions 39

When using ingest-based licensing, what Splunk role requires the license manager to scale?

Options:
A.

Search peers

B.

Search heads

C.

There are no roles that require the license manager to scale

D.

Deployment clients

Questions 40

(Which of the following is not facilitated by the deployer?)

Options:
A.

Replication of knowledge objects.

B.

Deployment of baseline app configurations.

C.

Distribute non-replicated, non-runtime configuration updates.

D.

Migration of app and user configurations into the search head cluster.