Big 11.11 Sale 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: sale65best

Free Splunk SPLK-2002 Practice Exam with Questions & Answers | Set: 5

Questions 41

On search head cluster members, where in $splunk_home does the Splunk Deployer deploy app content by default?

Options:
A.

etc/apps/

B.

etc/slave-apps/

C.

etc/shcluster/

D.

etc/deploy-apps/

Splunk SPLK-2002 Premium Access
Questions 42

Which of the following configuration attributes must be set in server, conf on the cluster manager in a single-site indexer cluster?

Options:
A.

master_uri

B.

site

C.

replication_factor

D.

site_replication_factor

Questions 43

Which of the following clarification steps should be taken if apps are not appearing on a deployment client? (Select all that apply.)

Options:
A.

Check serverclass.conf of the deployment server.

B.

Check deploymentclient.conf of the deployment client.

C.

Check the content of SPLUNK_HOME/etc/apps of the deployment server.

D.

Search for relevant events in splunkd.log of the deployment server.

Questions 44

A customer currently has many deployment clients being managed by a single, dedicated deployment server. The customer plans to double the number of clients.

What could be done to minimize performance issues?

Options:
A.

Modify deploymentclient. conf to change from a Pull to Push mechanism.

B.

Reduce the number of apps in the Manager Node repository.

C.

Increase the current deployment client phone home interval.

D.

Decrease the current deployment client phone home interval.

Questions 45

Which of the following describe migration from single-site to multisite index replication?

Options:
A.

A master node is required at each site.

B.

Multisite policies apply to new data only.

C.

Single-site buckets instantly receive the multisite policies.

D.

Multisite total values should not exceed any single-site factors.

Questions 46

A multi-site indexer cluster can be configured using which of the following? (Select all that apply.)

Options:
A.

Via Splunk Web.

B.

Directly edit SPLUNK_HOME/etc./system/local/server.conf

C.

Run a Splunk edit cluster-config command from the CLI.

D.

Directly edit SPLUNK_HOME/etc/system/default/server.conf

Questions 47

(A customer creates a saved search that runs on a specific interval. Which internal Splunk log should be viewed to determine if the search ran recently?)

Options:
A.

metrics.log

B.

kvstore.log

C.

scheduler.log

D.

btool.log

Questions 48

(A customer has a Splunk Enterprise deployment and wants to collect data from universal forwarders. What is the best step to secure log traffic?)

Options:
A.

Create signed SSL certificates and use them to encrypt data between the forwarders and indexers.

B.

Use the Splunk provided SSL certificates to encrypt data between the forwarders and indexers.

C.

Ensure all forwarder traffic is routed through a web application firewall (WAF).

D.

Create signed SSL certificates and use them to encrypt data between the search heads and indexers.

Questions 49

By default, what happens to configurations in the local folder of each Splunk app when it is deployed to a search head cluster?

Options:
A.

The local folder is copied to the local folder on the search heads.

B.

The local folder is merged into the default folder and deployed to the search heads.

C.

Only certain . conf files in the local folder are deployed to the search heads.

D.

The local folder is ignored and only the default folder is copied to the search heads.

Questions 50

Which of the following Splunk deployments has the recommended minimum components for a high-availability search head cluster?

Options:
A.

2 search heads, 1 deployer, 2 indexers

B.

3 search heads, 1 deployer, 3 indexers

C.

1 search head, 1 deployer, 3 indexers

D.

2 search heads, 1 deployer, 3 indexers