Summer Special 60% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: bestdeal

Free Splunk SPLK-3003 Practice Exam with Questions & Answers

Questions 1

The data in Splunk is now subject to auditing and compliance controls. A customer would like to ensure that at least one year of logs are retained for both Windows and Firewall events. What data retention controls must be configured?

Options:
A.

maxTotalDataSizeMB and frozenTimePeriodInSecs

B.

coldToFrozenDir and coldToFrozenScript

C.

Splunk Volume and maxTotalDataSizMB

D.

Splunk Volume and frozenTimePeriodInSecs

Splunk SPLK-3003 Premium Access
Questions 2

Which configuration item should be set to false to significantly improve data ingestion performance?

Options:
A.

AUTO_KV_JSON

B.

BREAK_ONLY_BEFORE_DATE

C.

SHOULD_LINEMERGE

D.

ANNOTATE_PUNCT

Questions 3

A customer would like Splunk to delete files after they’ve been ingested. The Universal Forwarder has read/ write access to the directory structure. Which input type would be most appropriate to use in order to ensure files are ingested and then deleted afterwards?

Options:
A.

Script

B.

Batch

C.

Monitor

D.

Fschange

Questions 4

When a bucket rolls from cold to frozen on a clustered indexer, which of the following scenarios occurs?

Options:
A.

All replicated copies will be rolled to frozen; original copies will remain.

B.

Replicated copies of the bucket will remain on all other indexers and the Cluster Master (CM) assigns a new primary bucket.

C.

The bucket rolls to frozen on all clustered indexers simultaneously.

D.

Nothing. Replicated copies of the bucket will remain on all other indexers until a local retention rule causes it to roll.

Questions 5

A customer has been using Splunk for one year, utilizing a single/all-in-one instance. This single Splunk server is now struggling to cope with the daily ingest rate. Also, Splunk has become a vital system in day-to-day operations making high availability a consideration for the Splunk service. The customer is unsure how to design the new environment topology in order to provide this.

Which resource would help the customer gather the requirements for their new architecture?

Options:
A.

Direct the customer to the docs.splunk.com and tell them that all the information to help them select the right design is documented there.

B.

Ask the customer to engage with the sales team immediately as they probably need a larger license.

C.

Refer the customer to answers.splunk.com as someone else has probably already designed a system that meets their requirements.

D.

Refer the customer to the Splunk Validated Architectures document in order to guide them through which approved architectures could meet their requirements.

Questions 6

A Splunk Index cluster is being installed and the indexers need to be configured with a license master. After the customer provides the name of the license master, what is the next step?

Options:
A.

Enter the license master configuration via Splunk web on each indexer before disabling Splunk web.

B.

Update /opt/splunk/etc/master-apps/_cluster/default/server.conf on the cluster master and apply a cluster bundle.

C.

Update the Splunk PS base config license app and copy to each indexer.

D.

Update the Splunk PS base config license app and deploy via the cluster master.

Questions 7

A customer has downloaded the Splunk App for AWS from Splunk base and installed it in a search head cluster following the instructions using the deployer. A power user modifies a dashboard in the app on one of the search head cluster members. The app containing an updated dashboard is upgraded to the latest version by following the instructions via the deployer.

What happens?

Options:
A.

The updated dashboard will not be deployed globally to all users, due to the conflict with the power user’s modified version of the dashboard.

B.

Applying the search head cluster bundle will fail due to the conflict.

C.

The updated dashboard will be available to the power user.

D.

The updated dashboard will not be available to the power user; they will see their modified version.

Questions 8

When setting up a multisite search head and indexer cluster, which nodes are required to declare site membership?

Options:
A.

Search head cluster members, deployer, indexers, cluster master

B.

Search head cluster members, deployment server, deployer, indexers, cluster master

C.

All splunk nodes, including forwarders, must declare site membership

D.

Search head cluster members, indexers, cluster master

Questions 9

In an environment that has Indexer Clustering, the Monitoring Console (MC) provides dashboards to monitor environment health. As the environment grows over time and new indexers are added, which steps would ensure the MC is aware of the additional indexers?

Options:
A.

No changes are necessary, the Monitoring Console has self-configuration capabilities.

B.

Using the MC setup UI, review and apply the changes.

C.

Remove and re-add the cluster master from the indexer clustering UI page to add new peers, then apply the changes under the MC setup UI.

D.

Each new indexer needs to be added using the distributed search UI, then settings must be saved under the MC setup UI.

Questions 10

When using SAML, where does user authentication occur?

Options:
A.

Splunk generates a SAML assertion that authenticates the user.

B.

The Service Provider (SP) decodes the SAML request and authenticates the user.

C.

The Identity Provider (IDP) decodes the SAML request and authenticates the user.

D.

The Service Provider (SP) generates a SAML assertion that authenticates the user.