Black Friday Sale - Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 65percent

Welcome To DumpsPedia

SPLK-2002 Sample Questions Answers

Questions 4

Data for which of the following indexes will count against an ingest-based license?

Options:

A.

summary

B.

main

C.

_metrics

D.

_introspection

Buy Now
Questions 5

What information is needed about the current environment before deploying Splunk? (select all that apply)

Options:

A.

List of vendors for network devices.

B.

Overall goals for the deployment.

C.

Key users.

D.

Data sources.

Buy Now
Questions 6

In which phase of the Splunk Enterprise data pipeline are indexed extraction configurations processed?

Options:

A.

Input

B.

Search

C.

Parsing

D.

Indexing

Buy Now
Questions 7

What is the best method for sizing or scaling a search head cluster?

Options:

A.

Estimate the maximum daily ingest volume in gigabytes and divide by the number of CPU cores per search head.

B.

Estimate the total number of searches per day and divide by the number of CPU cores available on the search heads.

C.

Divide the number of indexers by three to achieve the correct number of search heads.

D.

Estimate the maximum concurrent number of searches and divide by the number of CPU cores per search head.

Buy Now
Questions 8

(A customer has converted a CSV lookup to a KV Store lookup. What must be done to make it available for an automatic lookup?)

Options:

A.

Add the repFactor=true attribute in collections.conf.

B.

Add the replicate=true attribute in lookups.conf.

C.

Add the replicate=true attribute in collections.conf.

D.

Add the repFactor=true attribute in lookups.conf.

Buy Now
Questions 9

To expand the search head cluster by adding a new member, node2, what first step is required?

Options:

A.

splunk bootstrap shcluster-config -mgmt_uri https://node2:8089 -replication_port 9200 -secret supersecretkey

B.

splunk init shcluster-config -master_uri https://node2:8089 -replication_port 9200 -secret supersecretkey

C.

splunk init shcluster-config -mgmt_uri https://node2:8089 -replication_port 9200 -secret supersecretkey

D.

splunk add shcluster-member -new_member_uri https://node2:8089 -replication_port 9200 -secret supersecretkey

Buy Now
Questions 10

(How is the search log accessed for a completed search job?)

Options:

A.

Search for: index=_internal sourcetype=search.

B.

Select Settings > Searches, reports, and alerts, then from the Actions column, select View Search Log.

C.

From the Activity menu, select Show Search Log.

D.

From the Job menu, select Inspect Job, then click the search.log link.

Buy Now
Questions 11

Which two sections can be expanded using the Search Job Inspector?

Options:

A.

Execution costs.

B.

Saved search history.

C.

Search job properties.

D.

Optimization suggestions.

Buy Now
Questions 12

Which of the following use cases would be made possible by multi-site clustering? (select all that apply)

Options:

A.

Use blockchain technology to audit search activity from geographically dispersed data centers.

B.

Enable a forwarder to send data to multiple indexers.

C.

Greatly reduce WAN traffic by preferentially searching assigned site (search affinity).

D.

Seamlessly route searches to a redundant site in case of a site failure.

Buy Now
Questions 13

A three-node search head cluster is skipping a large number of searches across time. What should be done to increase scheduled search capacity on the search head cluster?

Options:

A.

Create a job server on the cluster.

B.

Add another search head to the cluster.

C.

server.conf captain_is_adhoc_searchhead = true.

D.

Change limits.conf value for max_searches_per_cpu to a higher value.

Buy Now
Questions 14

Which CLI command converts a Splunk instance to a license slave?

Options:

A.

splunk add licenses

B.

splunk list licenser-slaves

C.

splunk edit licenser-localslave

D.

splunk list licenser-localslave

Buy Now
Questions 15

(Which of the following is a minimum search head specification for a distributed Splunk environment?)

Options:

A.

A 1Gb Ethernet NIC, optional 2nd NIC for a management network.

B.

An x86 32-bit chip architecture.

C.

128 GB RAM.

D.

Two physical CPU cores, or four vCPU at 2GHz or greater speed per core.

Buy Now
Questions 16

Which instance can not share functionality with the deployer?

Options:

A.

Search head cluster member

B.

License master

C.

Master node

D.

Monitoring Console (MC)

Buy Now
Questions 17

Which Splunk server role regulates the functioning of indexer cluster?

Options:

A.

Indexer

B.

Deployer

C.

Master Node

D.

Monitoring Console

Buy Now
Questions 18

(Where can files be placed in a configuration bundle on a search peer that will persist after a new configuration bundle has been deployed?)

Options:

A.

In the $SPLUNK_HOME/etc/slave-apps//local folder.

B.

In the $SPLUNK_HOME/etc/master-apps//local folder.

C.

Nowhere; the entire configuration bundle is overwritten with each push.

D.

In the $SPLUNK_HOME/etc/slave-apps/_cluster/local folder.

Buy Now
Questions 19

Which of the following statements describe search head clustering? (Select all that apply.)

Options:

A.

A deployer is required.

B.

At least three search heads are needed.

C.

Search heads must meet the high-performance reference server requirements.

D.

The deployer must have sufficient CPU and network resources to process service requests and push configurations.

Buy Now
Questions 20

Why should intermediate forwarders be avoided when possible?

Options:

A.

To minimize license usage and cost.

B.

To decrease mean time between failures.

C.

Because intermediate forwarders cannot be managed by a deployment server.

D.

To eliminate potential performance bottlenecks.

Buy Now
Questions 21

Where in the Job Inspector can details be found to help determine where performance is affected?

Options:

A.

Search Job Properties > runDuration

B.

Search Job Properties > runtime

C.

Job Details Dashboard > Total Events Matched

D.

Execution Costs > Components

Buy Now
Questions 22

When Splunk is installed, where are the internal indexes stored by default?

Options:

A.

SPLUNK_HOME/bin

B.

SPLUNK_HOME/var/lib

C.

SPLUNK_HOME/var/run

D.

SPLUNK_HOME/etc/system/default

Buy Now
Questions 23

What log file would you search to verify if you suspect there is a problem interpreting a regular expression in a monitor stanza?

Options:

A.

btool.log

B.

metrics.log

C.

splunkd.log

D.

tailing_processor.log

Buy Now
Questions 24

Configurations from the deployer are merged into which location on the search head cluster member?

Options:

A.

SPLUNK_HOME/etc/system/local

B.

SPLUNK_HOME/etc/apps/APP_HOME/local

C.

SPLUNK_HOME/etc/apps/search/default

D.

SPLUNK_HOME/etc/apps/APP_HOME/default

Buy Now
Questions 25

(If the maxDataSize attribute is set to auto_high_volume in indexes.conf on a 64-bit operating system, what is the maximum hot bucket size?)

Options:

A.

4 GB

B.

750 MB

C.

10 GB

D.

1 GB

Buy Now
Questions 26

Which of the following artifacts are included in a Splunk diag file? (Select all that apply.)

Options:

A.

OS settings.

B.

Internal logs.

C.

Customer data.

D.

Configuration files.

Buy Now
Questions 27

Which of the following strongly impacts storage sizing requirements for Enterprise Security?

Options:

A.

The number of scheduled (correlation) searches.

B.

The number of Splunk users configured.

C.

The number of source types used in the environment.

D.

The number of Data Models accelerated.

Buy Now
Questions 28

(A customer creates a saved search that runs on a specific interval. Which internal Splunk log should be viewed to determine if the search ran recently?)

Options:

A.

metrics.log

B.

kvstore.log

C.

scheduler.log

D.

btool.log

Buy Now
Questions 29

(Which deployer push mode should be used when pushing built-in apps?)

Options:

A.

merge_to_default

B.

local_only

C.

full

D.

default only

Buy Now
Questions 30

When using ingest-based licensing, what Splunk role requires the license manager to scale?

Options:

A.

Search peers

B.

Search heads

C.

There are no roles that require the license manager to scale

D.

Deployment clients

Buy Now
Questions 31

Which of the following is an indexer clustering requirement?

Options:

A.

Must use shared storage.

B.

Must reside on a dedicated rack.

C.

Must have at least three members.

D.

Must share the same license pool.

Buy Now
Questions 32

The frequency in which a deployment client contacts the deployment server is controlled by what?

Options:

A.

polling_interval attribute in outputs.conf

B.

phoneHomeIntervalInSecs attribute in outputs.conf

C.

polling_interval attribute in deploymentclient.conf

D.

phoneHomeIntervalInSecs attribute in deploymentclient.conf

Buy Now
Questions 33

Consider a use case involving firewall data. There is no Splunk-supported Technical Add-On, but the vendor has built one. What are the items that must be evaluated before installing the add-on? (Select all that apply.)

Options:

A.

Identify number of scheduled or real-time searches.

B.

Validate if this Technical Add-On enables event data for a data model.

C.

Identify the maximum number of forwarders Technical Add-On can support.

D.

Verify if Technical Add-On needs to be installed onto both a search head or indexer.

Buy Now
Questions 34

What does setting site=site0 on all Search Head Cluster members do in a multi-site indexer cluster?

Options:

A.

Disables search site affinity.

B.

Sets all members to dynamic captaincy.

C.

Enables multisite search artifact replication.

D.

Enables automatic search site affinity discovery.

Buy Now
Questions 35

(Which indexes.conf attribute would prevent an index from participating in an indexer cluster?)

Options:

A.

available_sites = none

B.

repFactor = 0

C.

repFactor = auto

D.

site_mappings = default_mapping

Buy Now
Questions 36

Which of the following are possible causes of a crash in Splunk? (select all that apply)

Options:

A.

Incorrect ulimit settings.

B.

Insufficient disk IOPS.

C.

Insufficient memory.

D.

Running out of disk space.

Buy Now
Questions 37

In search head clustering, which of the following methods can you use to transfer captaincy to a different member? (Select all that apply.)

Options:

A.

Use the Monitoring Console.

B.

Use the Search Head Clustering settings menu from Splunk Web on any member.

C.

Run the splunk transfer shcluster-captain command from the current captain.

D.

Run the splunk transfer shcluster-captain command from the member you would like to become the captain.

Buy Now
Questions 38

Stakeholders have identified high availability for searchable data as their top priority. Which of the following best addresses this requirement?

Options:

A.

Increasing the search factor in the cluster.

B.

Increasing the replication factor in the cluster.

C.

Increasing the number of search heads in the cluster.

D.

Increasing the number of CPUs on the indexers in the cluster.

Buy Now
Questions 39

Which Splunk log file would be the least helpful in troubleshooting a crash?

Options:

A.

splunk_instrumentation.log

B.

splunkd_stderr.log

C.

crash-2022-05-13-ll:42:57.1og

D.

splunkd.log

Buy Now
Questions 40

When adding or decommissioning a member from a Search Head Cluster (SHC), what is the proper order of operations?

Options:

A.

1. Delete Splunk Enterprise, if it exists.2. Install and initialize the instance.3. Join the SHC.

B.

1. Install and initialize the instance.2. Delete Splunk Enterprise, if it exists.3. Join the SHC.

C.

1. Initialize cluster rebalance operation.2. Remove master node from cluster.3. Trigger replication.

D.

1. Trigger replication.2. Remove master node from cluster.3. Initialize cluster rebalance operation.

Buy Now
Questions 41

(Which of the following data sources are used for the Monitoring Console dashboards?)

Options:

A.

REST API calls

B.

Splunk btool

C.

Splunk diag

D.

metrics.log

Buy Now
Questions 42

(Which of the following is a valid way to determine if a new bundle push will trigger a rolling restart?)

Options:

A.

splunk show cluster-bundle-status

B.

splunk apply cluster-bundle

C.

splunk validate cluster-bundle —check-restart

D.

splunk apply cluster-bundle —validate-bundle

Buy Now
Questions 43

What is the minimum reference server specification for a Splunk indexer?

Options:

A.

12 CPU cores, 12GB RAM, 800 IOPS

B.

16 CPU cores, 16GB RAM, 800 IOPS

C.

24 CPU cores, 16GB RAM, 1200 IOPS

D.

28 CPU cores, 32GB RAM, 1200 IOPS

Buy Now
Questions 44

(The performance of a specific search is performing poorly. The search must run over All Time and is expected to have very few results. Analysis shows that the search accesses a very large number of buckets in a large index. What step would most significantly improve the performance of this search?)

Options:

A.

Increase the disk I/O hardware performance.

B.

Increase the number of indexing pipelines.

C.

Set indexed_realtime_use_by_default = true in limits.conf.

D.

Change this to a real-time search using an All Time window.

Buy Now
Questions 45

Where does the Splunk deployer send apps by default?

Options:

A.

etc/slave-apps//default

B.

etc/deploy-apps//default

C.

etc/apps//default

D.

etc/shcluster//default

Buy Now
Questions 46

When should multiple search pipelines be enabled?

Options:

A.

Only if disk IOPS is at 800 or better.

B.

Only if there are fewer than twelve concurrent users.

C.

Only if running Splunk Enterprise version 6.6 or later.

D.

Only if CPU and memory resources are significantly under-utilized.

Buy Now
Questions 47

Which of the following statements describe licensing in a clustered Splunk deployment? (Select all that apply.)

Options:

A.

Free licenses do not support clustering.

B.

Replicated data does not count against licensing.

C.

Each cluster member requires its own clustering license.

D.

Cluster members must share the same license pool and license master.

Buy Now
Questions 48

When preparing to ingest a new data source, which of the following is optional in the data source assessment?

Options:

A.

Data format

B.

Data location

C.

Data volume

D.

Data retention

Buy Now
Questions 49

A customer currently has many deployment clients being managed by a single, dedicated deployment server. The customer plans to double the number of clients.

What could be done to minimize performance issues?

Options:

A.

Modify deploymentclient. conf to change from a Pull to Push mechanism.

B.

Reduce the number of apps in the Manager Node repository.

C.

Increase the current deployment client phone home interval.

D.

Decrease the current deployment client phone home interval.

Buy Now
Questions 50

A Splunk user successfully extracted an ip address into a field called src_ip. Their colleague cannot see that field in their search results with events known to have src_ip. Which of the following may explain the problem? (Select all that apply.)

Options:

A.

The field was extracted as a private knowledge object.

B.

The events are tagged as communicate, but are missing the network tag.

C.

The Typing Queue, which does regular expression replacements, is blocked.

D.

The colleague did not explicitly use the field in the search and the search was set to Fast Mode.

Buy Now
Questions 51

To optimize the distribution of primary buckets; when does primary rebalancing automatically occur? (Select all that apply.)

Options:

A.

Rolling restart completes.

B.

Master node rejoins the cluster.

C.

Captain joins or rejoins cluster.

D.

A peer node joins or rejoins the cluster.

Buy Now
Questions 52

(What is a recommended way to improve search performance?)

Options:

A.

Use the shortest query possible.

B.

Filter as much as possible in the initial search.

C.

Use non-streaming commands as early as possible.

D.

Leverage the not expression to limit returned results.

Buy Now
Questions 53

Which of the following is a good practice for a search head cluster deployer?

Options:

A.

The deployer only distributes configurations to search head cluster members when they “phone home”.

B.

The deployer must be used to distribute non-replicable configurations to search head cluster members.

C.

The deployer must distribute configurations to search head cluster members to be valid configurations.

D.

The deployer only distributes configurations to search head cluster members with splunk apply shcluster-bundle.

Buy Now
Questions 54

Which of the following is unsupported in a production environment?

Options:

A.

Cluster Manager can run on the Monitoring Console instance in smaller environments.

B.

Search Head Cluster Deployer can run on the Monitoring Console instance in smaller environments.

C.

Search heads in a Search Head Cluster can run on virtual machines.

D.

Indexers in an indexer cluster can run on virtual machines.

Buy Now
Questions 55

Because Splunk indexing is read/write intensive, it is important to select the appropriate disk storage solution for each deployment. Which of the following statements is accurate about disk storage?

Options:

A.

High performance SAN should never be used.

B.

Enable NFS for storing hot and warm buckets.

C.

The recommended RAID setup is RAID 10 (1 + 0).

D.

Virtualized environments are usually preferred over bare metal for Splunk indexers.

Buy Now
Questions 56

Users who receive a link to a search are receiving an "Unknown sid" error message when they open the link.

Why is this happening?

Options:

A.

The users have insufficient permissions.

B.

An add-on needs to be updated.

C.

The search job has expired.

D.

One or more indexers are down.

Buy Now
Questions 57

Which of the following will cause the greatest reduction in disk size requirements for a cluster of N indexers running Splunk Enterprise Security?

Options:

A.

Setting the cluster search factor to N-1.

B.

Increasing the number of buckets per index.

C.

Decreasing the data model acceleration range.

D.

Setting the cluster replication factor to N-1.

Buy Now
Questions 58

Which Splunk Enterprise offering has its own license?

Options:

A.

Splunk Cloud Forwarder

B.

Splunk Heavy Forwarder

C.

Splunk Universal Forwarder

D.

Splunk Forwarder Management

Buy Now
Questions 59

Which command should be run to re-sync a stale KV Store member in a search head cluster?

Options:

A.

splunk clean kvstore -local

B.

splunk resync kvstore -remote

C.

splunk resync kvstore -local

D.

splunk clean eventdata -local

Buy Now
Questions 60

What is the algorithm used to determine captaincy in a Splunk search head cluster?

Options:

A.

Raft distributed consensus.

B.

Rapt distributed consensus.

C.

Rift distributed consensus.

D.

Round-robin distribution consensus.

Buy Now
Exam Code: SPLK-2002
Exam Name: Splunk Enterprise Certified Architect
Last Update: Nov 30, 2025
Questions: 202
$57.75  $164.99
$43.75  $124.99
$36.75  $104.99
buy now SPLK-2002