SPLK-2002(205Q) Exam Questions
202 real SPLK-2002(205Q) exam questions with expert-verified answers and explanations. Page 2 of 5.
- Question #52Search Head Clustering
In search head clustering, which of the following methods can you use to transfer captaincy to a different member? (Select all that apply.)
SHC captaincy transfersearch head clusteringCLI commandsSplunk Web - Question #53Index Management
Which command is used for thawing the archive bucket?
archive bucketthawingsplunk rebuildbucket management - Question #54Indexer Clustering
A Splunk instance has the following settings in SPLUNK_HOME/etc/system/local/server.conf: [clustering] mode = master replication_factor = 2 pass4SymmKey = password123 Which of the...
server.confclustering configurationreplication factormaster node - Question #55Multisite Clustering
Which of the following describe migration from single-site to multisite index replication?
multisite replicationsingle-site migrationbucket policiesdata replication - Question #56Multisite Clustering
What does setting site=site0 on all Search Head Cluster members do in a multi-site indexer cluster?
multisite clusteringsearch site affinitysite0SHC configuration - Question #57Troubleshooting and Diagnostics
Which of the following is a way to exclude search artifacts when creating a diag?
diag commandsearch artifactstroubleshootingCLI options - Question #58Licensing
Which of the following statements describe licensing in a clustered Splunk deployment? (Select all that apply.)
clustering licenselicense masterreplicated datalicense pool - Question #59Deployment Planning
When planning a search head cluster, which of the following is true?
SHC planningindexer clusteroperating system requirementsstandalone indexers - Question #60Data Pipeline
In which phase of the Splunk Enterprise data pipeline are indexed extraction configurations processed?
data pipelineindexed extractionindexing phaseparsing - Question #61Multisite Clustering
Which server.conf attribute should be added to the master node's server.conf file when decommissioning a site in an indexer cluster?
site decommissionserver.confmultisite clusteringsite_mappings - Question #62Troubleshooting Splunk Components
Which tool(s) can be leveraged to diagnose connection problems between an indexer and forwarder? (Select all that apply.)
forwarder-indexer connectivitynetwork troubleshootingtcpdumptelnet - Question #63Indexer Clustering
A search head has successfully joined a single site indexer cluster. Which command is used to configure the same search head to join another indexer cluster?
indexer clustersearch head configurationCLI commandscluster-master - Question #64Splunk Performance Optimization
To improve Splunk performance, parallelIngestionPipelines setting can be adjusted on which of the following components in the Splunk architecture? (Select all that apply.)
parallelIngestionPipelinesindexing performancepipeline tuningcomponent configuration - Question #66Troubleshooting Splunk Components
When troubleshooting monitor inputs, which command checks the status of the tailed files?
monitor inputstailing processorfile statusREST API - Question #67Splunk Performance Optimization
Which of the following is a best practice to maximize indexing performance?
indexing performancesource typingconfiguration optimizationbest practices - Question #68Splunk Performance Optimization
When should multiple search pipelines be enabled?
search pipelinesparallelismCPU utilizationperformance tuning - Question #69Splunk Indexing Architecture
Of the following types of files within an index bucket, which file type may consume the most disk?
index bucketrawdatabloom filterdisk storage - Question #70Indexer Clustering
When converting from a single-site to a multi-site cluster, what happens to existing single-site clustered buckets?
multi-site clusteringbucket replicationsite migrationaging policies - Question #71Splunk App Management
Which of the following should be done when installing Enterprise Security on a Search Head Cluster? (Select all that apply.)
Enterprise SecuritySearch Head Clusterdeployerapp installation - Question #72Splunk Configuration Management
Splunk configuration parameter settings can differ between multiple .conf files of the same name contained within different apps. Which of the following directories has the highest...
configuration precedence.conf filessystem local directoryapp directories - Question #73Indexer Clustering
Which of the following is an indexer clustering requirement?
indexer clusteringlicense poolcluster requirementsshared storage - Question #74Search Head Clustering
What is the algorithm used to determine captaincy in a Splunk search head cluster?
Search Head ClusterRaft consensuscaptain electiondistributed consensus - Question #75Splunk Integration
Which of the following statements about integrating with third-party systems is true? (Select all that apply.)
third-party integrationHadoopdata forwardingalert actions - Question #76Splunk License Management
As a best practice, where should the internal licensing logs be stored?
licensinginternal logslicense serverbest practices - Question #77Splunk Performance Optimization
How does the average run time of all searches relate to the available CPU cores on the indexers?
search performanceCPU coresindexer resourcesrun time - Question #78Distributed Search
In a distributed environment, knowledge object bundles are replicated from the search head to which location on the search peer(s)?
knowledge object bundlessearch peer replicationdistributed searchfile paths - Question #79Splunk App Management
Consider a use case involving firewall data. There is no Splunk-supported Technical Add-On, but the vendor has built one. What are the items that must be evaluated before installin...
Technical Add-Onapp evaluationdata modelsforwarder compatibility - Question #80Indexer Clustering
When configuring a Splunk indexer cluster, what are the default values for replication and search factor?
indexer clusteringreplication factorsearch factordefault values - Question #81Splunk Knowledge Management
A Splunk user successfully extracted an ip address into a field called src_ip. Their colleague cannot see that field in their search results with events known to have src_ip. Which...
field extractionknowledge object permissionssearch modesFast Mode - Question #82Search Management and Optimization
Which two sections can be expanded using the Search Job Inspector?
Search Job Inspectorsearch job propertiesexecution costsSplunk UI - Question #83Splunk Monitoring and Troubleshooting
What is the default log size for Splunk internal logs?
internal logslog sizesplunk.logSplunk configuration - Question #84Search Architecture
What is a Splunk Job? (Select all that apply.)
Splunk jobssplunkd processsearch executionOS process - Question #85Splunk Architecture and Installation
When Splunk is installed, where are the internal indexes stored by default?
internal indexesSPLUNK_HOMEdirectory structuredefault paths - Question #86Data Collection and Inputs
Which of the following options can improve reliability of syslog delivery to Splunk? (Select all that apply.)
syslog deliveryTCP vs UDPUniversal Forwarderdata inputs - Question #87Deployment Planning
What is the logical first step when starting a deployment plan?
deployment planningrequirements gatheringstakeholdersdeployment strategy - Question #88Search Head Clustering
Which of the following statements describe search head clustering? (Select all that apply.)
search head clusteringdeployerSHC requirementshigh availability - Question #89Deployment Planning
Which of the following tasks should the architect perform when building a deployment plan? (Select all that apply.)
deployment planninguse case checklistdata source inventorynetwork topology - Question #90Capacity Planning and Hardware Sizing
Because Splunk indexing is read/write intensive, it is important to select the appropriate disk storage solution for each deployment. Which of the following statements is accurate...
disk storageRAID 10SANindexer storage - Question #91Monitoring and Troubleshooting
Which of the following are possible causes of a crash in Splunk? (select all that apply)
crash causesulimit settingsdisk IOPSdisk space - Question #92Capacity Planning
Which of the following strongly impacts storage sizing requirements for Enterprise Security?
Enterprise SecurityData Model accelerationstorage sizingcapacity planning - Question #93Indexer Clustering
Which of the following is true regarding the migration of an index cluster from single-site to multi- site?
indexer clusteringmulti-site migrationsingle-site to multi-sitecluster configuration - Question #94Monitoring and Troubleshooting
What information is written to the __introspection log file?
introspection logKV store performanceinternal logging__introspection - Question #95Indexer Clustering
A customer has a four site indexer cluster. The customer has requirements to store five copies of searchable data, with one searchable copy of data at the origin site, and one sear...
multi-site clusteringsite_replication_factorsite_search_factordisaster recovery - Question #96Indexer Clustering
Which of the following server. conf stanzas indicates the Indexer Discovery feature has not been fully configured (restart pending) on the Master Node? A) B) C) D)
Indexer Discoveryserver.confMaster Nodeconfiguration stanzas - Question #97Deployment Server Management
A customer currently has many deployment clients being managed by a single, dedicated deployment server. The customer plans to double the number of clients. What could be done to m...
deployment serverphone home intervaldeployment clientsperformance tuning - Question #98Monitoring and Troubleshooting
Following Splunk recommendations, where could the Monitoring Console (MC) be installed in a distributed deployment with an indexer cluster, a search head cluster, and 1000 forwarde...
Monitoring Consoledistributed deploymentdeployersearch head cluster - Question #99Monitoring and Troubleshooting
A Splunk instance has crashed, but no crash log was generated. There is an attempt to determine what user activity caused the crash by running the following search: What does searc...
crash analysisclosed_txnaudit loggingsplunkd transactions - Question #100Indexer Clustering
The master node distributes configuration bundles to peer nodes. Which directory peer nodes receive the bundles?
indexer clusterslave-appsconfiguration bundlespeer nodes - Question #101Splunk Internal Logging and Monitoring
metrics. log is stored in which index?
metrics.log_internal indexinternal loggingSplunk monitoring - Question #102Indexer Cluster Management
A single-site indexer cluster has a replication factor of 3, and a search factor of 2. What is true about
replication factorsearch factorindexer clusteringbucket copies