SPLK-2002(205Q) Exam Questions
202 real SPLK-2002(205Q) exam questions with expert-verified answers and explanations. Page 3 of 5.
- Question #103
Which of the following configuration attributes must be set in server, conf on the cluster manager in a single-site indexer cluster?
- Question #104
An index has large text log entries with many unique terms in the raw data. Other than the raw data, which index components will take the most space?
- Question #105
A search head cluster with a KV store collection can be updated from where in the KV store collection?
- Question #106
Which of the following items are important sizing parameters when architecting a Splunk environment? (select all that apply)
- Question #107
If there is a deployment server with many clients and one deployment client is not updating apps, which of the following should be done first?
- Question #109
When should a Universal Forwarder be used instead of a Heavy Forwarder?
- Question #110
Which of the following most improves KV Store resiliency?
- Question #111
Which of the following Splunk deployments has the recommended minimum components for a high- availability search head cluster?
- Question #112
What is needed to ensure that high-velocity sources will not have forwarding delays to the indexers?
- Question #113
Users who receive a link to a search are receiving an "Unknown sid" error message when they open the link. Why is this happening?
- Question #114
Why should intermediate forwarders be avoided when possible?
- Question #115
A Splunk deployment is being architected and the customer will be using Splunk Enterprise Security (ES) and Splunk IT Service Intelligence (ITSI). Through data onboarding and sizin...
- Question #116
How can internal logging levels in a Splunk environment be changed to troubleshoot an issue? (select all that apply)
- Question #117
Other than high availability, which of the following is a benefit of search head clustering?
- Question #118
By default, what happens to configurations in the local folder of each Splunk app when it is deployed to a search head cluster?
- Question #119
A Splunk environment collecting 10 TB of data per day has 50 indexers and 5 search heads. A single- site indexer cluster will be implemented. Which of the following is a best pract...
- Question #120
Which Splunk log file would be the least helpful in troubleshooting a crash?
- Question #121
Which of the following use cases would be made possible by multi-site clustering? (select all that apply)
- Question #122
Which of the following would be the least helpful in troubleshooting contents of Splunk configuration files?
- Question #123
What is the expected minimum amount of storage required for data across an indexer cluster with the following input and parameters? - Raw data = 15 GB per day - Index files = 35 GB...
- Question #124
A monitored log file is changing on the forwarder. However, Splunk searches are not finding any new data that has been added. What are possible causes? (select all that apply)
- Question #125
Which of the following is a problem that could be investigated using the Search Job Inspector?
- Question #126
When troubleshooting a situation where some files within a directory are not being indexed, the ignored files are discovered to have long headers. What is the first thing that shou...
- Question #127
In an indexer cluster, what tasks does the cluster manager perform? (select all that apply)
- Question #128
New data has been added to a monitor input file. However, searches only show older data. Which splunkd. log channel would help troubleshoot this issue?
- Question #129
Determining data capacity for an index is a non-trivial exercise. Which of the following are possible considerations that would affect daily indexing volume? (select all that apply...
- Question #130
Splunk Enterprise performs a cyclic redundancy check (CRC) against the first and last bytes to prevent the same file from being re-indexed if it is rotated or renamed. What is the...
- Question #131
Users are asking the Splunk administrator to thaw recently-frozen buckets very frequently. What could the Splunk administrator do to reduce the need to thaw buckets?
- Question #132
When should a dedicated deployment server be used?
- Question #133
Which Splunk internal field can confirm duplicate event issues from failed file monitoring?
- Question #134
What information is needed about the current environment before deploying Splunk? (select all that apply)
- Question #135
Which of the following options in limits, conf may provide performance benefits at the forwarding tier?
- Question #136
How many cluster managers are required for a multisite indexer cluster?
- Question #137
On search head cluster members, where in $splunk_home does the Splunk Deployer deploy app content by default?
- Question #138
Several critical searches that were functioning correctly yesterday are not finding a lookup table today. Which log file would be the best place to start troubleshooting?
- Question #139
Which of the following is a valid use case that a search head cluster addresses?
- Question #140
When using ingest-based licensing, what Splunk role requires the license manager to scale?
- Question #141
Which part of the deployment plan is vital prior to installing Splunk indexer clusters and search head clusters?
- Question #142
Data for which of the following indexes will count against an ingest-based license?
- Question #143
An indexer cluster is being designed with the following characteristics: - 10 search peers - Replication Factor (RF): 4 - Search Factor (SF): 3 - No SmartStore usage How many searc...
- Question #144
A customer is migrating 500 Universal Forwarders from an old deployment server to a new deployment server, with a different DNS name. The new deployment server is configured and ru...
- Question #145
What types of files exist in a bucket within a clustered index? (select all that apply)
- Question #146
When designing the number and size of indexes, which of the following considerations should be applied?
- Question #147
Which Splunk component is mandatory when implementing a search head cluster?
- Question #148
When implementing KV Store Collections in a search head cluster, which of the following considerations is true?
- Question #149
Which of the following is true for indexer cluster knowledge bundles?
- Question #150
When preparing to ingest a new data source, which of the following is optional in the data source assessment?
- Question #151
Where in the Job Inspector can details be found to help determine where performance is affected?
- Question #152
Which command should be run to re-sync a stale KV Store member in a search head cluster?
- Question #153
What is the best method for sizing or scaling a search head cluster?