SPLK-2002(205Q) Exam Questions
202 real SPLK-2002(205Q) exam questions with expert-verified answers and explanations. Page 4 of 5.
- Question #154Search Head Cluster Management
Where does the Splunk deployer send apps by default?
deployershcluster directoryapp deploymentsearch head cluster - Question #155Indexer Cluster Management
If .delta replication fails during knowledge bundle replication, what is the fall-back method for Splunk?
knowledge bundle replicationdelta replicationbundle replicationindexer cluster - Question #156Monitoring and Troubleshooting
In splunkd. log events written to the _internal index, which field identifies the specific log channel?
splunkd.log_internal indexlog channel fieldmonitoring - Question #157Data Onboarding
Which props.conf setting has the least impact on indexing performance?
props.confindexing performanceCHARSETdata parsing settings - Question #158Distributed Deployment Configuration
A search head cluster member contains the following in its server .conf. What is the Splunk server name of this member?
server.confserverNamesearch head clusterserver configuration - Question #159Monitoring and Troubleshooting
As of Splunk 9.0, which index records changes to . conf files?
_configtracker indexconf file changesSplunk 9.0internal indexes - Question #160Search Head Cluster Management
Which instance can not share functionality with the deployer?
deployercomponent coexistencesearch head clusterlicense master - Question #161Splunk Security
(A customer has a Splunk Enterprise deployment and wants to collect data from universal forwarders. What is the best step to secure log traffic?)
SSL certificatesdata encryptionuniversal forwardernetwork security - Question #162License Management
(Which btool command will identify license master configuration errors for a search peer cluster node?)
btoollicense mastercluster configurationCLI commands - Question #163Search Management
(The performance of a specific search is performing poorly. The search must run over All Time and is expected to have very few results. Analysis shows that the search accesses a ve...
search performancedisk I/Obucket accessindex optimization - Question #164Clustering
(Which command is used to initially add a search head to a single-site indexer cluster?)
search headindexer clusterCLI commandscluster configuration - Question #165Architect Planning and Design
(A customer wishes to keep costs to a minimum, while still implementing Search Head Clustering (SHC). What are the minimum supported architecture standards?)
Search Head ClusteringSHC deployerminimum architecturehigh availability - Question #166Search Management
(What is a recommended way to improve search performance?)
search optimizationstreaming commandssearch best practicesfiltering - Question #167Architect Planning and Design
(Which of the following is a minimum search head specification for a distributed Splunk environment?)
search headhardware requirementsCPU specificationsdistributed environment - Question #168Data Management
(A high-volume source and a low-volume source feed into the same index. Which of the following items best describe the impact of this design choice?)
index designvolume-based retentiondata agingindex co-mingling - Question #169License Management
(If a license peer cannot communicate to a license manager for 72 hours or more, what will happen?)
license peerlicense violationcommunication failuresearch blocking - Question #170Clustering
(Which deployer push mode should be used when pushing built-in apps?)
SHC deployerpush modebuilt-in appsapp deployment - Question #171Data Management
(A customer has converted a CSV lookup to a KV Store lookup. What must be done to make it available for an automatic lookup?)
KV Storeautomatic lookupcollections.conflookup replication - Question #172Monitoring and Troubleshooting
(Which of the following data sources are used for the Monitoring Console dashboards?)
Monitoring ConsoleREST APIdashboard data sourcesmetrics.log - Question #173Architect Planning and Design
(Based on the data sizing and retention parameters listed below, which of the following will correctly calculate the index storage required?) - Daily rate = 20 GB / day - Compress...
capacity planningindex storage calculationcompression factordata sizing - Question #174Monitoring and Troubleshooting
(A customer creates a saved search that runs on a specific interval. Which internal Splunk log should be viewed to determine if the search ran recently?)
scheduler.logsaved searchesinternal logssearch scheduling - Question #175Architect Planning and Design
(Which of the following must be included in a deployment plan?)
deployment planningdata source inventoryrequirements gatheringarchitecture planning - Question #176Deploy Splunk Enterprise
(Which index does Splunk use to record user activities?)
_audit indexuser activity logginginternal indexesaudit trail - Question #177Data Management
(If the maxDataSize attribute is set to auto_high_volume in indexes.conf on a 64-bit operating system, what is the maximum hot bucket size?)
indexes.confhot bucket sizemaxDataSizeauto_high_volume - Question #178SmartStore
(Which of the following is a benefit of using SmartStore?)
SmartStorestorage and compute separationremote storageobject storage - Question #179Deploy Splunk Enterprise
(A new Splunk Enterprise deployment is being architected, and the customer wants to ensure that the data to be indexed is encrypted. Where should TLS be turned on in the Splunk dep...
TLS encryptiondata in transitforwarder to indexernetwork security - Question #180Monitoring and Troubleshooting
(When determining where a Splunk forwarder is trying to send data, which of the following searches can provide assistance?)
forwarder troubleshooting_internal indexdestHostsplunkd metrics - Question #181Clustering
(What command will decommission a search peer from an indexer cluster?)
cluster peer decommissionsplunk offlineindexer clusterCLI commands - Question #182Troubleshooting Splunk
(Which Splunk component allows viewing of the LISPY to assist in debugging Splunk searches?)
walklexLISPYsearch debuggingSplunk components - Question #183Splunk Enterprise Architecture
(On which Splunk components does the Splunk App for Enterprise Security place the most load?)
Enterprise SecuritySearch Headscomponent loadSplunk architecture - Question #184Indexer Cluster Configuration
(What is the best way to configure and manage receiving ports for clustered indexers?)
indexer clusterreceiving portsinputs.confcluster manager - Question #185Search Head Cluster Administration
(Which of the following is not facilitated by the deployer?)
deployersearch head clusterknowledge objectsapp deployment - Question #186Indexer Cluster Administration
(Which of the following is a valid way to determine if a new bundle push will trigger a rolling restart?)
cluster bundlerolling restartCLI commandsindexer cluster - Question #187Search Head Cluster Troubleshooting
(An admin removed and re-added search head cluster (SHC) members as part of patching the operating system. When trying to re-add the first member, a script reverted the SHC member...
SHC troubleshootingRaft metadatacluster recoverysearch head cluster - Question #188Search Optimization and Troubleshooting
(How can a Splunk admin control the logging level for a specific search to get further debug information?)
noop commandsearch loggingdebug levelsearch troubleshooting - Question #189Indexer Cluster Configuration
(What are the possible values for the mode attribute in server.conf for a Splunk server in the [clustering] stanza?)
server.confclustering stanzacluster modesconfiguration - Question #190Splunk Performance Tuning
(Which of the following has no impact on search performance?)
search performancedeployment clientphone home intervalperformance factors - Question #191Indexer Cluster Configuration
(Which indexes.conf attribute would prevent an index from participating in an indexer cluster?)
indexes.confrepFactorreplicationindexer cluster - Question #192Deployment Server Administration
(It is possible to lose UI edit functionality after manually editing which of the following files in the deployment server?)
serverclass.confdeployment serverUI managementconfiguration files - Question #193User and Role Management
(When planning user management for a new Splunk deployment, which task can be disregarded?)
user managementauthentication planningLDAPSAML - Question #194Capacity Planning and Architecture
(What is the expected performance reduction when architecting Splunk in a virtualized environment instead of a physical environment?)
virtualizationperformance benchmarkscapacity planninginfrastructure - Question #195Indexer Cluster Administration
(Where can files be placed in a configuration bundle on a search peer that will persist after a new configuration bundle has been deployed?)
configuration bundleslave-apps_cluster directorypersistent config - Question #196Search Administration and Troubleshooting
(How is the search log accessed for a completed search job?)
search.logJob Inspectorsearch debuggingcompleted search job - Question #197License Management
(A customer has an environment with a Search Head Cluster and an indexer cluster. They are troubleshooting license usage data, including indexed volume in bytes per pool, index, ho...
license_usage.logLicense Managerlicense monitoringlog location - Question #198Splunk Deployment Planning
What is the recommended order of activities in the Splunk deployment process?
deployment processinfrastructure planningrollout orderbest practices - Question #199Multisite Cluster Configuration
A customer has a multisite cluster with site1 and site2 configured. They want to configure search heads in these sites to get search results only from data stored on their local si...
multisite clustersite affinitysite0search head configuration - Question #200Search Head Cluster High Availability
A customer has a Search Head Cluster (SHC) with site1 and site2. Site1 has five search heads and Site2 has four. Site1 search heads are preferred captains. What action should be ta...
SHC captain electionmultisite SHCquorumnetwork partition - Question #201Indexer Cluster Administration
Which Splunk cluster feature requires additional indexer storage?
index summarizationsummary indexesstorage overheadindexer cluster - Question #202Forwarder Management and Deployment Server
A customer plans to have 20,000 Splunk-managed forwarders. What is a common step to ensure Splunk forwarder management performance is not impacted?
Deployment Serverserver classesforwarder managementscalability - Question #203Indexer Cluster Architecture and Resiliency
Buttercup Games has a multi-site indexer cluster. Site 1, which hosts the Cluster Manager, experiences a DNS failure. Site 2 is unable to reach Site 1. What happens to searching at...
multi-site indexer clustercluster manager failuresite resiliencyhigh availability