PrepAway - Latest Free Exam Questions & Answers

Category: Splunk SPLK-2002

Exam Splunk SPLK-2002: Splunk Enterprise Certified Architect

Which of the following is true regarding Splunk Enterprise performance?

Which of the following is true regarding Splunk Enterprise performance? (Select all that apply.) A. Adding search peers increases the maximum size of search results. B. Adding RAM to an existing search heads provides additional search capacity. C. Adding search peers increases the search throughput as search load increases. D. Adding search heads provides additional […]

In a four site indexer cluster, which configuration stores two searchable copies at the origin site, one searc

In a four site indexer cluster, which configuration stores two searchable copies at the origin site, one searchable copy at site2, and a total of four searchable copies? A. site_search_factor = origin:2, site1:2, total:4 B. site_search_factor = origin:2, site2:1, total:4 C. site_replication_factor = origin:2, site1:2, total:4 D. site_replication_factor = origin:2, site2:1, total:4 Reference: https://docs.splunk.com/Documentation/Splunk/7.3.2/Indexer/Sitereplicationfactor

What log file would you search to verify if you suspect there is a problem interpreting a regular expression i

What log file would you search to verify if you suspect there is a problem interpreting a regular expression in a monitor stanza? A. btool.log B. metrics.log C. splunkd.log D. tailing_processor.log Reference: https://answers.splunk.com/answers/479312/how-to-edit-inputsconf-to-monitor-multiple-files-w-1.html

A multi-site indexer cluster can be configured using which of the following?

A multi-site indexer cluster can be configured using which of the following? (Select all that apply.) A. Via Splunk Web. B. Directly edit SPLUNK_HOME/etc/system/local/server.conf C. Run a splunk edit cluster-config command from the CLI. D. Directly edit SPLUNK_HOME/etc/system/default/server.conf Reference: https://docs.splunk.com/Documentation/Splunk/7.3.2/Indexer/Enableclustersindetail

Which of the following should be included in a deployment plan?

Which of the following should be included in a deployment plan? A. Business continuity and disaster recovery plans. B. Current logging details and data source inventory. C. Current and future topology diagrams of the IT environment. D. A comprehensive list of stakeholders, either direct or indirect. Reference: https://docs.splunk.com/Documentation/CoE/ssf/Handbook/StakeholderReg


Page 1 of 212