Splunk Enterprise Architect (SPLK-2002) Certification Sample Questions
Getting knowledge of the Splunk SPLK-2002 exam structure and question format is vital in preparing for the Splunk Enterprise Certified Architect certification exam. Our Splunk Enterprise Architect sample questions offer you information regarding the question types and level of difficulty you will face in the real exam. The benefit of using these Splunk SPLK-2002 sample questions is that you will get to check your preparation level or enhance your knowledge by learning the unknown questions. You will also get a clear idea of the exam environment and exam pattern you will face in the actual exam with the Splunk Enterprise Certified Architect Sample Practice Test. Therefore, solve the Splunk Enterprise Architect sample questions to stay one step forward in grabbing the Splunk Enterprise Certified Architect credential.
These Splunk SPLK-2002 sample questions are simple and basic questions similar to the actual Splunk Enterprise Architect questions. If you want to evaluate your preparation level, we suggest taking our Splunk Enterprise Certified Architect Premium Practice Test. You might face difficulties while solving the real-exam-like questions. But, you can work hard and build your confidence on the syllabus topics through unlimited practice attempts.
Splunk SPLK-2002 Sample Questions:
a) Redistribute the scheduled searches that fire on the hour across the rest of the hour.
b) Add indexer peers so the searches on the hour have more indexing capacity to draw on.
c) Add a member to the search head cluster so more concurrent searches can run at once.
d) Raise the license pool allocation so the hourly volume stops restricting the searches.
02. After a maintenance window one peer in an indexer cluster receives no data from any forwarder. The peer is up, the manager node lists it as searchable, and it still serves searches over the buckets it already holds. Every other peer is receiving normally.
What is the most likely cause?
a) The license manager is unreachable from that peer, so the peer is refusing new data.
b) The manager node stopped routing incoming data to that peer while it caught up on replication.
c) A receiving input is not enabled on that peer, so no forwarder can establish a connection to it.
d) The forwarders' outputs.conf names a receiving port the indexing tier is not using.
03. Splunk Support has asked for the data needed to investigate repeated restarts on one indexer peer in a single-site cluster. The peer is still running and the rest of the cluster is healthy. Which action collects what Support needs from that peer?
a) Run splunk cmd btool --debug on the peer and send the resolved configuration.
b) Run splunk diag on the affected peer and send Support the archive it produces.
c) Take a diag from the manager node; it holds the cluster's configuration bundle.
d) Export the peer's recent _internal events from the Monitoring Console and send those.
04. An architect is sizing disk for an indexer cluster. The daily indexed volume and the retention period are both agreed, and a pilot has measured what one copy of a day's data occupies on disk once it is compressed and indexed. What remains to be applied to reach the cluster's storage requirement?
a) Nothing further, because the measured figure already covers the whole cluster.
b) The number of peers, since dividing the single-copy figure among them gives what each must provide.
c) The number of copies the cluster keeps, because each one occupies disk on some peer.
d) The license volume, since the license meters indexed data, and what may be indexed bounds what may be stored.
05. Licensed volume has risen month on month and the architect must say which source types account for it. Which internal source records the volume the license meter actually counted?
a) license_usage.log, which the license manager writes as it meters the indexed volume.
b) splunkd.log, which records the component-level errors each instance raises.
c) audit.log, which records administrative and search activity on the instance.
d) metrics.log, which reports per-source-type throughput through the indexing pipeline.
06. An architect is preparing a support case about an indexing problem on one peer and plans to attach a diag taken from that peer. What has to be supplied separately, because the archive does not carry it?
a) The configuration files from the affected instance, including indexes.conf.
b) The instance's recent splunkd.log and metrics.log history.
c) The bucket listing and index directory metadata for that peer.
d) The raw indexed events from the index exhibiting the problem.
07. A single-site indexer cluster is being converted to multisite across two data centers, and the architect has chosen the site replication and site search factors. Where do those factors and the site assignments belong?
a) The factors on each peer, so a site's copies can be tuned to that site's own hardware and network.
b) The factors on the manager node; each peer and search head declares its own site.
c) The factors in the manager's configuration bundle, which is what pushes them to the peers.
d) The factors in indexes.conf, per index, so each index can hold a different number.
08. Two data centers must each keep a complete searchable copy of all indexed data, so that either site can be lost without losing data or search coverage, and searches issued in a site should read that site's own copies wherever possible. Which statement about converting the indexer cluster to multisite is correct?
a) A separate license manager is required in each site once the cluster spans two sites.
b) Search head clustering is no longer needed, because each site now searches and stores its own copies.
c) Site-level factors place searchable copies in each site, and site affinity keeps searches local.
d) Total storage is unchanged, because the two sites share the copies the factors require.
09. Each new member of a search head cluster has to be told which cluster it belongs to and which port the members replicate over. Where do those settings end up?
a) inputs.conf on each member
b) server.conf on each member
c) shclustering.conf on each member
d) distsearch.conf on each member
10. One member of a search head cluster is about to be taken down for an operating-system patch, and that member is currently the captain. The work is planned, and the cluster is expected to keep coordinating searches throughout. What should be done before it is taken down?
a) Put the cluster into maintenance mode, as you would before patching an indexer peer.
b) Nothing; the remaining members elect a new captain once the member stops responding.
c) Transfer captaincy to the deployer, which already holds the cluster's configuration bundle.
d) Transfer captaincy to another member, so no election happens while one is leaving.
Answers:
|
Question: 01 Answer: a |
Question: 02 Answer: c |
Question: 03 Answer: b |
Question: 04 Answer: c |
Question: 05 Answer: a |
|
Question: 06 Answer: d |
Question: 07 Answer: b |
Question: 08 Answer: c |
Question: 09 Answer: b |
Question: 10 Answer: d |
Note: For any error in Splunk Enterprise Certified Architect (SPLK-2002) certification exam sample questions, please update us by writing an email on feedback@certfun.com.
- SPLK-2002 Questions |
- SPLK-2002 Quiz |
- SPLK-2002 |
- Splunk Enterprise Architect Certification |
- Splunk SPLK-2002 Question Bank |
- Enterprise Architect Mock Exam |
- Enterprise Architect |
- Enterprise Architect Sample Questions |
- Splunk SPLK-2002 Practice Test Free |
- Enterprise Architect Certification Sample Questions
