Splunk SPLK-2002 Practice Test - Questions Answers, Page 10
List of questions
Related questions
Which of the following statements describe search head clustering? (Select all that apply.)
A deployer is required.
At least three search heads are needed.
Search heads must meet the high-performance reference server requirements.
The deployer must have sufficient CPU and network resources to process service requests and push configurations.
Which of the following tasks should the architect perform when building a deployment plan? (Select all that apply.)
Use case checklist.
Install Splunk apps.
Inventory data sources.
Review network topology.
Because Splunk indexing is read/write intensive, it is important to select the appropriate disk storage solution for each deployment. Which of the following statements is accurate about disk storage?
High performance SAN should never be used.
Enable NFS for storing hot and warm buckets.
The recommended RAID setup is RAID 10 (1 + 0).
Virtualized environments are usually preferred over bare metal for Splunk indexers.
Which of the following are possible causes of a crash in Splunk? (select all that apply)
Incorrect ulimit settings.
Insufficient disk IOPS.
Insufficient memory.
Running out of disk space.
Which of the following strongly impacts storage sizing requirements for Enterprise Security?
The number of scheduled (correlation) searches.
The number of Splunk users configured.
The number of source types used in the environment.
The number of Data Models accelerated.
Which of the following is true regarding the migration of an index cluster from single-site to multi-site?
Multi-site policies will apply to all data in the indexer cluster.
All peer nodes must be running the same version of Splunk.
Existing single-site attributes must be removed.
Single-site buckets cannot be converted to multi-site buckets.
What information is written to the __introspection log file?
File monitor input configurations.
File monitor checkpoint offset.
User activities and knowledge objects.
KV store performance.
A customer has a four site indexer cluster. The customer has requirements to store five copies of searchable data, with one searchable copy of data at the origin site, and one searchable copy at the disaster recovery site (site4).
Which configuration meets these requirements?
site_replication_factor = origin:2, site4:l, total:3
site_replication_factor = origin:l, site4:l, total:5
site_search_factor = origin:2, site4:l, total:3
site search factor = origin:1, site4:l, total:5
Which of the following server. conf stanzas indicates the Indexer Discovery feature has not been fully configured (restart pending) on the Master Node?
A)
B)
C)
D)
Option A
Option B
Option C
Option D
A customer currently has many deployment clients being managed by a single, dedicated deployment server. The customer plans to double the number of clients.
What could be done to minimize performance issues?
Modify deploymentclient. conf to change from a Pull to Push mechanism.
Reduce the number of apps in the Manager Node repository.
Increase the current deployment client phone home interval.
Decrease the current deployment client phone home interval.
Question