Splunk SPLK-2002 Practice Test - Questions Answers, Page 8
List of questions
Related questions
When should multiple search pipelines be enabled?
Only if disk IOPS is at 800 or better.
Only if there are fewer than twelve concurrent users.
Only if running Splunk Enterprise version 6.6 or later.
Only if CPU and memory resources are significantly under-utilized.
Of the following types of files within an index bucket, which file type may consume the most disk?
Rawdata
Bloom filter
Metadata (.data)
Inverted index (.tsidx)
When converting from a single-site to a multi-site cluster, what happens to existing single-site clustered buckets?
They will continue to replicate within the origin site and age out based on existing policies.
They will maintain replication as required according to the single-site policies, but never age out.
They will be replicated across all peers in the multi-site cluster and age out based on existing policies.
They will stop replicating within the single-site and remain on the indexer they reside on and age out according to existing policies.
Which of the following should be done when installing Enterprise Security on a Search Head Cluster? (Select all that apply.)
Install Enterprise Security on the deployer.
Install Enterprise Security on a staging instance.
Copy the Enterprise Security configurations to the deployer.
Use the deployer to deploy Enterprise Security to the cluster members.
Splunk configuration parameter settings can differ between multiple .conf files of the same name contained within different apps. Which of the following directories has the highest precedence?
System local directory.
System default directory.
App local directories, in ASCII order.
App default directories, in ASCII order.
Which of the following is an indexer clustering requirement?
Must use shared storage.
Must reside on a dedicated rack.
Must have at least three members.
Must share the same license pool.
What is the algorithm used to determine captaincy in a Splunk search head cluster?
Raft distributed consensus.
Rapt distributed consensus.
Rift distributed consensus.
Round-robin distribution consensus.
Which of the following statements about integrating with third-party systems is true? (Select all that apply.)
A Hadoop application can search data in Splunk.
Splunk can search data in the Hadoop File System (HDFS).
You can use Splunk alerts to provision actions on a third-party system.
You can forward data from Splunk forwarder to a third-party system without indexing it first.
As a best practice, where should the internal licensing logs be stored?
Indexing layer.
License server.
Deployment layer.
Search head layer.
How does the average run time of all searches relate to the available CPU cores on the indexers?
Average run time is independent of the number of CPU cores on the indexers.
Average run time decreases as the number of CPU cores on the indexers decreases.
Average run time increases as the number of CPU cores on the indexers decreases.
Average run time increases as the number of CPU cores on the indexers increases.
Question