Skip to main content

SPLK-2002 Real Exam Questions

Splunk Enterprise Certified Architect

90 questions available · Page 1 of 9

Updated Exam DumpsVerified AnswersPass Guarantee

Get Complete Exam Dumps
Question 1 Single choice

Which Splunk Enterprise offering has its own license?

  1. A

    Splunk Cloud Forwarder

  2. B

    Splunk Heavy Forwarder

  3. C

    Splunk Universal Forwarder

  4. D

    Splunk Forwarder Management

Show answer and explanation

Correct answer: C

Explanation

References:
https://docs.splunk.com/Splexicon:Forwardinglicense

Question 2 Single choice

The frequency in which a deployment client contacts the deployment server is controlled by what?

  1. A

    polling_interval attribute in outputs.conf

  2. B

    phoneHomeIntervalInSecs attribute in outputs.conf

  3. C

    polling_interval attribute in deploymentclient.conf

  4. D

    phoneHomeIntervalInSecs attribute in deploymentclient.conf

Show answer and explanation

Correct answer: D

Explanation

References:
https://docs.splunk.com/Documentation/SplunkCloud/7.2.7/RESTREF/RESTdeploy

Question 3 Multiple choice

A Splunk instance has the following settings in SPLUNK_HOME/etc/system/local/server.conf:

[clustering]
mode = master
replication_factor = 2
pass4SymmKey = password123

Which of the following statements describe this Splunk instance? (Select all that apply.)

  1. A

    This is a multi-site cluster.

  2. B

    This cluster's search factor is 2.

  3. C

    This Splunk instance needs to be restarted.

  4. D

    This instance is missing the master_uri attribute.

Show answer and explanation

Correct answers: A, C

Question 4 Single choice

Which of the following can a Splunk diag contain?

  1. A

    Search history, Splunk users and their roles, running processes, indexed data

  2. B

    Server specs, current open connections, internal Splunk log files, index listings

  3. C

    KV store listings, internal Splunk log files, search peer bundles listings, indexed data

  4. D

    Splunk platform configuration details, Splunk users and their roles, current open connections, index listings

Show answer and explanation

Correct answer: B

Explanation

References:
https://splunkonbigdata.com/2018/10/01/splunk-diag/

Question 5 Single choice

Stakeholders have identified high availability for searchable data as their top priority.

Which of the following best addresses this requirement?

  1. A

    Increasing the search factor in the cluster.

  2. B

    Increasing the replication factor in the cluster.

  3. C

    Increasing the number of search heads in the cluster.

  4. D

    Increasing the number of CPUs on the indexers in the cluster.

Show answer and explanation

Correct answer: B

Explanation

References:
https://docs.splunk.com/Documentation/Splunk/7.3.2/DistSearch/SHCarchitecture

Question 6 Single choice

Before users can use a KV store, an admin must create a collection.

Where is a collection is defined?

  1. A

    kvstore.conf

  2. B

    collection.conf

  3. C

    collections.conf

  4. D

    kvcollections.conf

Show answer and explanation

Correct answer: C

Explanation

References:
https://docs.splunk.com/Documentation/Splunk/7.3.2/Knowledge/
DefineaKVStorelookupinSplunkWeb

Question 7 Single choice

What is a Splunk Job? (Select all that apply.)

  1. A

    A user-defined Splunk capability.

  2. B

    Searches that are subjected to some usage quota.

  3. C

    A search process kicked off via a report or an alert.

  4. D

    A child OS process manifested from the splunkd process.

Show answer and explanation

Correct answer: A

Question 8 Single choice

Which of the following is a way to exclude search artifacts when creating a diag?

  1. A

    SPLUNK_HOME/bin/splunk diag --exclude

  2. B

    SPLUNK_HOME/bin/splunk diag --debug --refresh

  3. C

    SPLUNK_HOME/bin/splunk diag --disable=dispatch

  4. D

    SPLUNK_HOME/bin/splunk diag --filter-searchstrings

Show answer and explanation

Correct answer: A

Explanation

References:
https://splunkonbigdata.com/2018/10/01/splunk-diag/

Question 9 Single choice

Which server.conf attribute should be added to the master node's server.conf file when decommissioning a site in an indexer cluster?

  1. A

    site_mappings

  2. B

    available_sites

  3. C

    site_search_factor

  4. D

    site_replication_factor

Show answer and explanation

Correct answer: A

Explanation

References:
https://docs.splunk.com/Documentation/Splunk/7.3.2/Indexer/Decommissionasite

Question 10 Single choice

When Splunk indexes data in a non clustered environment, what kind of files does it create by default?

  1. A

    Index and .tsidx files.

  2. B

    Rawdata and index files.

  3. C

    Compressed and .tsidx files.

  4. D

    Compressed and meta data files.

Show answer and explanation

Correct answer: B

Explanation

References:
https://docs.splunk.com/Documentation/Splunk/7.3.1/Indexer/Aboutindexesandindexers