Sign In
Home/Splunk/SPLK-2002/Free questions

SPLK-2002 — Free Practice Questions

10 free sample questions from a bank of 161, with the correct answers and explanations. No signup required — start practising right now.

1Which of the following will cause the greatest reduction in disk size requirements for a cluster of N indexers running Splunk Enterprise Security?
  • Setting the cluster search factor to N-1.
  • Increasing the number of buckets per index.
  • Decreasing the data model acceleration range.
  • Setting the cluster replication factor to N-1.
Answer: A
2Which index-time props.conf attributes impact indexing performance? (Select all that apply.)
  • REPORT
  • LINE_BREAKER
  • ANNOTATE_PUNCT
  • SHOULD_LINEMERGE
Answer: B, C
3Which of the following are client filters available in serverclass.conf? (Select all that apply.)
  • DNS name.
  • IP address.
  • Splunk server role.
  • Platform (machine type).
Answer: A, B
4What log file would you search to verify if you suspect there is a problem interpreting a regular expression in a monitor stanza?
  • btool.log
  • metrics.log
  • splunkd.log
  • tailing_processor.log
Answer: C
5Which Splunk tool offers a health check for administrators to evaluate the health of their Splunk deployment?
  • btool
  • DiagGen
  • SPL Clinic
  • Monitoring Console
Answer: D
6In a four site indexer cluster, which configuration stores two searchable copies at the origin site, one searchable copy at site2, and a total of four searchable copies?
  • site_search_factor = origin:2, site1:2, total:4
  • site_search_factor = origin:2, site2:1, total:4
  • site_replication_factor = origin:2, site1:2, total:4
  • site_replication_factor = origin:2, site2:1, total:4
Answer: B
7Which Splunk Enterprise offering has its own license?
  • Splunk Cloud Forwarder
  • Splunk Heavy Forwarder
  • Splunk Universal Forwarder
  • Splunk Forwarder Management
Answer: C
8Which component in the splunkd.log will log information related to bad event breaking?
  • Audittrail
  • EventBreaking
  • IndexingPipeline
  • AggregatorMiningProcessor
Answer: D
9Which Splunk server role regulates the functioning of indexer cluster?
  • Indexer
  • Deployer
  • Master Node
  • Monitoring Console
Answer: C
10When adding or rejoining a member to a search head cluster, the following error is displayed: Error pulling configurations from the search head cluster captain; consider performing a destructive configuration resync on this search head cluster member. What corrective action should be taken?
  • Restart the search head.
  • Run the splunk apply shcluster-bundle command from the deployer.
  • Run the clean raft command on all members of the search head cluster.
  • Run the splunk resync shcluster-replicated-config command on this member.
Answer: D

Want the full bank of 161 questions for SPLK-2002? See all practice exams.