Splunk

SPLK-2002 practice test

Practice with 15 free Testara sample questions, or choose paid access to the full 71-question bank.

Provider
Splunk
Question bank
71
Free sample
15 questions
Publisher
Testara

About this practice material

This page covers Testara's practice question bank for SPLK-2002, a certification listed under Splunk. Questions use original, exam-style scenarios and are not questions from the official certification exam.

Testara is an independent practice platform and is not affiliated with, endorsed by, or authorized by Splunk. The certification credential is issued by Splunk, not Testara. Certification and provider names belong to their respective owners.

Start practicing

The guest demo does not save an attempt. Sign in before buying access.

Try 15 questions free

Available without signing in

Free sample questions

These 15 questions and their explanations are server-rendered so you can inspect the material before opening the interactive demo.

  1. Question 1 · 1

    Which of the following will cause the greatest reduction in disk size requirements for a cluster of N indexers running Splunk Enterprise Security?

    Choose one answer.

    • Setting the cluster search factor to N-1.
    • Increasing the number of buckets per index.
    • Decreasing the data model acceleration range.
    • Setting the cluster replication factor to N-1.
  2. Question 2 · 1

    Which index-time props.conf attributes impact indexing performance? (Select all that apply.)

    Choose all answers that apply.

    • REPORT
    • LINE_BREAKER
    • ANNOTATE_PUNCT
    • SHOULD_LINEMERGE
  3. Question 3 · 1

    Which of the following are client filters available in serverclass.conf? (Select all that apply.)

    Choose all answers that apply.

    • DNS name.
    • IP address.
    • Splunk server role.
    • Platform (machine type).
  4. Question 4 · 1

    In a four site indexer cluster, which configuration stores two searchable copies at the origin site, one searchable copy at site2, and a total of four searchable copies?

    Choose one answer.

    • site_search_factor = origin:2, site1:2, total:4
    • site_search_factor = origin:2, site2:1, total:4
    • site_replication_factor = origin:2, site1:2, total:4
    • site_replication_factor = origin:2, site2:1, total:4
  5. Question 5 · 1

    Which Splunk Enterprise offering has its own license?

    Choose one answer.

    • Splunk Cloud Forwarder
    • Splunk Heavy Forwarder
    • Splunk Universal Forwarder
    • Splunk Forwarder Management
  6. Question 6 · 1

    Which Splunk server role regulates the functioning of indexer cluster?

    Choose one answer.

    • Indexer
    • Deployer
    • Master Node
    • Monitoring Console
  7. Question 7 · 1

    When adding or rejoining a member to a search head cluster, the following error is displayed: Error pulling configurations from the search head cluster captain; consider performing a destructive configuration resync on this search head cluster member. What corrective action should be taken?

    Choose one answer.

    • Restart the search head.
    • Run the splunk apply shcluster-bundle command from the deployer.
    • Run the clean raft command on all members of the search head cluster.
    • Run the splunk resync shcluster-replicated-config command on this member.
  8. Question 8 · 1

    Stakeholders have identified high availability for searchable data as their top priority. Which of the following best addresses this requirement?

    Choose one answer.

    • Increasing the search factor in the cluster.
    • Increasing the replication factor in the cluster.
    • Increasing the number of search heads in the cluster.
    • Increasing the number of CPUs on the indexers in the cluster.
  9. Question 9 · 1

    Indexing is slow and real-time search results are delayed in a Splunk environment with two indexers and one search head. There is ample CPU and memory available on the indexers. Which of the following is most likely to improve indexing performance?

    Choose one answer.

    • Increase the maximum number of hot buckets in indexes.conf
    • Increase the number of parallel ingestion pipelines in server.conf
    • Decrease the maximum size of the search pipelines in limits.conf
    • Decrease the maximum concurrent scheduled searches in limits.conf
  10. Question 10 · 1

    The guidance Splunk gives for estimating size on for syslog data is 50% of original data size. How does this divide between files in the index?

    Choose one answer.

    • rawdata is: 10%, tsidx is: 40%
    • rawdata is: 15%, tsidx is: 35%
    • rawdata is: 35%, tsidx is: 15%
    • rawdata is: 40%, tsidx is: 10%
  11. Question 11 · 1

    A three-node search head cluster is skipping a large number of searches across time. What should be done to increase scheduled search capacity on the search head cluster?

    Choose one answer.

    • Create a job server on the cluster.
    • Add another search head to the cluster.
    • server.conf captain_is_adhoc_searchhead = true.
    • Change limits.conf value for max_searches_per_cpu to a higher value.
  12. Question 12 · 1

    Which of the following clarification steps should be taken if apps are not appearing on a deployment client? (Select all that apply.)

    Choose all answers that apply.

    • Check serverclass.conf of the deployment server.
    • Check deploymentclient.conf of the deployment client.
    • Check the content of SPLUNK_HOME/etc/apps of the deployment server.
    • Search for relevant events in splunkd.log of the deployment server.
  13. Question 13 · 1

    Which of the following artifacts are included in a Splunk diag file? (Select all that apply.)

    Choose all answers that apply.

    • OS settings.
    • Internal logs.
    • Customer data.
    • Configuration files.
  14. Question 14 · 1

    Which command will permanently decommission a peer node operating in an indexer cluster?

    Choose one answer.

    • splunk stop -f
    • splunk offline -f
    • splunk offline --enforce-counts
    • splunk decommission --enforce counts
  15. Question 15 · 1

    Which CLI command converts a Splunk instance to a license slave?

    Choose one answer.

    • splunk add licenses
    • splunk list licenser-slaves
    • splunk edit licenser-localslave
    • splunk list licenser-localslave

Each purchase applies to this certification. Prices are one-time payments, not monthly subscriptions.

Starter

$29 USD one time

Full access to one certification's question bank in standard practice mode for 60 days.

  • Full question bank for one certification
  • 60 days of access
  • Standard practice mode
  • Question notes and community discussions
  • Attempt scores and answer review

Professional

$49 USD one time

Full access to one certification's question bank, custom test controls and advanced analytics for 60 days.

  • Custom test builder
  • Timers and question selection
  • Randomized question and answer order
  • Advanced performance and weak-question analytics
  • Priority customer support
Try 15 questions free