Exam 5: Splunk Enterprise Security Certified Admin

arrow
  • Select Tags
search iconSearch Question
flashcardsStudy Flashcards
  • Select Tags

Configurations from the deployer are merged into which location on the search head cluster member?

Free
(Multiple Choice)
4.8/5
(35)
Correct Answer:
Verified

A

The frequency in which a deployment client contacts the deployment server is controlled by what?

Free
(Multiple Choice)
4.8/5
(31)
Correct Answer:
Verified

D

Which of the following is an indexer clustering requirement?

Free
(Multiple Choice)
4.8/5
(26)
Correct Answer:
Verified

D

Which search will show all deployment client messages from the client (UF)?

(Multiple Choice)
4.8/5
(35)

Before users can use a KV store, an admin must create a collection. Where is a collection is defined?

(Multiple Choice)
4.9/5
(39)

In search head clustering, which of the following methods can you use to transfer captaincy to a different member? (Select all that apply.)

(Multiple Choice)
4.8/5
(32)

A multi-site indexer cluster can be configured using which of the following? (Select all that apply.)

(Multiple Choice)
4.9/5
(39)

What is a Splunk Job? (Select all that apply.)

(Multiple Choice)
4.9/5
(25)

Which of the following commands is used to clear the KV store?

(Multiple Choice)
4.9/5
(31)

Which of the following will cause the greatest reduction in disk size requirements for a cluster of N indexers running Splunk Enterprise Security?

(Multiple Choice)
4.9/5
(37)

What does setting site=site0 on all Search Head Cluster members do in a multi-site indexer cluster?

(Multiple Choice)
4.8/5
(34)

To reduce the captain's work load in a search head cluster, what setting will prevent scheduled searches from running on the captain?

(Multiple Choice)
4.9/5
(30)

At which default interval does metrics.log generate a periodic report regarding license utilization?

(Multiple Choice)
4.9/5
(28)

Which of the following statements describe licensing in a clustered Splunk deployment? (Select all that apply.)

(Multiple Choice)
4.8/5
(39)

Which of the following are client filters available in serverclass.conf ? (Select all that apply.)

(Multiple Choice)
4.8/5
(34)

Which of the following artifacts are included in a Splunk diag file? (Select all that apply.)

(Multiple Choice)
4.8/5
(37)

Which server.conf attribute should be added to the master node's file when decommissioning a site in an indexer cluster?

(Multiple Choice)
4.8/5
(36)

Which CLI command converts a Splunk instance to a license slave?

(Multiple Choice)
4.9/5
(32)

Search dashboards in the Monitoring Console indicate that the distributed deployment is approaching its capacity. Which of the following options will provide the most search performance improvement?

(Multiple Choice)
4.8/5
(31)

To improve Splunk performance, parallelIngestionPipeline s setting can be adjusted on which of the following components in the Splunk architecture? (Select all that apply.)

(Multiple Choice)
4.7/5
(38)
Showing 1 - 20 of 85
close modal

Filters

  • Essay(0)
  • Multiple Choice(0)
  • Short Answer(0)
  • True False(0)
  • Matching(0)