Exam 5: Splunk Enterprise Security Certified Admin

arrow
  • Select Tags
search iconSearch Question
flashcardsStudy Flashcards
  • Select Tags

Which of the following options can improve reliability of syslog delivery to Splunk? (Select all that apply.)

(Multiple Choice)
4.8/5
(33)

What is the default log size for Splunk internal logs?

(Multiple Choice)
4.8/5
(34)

To optimize the distribution of primary buckets; when does primary rebalancing automatically occur? (Select all that apply.)

(Multiple Choice)
4.8/5
(34)

When Splunk indexes data in a non clustered environment, what kind of files does it create by default?

(Multiple Choice)
4.9/5
(40)

Which Splunk tool offers a health check for administrators to evaluate the health of their Splunk deployment?

(Multiple Choice)
4.8/5
(35)

A three-node search head cluster is skipping a large number of searches across time. What should be done to increase scheduled search capacity on the search head cluster?

(Multiple Choice)
4.9/5
(40)

A search head has successfully joined a single site indexer cluster. Which command is used to configure the same search head to join another indexer cluster?

(Multiple Choice)
4.8/5
(37)

Which of the following tasks should the architect perform when building a deployment plan? (Select all that apply.)

(Multiple Choice)
4.7/5
(40)

Which of the following is a best practice to maximize indexing performance?

(Multiple Choice)
4.9/5
(47)

Which command is used for thawing the archive bucket?

(Multiple Choice)
4.8/5
(40)

Which Splunk Enterprise offering has its own license?

(Multiple Choice)
4.8/5
(40)

In the deployment planning process, when should a person identify who gets to see network data?

(Multiple Choice)
4.8/5
(39)

When Splunk is installed, where are the internal indexes stored by default?

(Multiple Choice)
4.7/5
(38)

Which of the following is a good practice for a search head cluster deployer?

(Multiple Choice)
4.7/5
(39)

As a best practice, where should the internal licensing logs be stored?

(Multiple Choice)
4.9/5
(36)

When should multiple search pipelines be enabled?

(Multiple Choice)
4.9/5
(43)

The KV store forms its own cluster within a SHC. What is the maximum number of SHC members KV store will form?

(Multiple Choice)
4.8/5
(31)

Which of the following can a Splunk diag contain?

(Multiple Choice)
4.7/5
(39)

When troubleshooting monitor inputs, which command checks the status of the tailed files?

(Multiple Choice)
4.9/5
(39)

Which Splunk server role regulates the functioning of indexer cluster?

(Multiple Choice)
4.9/5
(27)
Showing 61 - 80 of 85
close modal

Filters

  • Essay(0)
  • Multiple Choice(0)
  • Short Answer(0)
  • True False(0)
  • Matching(0)