Exam 7: Splunk Core Certified Consultant

arrow
  • Select Tags
search iconSearch Question
flashcardsStudy Flashcards
  • Select Tags

A customer is migrating their existing Splunk Indexer from an old set of hardware to a new set of indexers. What is the earliest method to migrate the system?

Free
(Multiple Choice)
4.7/5
(25)
Correct Answer:
Verified

B

A non-ES customer has a concern about data availability during a disaster recovery event. Which of the following Splunk Validated Architectures (SVAs) would be recommended for that use case?

Free
(Multiple Choice)
4.7/5
(38)
Correct Answer:
Verified

B

Which command is most efficient in finding the pass4SymmKey of an index cluster?

Free
(Multiple Choice)
4.9/5
(30)
Correct Answer:
Verified

D

What does Splunk do when it indexes events?

(Multiple Choice)
4.8/5
(37)

In a single indexer cluster, where should the Monitoring Console (MC) be installed?

(Multiple Choice)
4.8/5
(31)

What is the default push mode for a search head cluster deployer app configuration bundle?

(Multiple Choice)
4.8/5
(33)

What should be considered when running the following CLI commands with a goal of accelerating an index cluster migration to new hardware? What should be considered when running the following CLI commands with a goal of accelerating an index cluster migration to new hardware?

(Multiple Choice)
4.9/5
(33)

In which of the following scenarios should base configurations be used to provide consistent, repeatable, and supportable configurations?

(Multiple Choice)
4.8/5
(36)

Where does the bloomfilter reside?

(Multiple Choice)
4.8/5
(42)

How does Monitoring Console (MC) initially identify the server role(s) of a new Splunk Instance?

(Multiple Choice)
4.8/5
(38)

In preparation for the deployment of a new environment for a customer, which of the following mappings are correct per PS best practices?

(Multiple Choice)
4.9/5
(28)

A customer has a multisite cluster (two sites, each site in its own data center) and users experiencing a slow response when searches are run on search heads located in either site. The Search Job Inspector shows the delay is being caused by search heads on either site waiting for results to be returned by indexers on the opposing site. The network team has confirmed that there is limited bandwidth available between the two data centers, which are in different geographic locations. Which of the following would be the least expensive and easiest way to improve search performance?

(Multiple Choice)
4.9/5
(35)

A customer's deployment server is overwhelmed with forwarder connections after adding an additional 1000 clients. The default phone home interval is set to 60 seconds. To reduce the number of connection failures to the DS what is recommended?

(Multiple Choice)
4.7/5
(31)

What is the Splunk PS recommendation when using the deployment server and building deployment apps?

(Multiple Choice)
4.8/5
(32)

A customer has a search cluster (SHC) of six members split evenly between two data centers (DC). The customer is concerned with network connectivity between the two DCs due to frequent outages. Which of the following is true as it relates to SHC resiliency when a network outage occurs between the two DCs?

(Multiple Choice)
4.9/5
(29)

The customer has an indexer cluster supporting a wide variety of search needs, including scheduled search, data model acceleration, and summary indexing. Here is an excerpt from the cluster mater's server.conf : The customer has an indexer cluster supporting a wide variety of search needs, including scheduled search, data model acceleration, and summary indexing. Here is an excerpt from the cluster mater's server.conf :   Which strategy represents the minimum and least disruptive change necessary to protect the searchability of the indexer cluster in case of indexer failure? Which strategy represents the minimum and least disruptive change necessary to protect the searchability of the indexer cluster in case of indexer failure?

(Multiple Choice)
4.8/5
(32)

In the diagrammed environment shown below, the customer would like the data read by the universal forwarders to set an indexed field containing the UF's host name. Where would the parsing configurations need to be installed for this to work? In the diagrammed environment shown below, the customer would like the data read by the universal forwarders to set an indexed field containing the UF's host name. Where would the parsing configurations need to be installed for this to work?

(Multiple Choice)
4.8/5
(35)

A customer is using both internal Splunk authentication and LDAP for user management. If a username exists in both $SPLUNK_HOME/etc/passwd and LDAP, which of the following statements is accurate?

(Multiple Choice)
4.8/5
(36)

In an environment that has Indexer Clustering, the Monitoring Console (MC) provides dashboards to monitor environment health. As the environment grows over time and new indexers are added, which steps would ensure the MC is aware of the additional indexers?

(Multiple Choice)
4.9/5
(34)

The Splunk Validated Architectures (SVAs) document provides a series of approved Splunk topologies. Which statement accurately describes how it should be used by a customer?

(Multiple Choice)
4.9/5
(39)
Showing 1 - 20 of 62
close modal

Filters

  • Essay(0)
  • Multiple Choice(0)
  • Short Answer(0)
  • True False(0)
  • Matching(0)