SPLUNK ARCHITECT EXAM STUDY
GUIDE
Which of the following statements are true regarding multisite indexer clusters?
A. Each site has its own set of peer nodes, but they all use the same search heads
B. Each site also obeys site-specific replication and search factor rules
C. The cluster administrator defines the "sites"
D. B&C
E. All of the above
F. None of the above - Correct Answers -D
_________ controls and manages index replication, as well as distributes apps and
configurations.
A. Deployment Server
B. Deployer Server
C. Master Node
D. Peer Nodes - Correct Answers -C
Peer nodes index data from inputs/forwarders and replicates data to other peer nodes
as instructed by the deployment server.
True or False? - Correct Answers -False , (as instructed by Master Node)
Multisite clusters offer two key benefits: Disaster Recovery and Search Affinity.
True or False? - Correct Answers -True
There can be only one Master Node, even in a multisite cluster.
True or False? - Correct Answers -True
Which of the following are true statements about how a master node manages an index
cluster?
A. Coordinates the replicating activities of the peer nodes
B. Tells search heads where to find the data
C. Orchestrates remedial activities if a peer becomes unavailable
,D. B&C
E. All of the above - Correct Answers -E
The cluster will continue to operate while the Master Node is offline.
True or False? - Correct Answers -True
Which of the following are true statements regarding Replication Factor (RF)? (Select all
that apply)
A. Specifies how many copies will be searchable
B. Specifies how many total copies of rawdata the cluster can maintain
C. Sets the total failure tolerance level
D. Determines how quickly you can recover the search capability - Correct Answers -B
C
Which of the following are true statements regarding Search Factor (SF)? (Select all
that apply)
A. Specifies how many copies will be searchable
B. Specifies how many total copies of rawdata the cluster can maintain
C. Sets the total failure tolerance level
D. Determines how quickly you can recover the search capability - Correct Answers -A
D
For indexer clustering, multisite mode requires at least __ peer nodes per site in
multisite mode.
A. 3
B. 2
C. 4
D. 1 - Correct Answers -B
For indexer clustering, best practice for a single-site mode is to have at least _______
nodes as a minimum.
A. RF+1
B. RF+2
C. SF+1
D. SF+2 - Correct Answers -A
Regarding Remote Storage/SmartStore, hot buckets and warm buckets are stored
remotely and retrieved using the cache manager.
True or False? - Correct Answers -False
,Regarding SmartStore and index clustering, the indexer cluster can recover all of its
warm bucket data even when the number of failed nodes equals or exceeds the
replication factor.
True or False? - Correct Answers -True
All search heads in a cluster must have matching hardware specs.
True or False? - Correct Answers -True
You can run the same searches, view the same dashboards and access the same
search results from any search head in a cluster.
True or False? - Correct Answers -True
For Search Head clustering, the requirements include at least ___ search heads and a
_________.
A. 2, deployment server
B. 3, deployment server
C. 2, deployer
D. 3, deployer - Correct Answers -D - 3, deployer
Regarding Search Head clustering, the sizing guidelines for a ________ states that it
must have sufficient CPU and network resources to service requests and to push
configurations.
A. Search head
B. Deployment server
C. Deployer server
D. None of the above - Correct Answers -C
For Search Head clustering, the summary indexes must be forwarded to the indexer
tier.
True or False? - Correct Answers -True
Choose the Types of Integration:
A. Apps from Splunkbase
B. HDFS
C. Re-forwarding data to other Apps after indexing occurs
D. Alert Actions
E. All of the above - Correct Answers -E. All of the above
What are two ways to send/move data to other systems via Splunk?
, (Select all that apply)
A. TCP
B. Email
C. Copy/Paste
D. Scheduled Searches
E. All of the above - Correct Answers -A D
When forwarding data to other systems via TCP, Splunk is unable to send raw text or
syslog.
True or False? - Correct Answers -False - TCP sends raw text and syslog data
SDK's help to simplify code development for languages such as Python & C#.
True or False? - Correct Answers -True : JavaScript & Java as well
Hadoop searches only work in _________ installs.
A. Windows
B. DOS
C. Town OS by Fujitsu
D. Linux - Correct Answers -D
Scheduled searches leverage the functionality of Splunk alerts.
True or False? - Correct Answers -True
Splunk Analytics for Hadoop requires at least 2 Search Heads to access both Splunk
index and HDFS.
True or False? - Correct Answers -False: Accesses both Splunk indexes & HDFS from
single SH
Search Extensibility includes:
(Select all that apply)
A. Indexers
B. Custom Search commands
C. Workflow Actions
D. Custom Navigation
E. Universal Forwarders
F. Scripted lookups - Correct Answers -B C D F
There are over 200 endpoints REST API can interact with in a Splunk instance.
GUIDE
Which of the following statements are true regarding multisite indexer clusters?
A. Each site has its own set of peer nodes, but they all use the same search heads
B. Each site also obeys site-specific replication and search factor rules
C. The cluster administrator defines the "sites"
D. B&C
E. All of the above
F. None of the above - Correct Answers -D
_________ controls and manages index replication, as well as distributes apps and
configurations.
A. Deployment Server
B. Deployer Server
C. Master Node
D. Peer Nodes - Correct Answers -C
Peer nodes index data from inputs/forwarders and replicates data to other peer nodes
as instructed by the deployment server.
True or False? - Correct Answers -False , (as instructed by Master Node)
Multisite clusters offer two key benefits: Disaster Recovery and Search Affinity.
True or False? - Correct Answers -True
There can be only one Master Node, even in a multisite cluster.
True or False? - Correct Answers -True
Which of the following are true statements about how a master node manages an index
cluster?
A. Coordinates the replicating activities of the peer nodes
B. Tells search heads where to find the data
C. Orchestrates remedial activities if a peer becomes unavailable
,D. B&C
E. All of the above - Correct Answers -E
The cluster will continue to operate while the Master Node is offline.
True or False? - Correct Answers -True
Which of the following are true statements regarding Replication Factor (RF)? (Select all
that apply)
A. Specifies how many copies will be searchable
B. Specifies how many total copies of rawdata the cluster can maintain
C. Sets the total failure tolerance level
D. Determines how quickly you can recover the search capability - Correct Answers -B
C
Which of the following are true statements regarding Search Factor (SF)? (Select all
that apply)
A. Specifies how many copies will be searchable
B. Specifies how many total copies of rawdata the cluster can maintain
C. Sets the total failure tolerance level
D. Determines how quickly you can recover the search capability - Correct Answers -A
D
For indexer clustering, multisite mode requires at least __ peer nodes per site in
multisite mode.
A. 3
B. 2
C. 4
D. 1 - Correct Answers -B
For indexer clustering, best practice for a single-site mode is to have at least _______
nodes as a minimum.
A. RF+1
B. RF+2
C. SF+1
D. SF+2 - Correct Answers -A
Regarding Remote Storage/SmartStore, hot buckets and warm buckets are stored
remotely and retrieved using the cache manager.
True or False? - Correct Answers -False
,Regarding SmartStore and index clustering, the indexer cluster can recover all of its
warm bucket data even when the number of failed nodes equals or exceeds the
replication factor.
True or False? - Correct Answers -True
All search heads in a cluster must have matching hardware specs.
True or False? - Correct Answers -True
You can run the same searches, view the same dashboards and access the same
search results from any search head in a cluster.
True or False? - Correct Answers -True
For Search Head clustering, the requirements include at least ___ search heads and a
_________.
A. 2, deployment server
B. 3, deployment server
C. 2, deployer
D. 3, deployer - Correct Answers -D - 3, deployer
Regarding Search Head clustering, the sizing guidelines for a ________ states that it
must have sufficient CPU and network resources to service requests and to push
configurations.
A. Search head
B. Deployment server
C. Deployer server
D. None of the above - Correct Answers -C
For Search Head clustering, the summary indexes must be forwarded to the indexer
tier.
True or False? - Correct Answers -True
Choose the Types of Integration:
A. Apps from Splunkbase
B. HDFS
C. Re-forwarding data to other Apps after indexing occurs
D. Alert Actions
E. All of the above - Correct Answers -E. All of the above
What are two ways to send/move data to other systems via Splunk?
, (Select all that apply)
A. TCP
B. Email
C. Copy/Paste
D. Scheduled Searches
E. All of the above - Correct Answers -A D
When forwarding data to other systems via TCP, Splunk is unable to send raw text or
syslog.
True or False? - Correct Answers -False - TCP sends raw text and syslog data
SDK's help to simplify code development for languages such as Python & C#.
True or False? - Correct Answers -True : JavaScript & Java as well
Hadoop searches only work in _________ installs.
A. Windows
B. DOS
C. Town OS by Fujitsu
D. Linux - Correct Answers -D
Scheduled searches leverage the functionality of Splunk alerts.
True or False? - Correct Answers -True
Splunk Analytics for Hadoop requires at least 2 Search Heads to access both Splunk
index and HDFS.
True or False? - Correct Answers -False: Accesses both Splunk indexes & HDFS from
single SH
Search Extensibility includes:
(Select all that apply)
A. Indexers
B. Custom Search commands
C. Workflow Actions
D. Custom Navigation
E. Universal Forwarders
F. Scripted lookups - Correct Answers -B C D F
There are over 200 endpoints REST API can interact with in a Splunk instance.