
SplunkEnterprise Certified Architect
Domain 1Objective 1
Gather Requirements SPLK-2002 Practice Questions (Page 2)
Part of the Requirements and Infrastructure Planning domain, which makes up ~12% of our current practice bank. Splunk does not publish an official question count, but from its 90-minute exam (~35–60 total, ~4–7 in this domain), expect 1–1 from this objective — we provide 24 practice questions to prepare you well beyond it. (estimate)
24questions here
5free pages
6concepts
Questions 6–10
- 6
A company plans to deploy Splunk Enterprise to index security logs from 500 servers. Each server generates 2 GB of logs per day, and they want to retain data for 90 days. They also expect a 20% annual growth in log volume. Using the Splunk sizing calculator, what is the most important input to determine the required storage capacity?
Select an answer first - 7
A company is planning a Splunk deployment. They currently ingest 500 GB/day and expect a 50% growth in the next year. They want to retain data for 180 days. The architect is considering using a single indexer with a large disk. What is the most important consideration when planning storage?
Select an answer first - 8
A Splunk architect is planning a deployment and needs to estimate storage requirements. They have the daily ingest volume and retention period. However, they are unsure about the projected growth rate. What is the best approach?
Select an answer first - 9
A company is planning a Splunk deployment. They have a mix of on-premises servers and cloud-based applications. They want to ingest logs from both environments. What is the most important environmental characteristic to document?
Select an answer first - 10
Which of the following items is typically included in a Splunk requirements gathering checklist?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Splunk. “SPLK-2002” is a trademark of its owner, used for identification only.