Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Splunk logo

SplunkEnterprise Certified Architect

Domain 1Objective 5

Identify Apps and Security SPLK-2002 Practice Questions (Page 1)

Part of the Requirements and Infrastructure Planning domain, which makes up ~12% of our current practice bank. Splunk does not publish an official question count, but from its 90-minute exam (~35–60 total, ~4–7 in this domain), expect 1–1 from this objective — we provide 14 practice questions to prepare you well beyond it. (estimate)

14questions here
3free pages
4concepts

Questions 1–5

  1. 1expert · hard

    A retail company is deploying Splunk to monitor customer transactions. The marketing team wants to analyze purchase patterns, while the privacy team requires that customer email addresses be masked. The architect must balance these needs. Which approach should the architect take?

    Select an answer first
  2. 2foundation · easy

    An organization wants to monitor the health and performance of its Splunk deployment, including indexer and search head status. Which Splunk app is specifically designed for this purpose?

    Select an answer first
  3. 3expert · hard

    A large organization is deploying Splunk Enterprise to support both security monitoring and compliance reporting. The security team wants to use the Splunk App for Enterprise Security, while the compliance team wants to use the Splunk App for PCI Compliance. The architect must decide whether to install both apps or just one. Which consideration should drive the decision?

    Select an answer first
  4. 4application · medium

    A security operations team is using Splunk to monitor firewall logs. They suspect that a malicious actor may have tampered with log data to hide an intrusion. The architect needs to implement a measure that ensures the integrity of the data and provides a way to detect tampering. Which measure should the architect implement?

    Select an answer first
  5. 5foundation · easy

    A security operations team needs to analyze authentication events from multiple sources, including VPN, Active Directory, and cloud identity providers. Which Splunk app is designed to provide prebuilt dashboards and correlation searches for this use case?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Splunk. “SPLK-2002” is a trademark of its owner, used for identification only.