
SplunkEnterprise Certified Architect
Domain 3Objective 5
Indexer Cluster Storage Utilization Options SPLK-2002 Practice Questions (Page 5)
Part of the Indexer Clustering domain, which makes up ~25% of our current practice bank. Splunk does not publish an official question count, but from its 90-minute exam (~35–60 total, ~9–15 in this domain), expect 1–2 from this objective — we provide 25 practice questions to prepare you well beyond it. (estimate)
25questions here
5free pages
7concepts
Questions 21–25
- 21
A Splunk administrator notices that one index in a cluster is consuming a disproportionate amount of storage, causing other indexes to fail replication due to lack of space. The administrator wants to prevent this by limiting the storage that this index can use. Which configuration should be applied?
Select an answer first - 22
A Splunk indexer cluster is running low on storage. The administrator needs to free up space without losing the ability to search recent data. The cluster has a replication factor of 2 and a search factor of 1. Which action will reduce storage utilization while preserving searchability of the most recent data?
Select an answer first - 23
A Splunk administrator suspects that one indexer in a cluster is running out of storage space, which could cause replication failures. Which command or tool should be used to quickly assess the current storage utilization of each indexer in the cluster?
Select an answer first - 24
A Splunk administrator is troubleshooting a search performance issue in an indexer cluster. The cluster has a replication factor of 3 and a search factor of 1. Searches are taking longer than expected, and the administrator suspects that the search factor is too low. Which action should be taken to improve search performance?
Select an answer first - 25
A Splunk administrator is managing an indexer cluster with multiple indexes. One index is used for compliance data that must be retained for 7 years, while another index is used for operational logs that only need 30 days of retention. The cluster is running out of storage. The administrator wants to ensure that the compliance data is never lost, but the operational logs can be deleted after 30 days. Which approach should be taken?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to SPLK-2002
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Splunk. “SPLK-2002” is a trademark of its owner, used for identification only.