Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Splunk logo

SplunkEnterprise Certified Architect

Domain 4Objective 5

Search Head Member Addition and Decommissioning SPLK-2002 Practice Questions (Page 1)

Part of the Search Head Clustering and KV Store domain, which makes up ~19% of our current practice bank. Splunk does not publish an official question count, but from its 90-minute exam (~35–60 total, ~7–11 in this domain), expect 1–2 from this objective — we provide 18 practice questions to prepare you well beyond it. (estimate)

18questions here
4free pages
6concepts

Questions 1–5

  1. 1application · medium

    You are decommissioning a search head from your cluster. The member has a custom knowledge object (a saved search) that is not shared. What should you do before removing the member?

    Select an answer first
  2. 2foundation · easy

    Which check should be performed before decommissioning a search head from a search head cluster?

    Select an answer first
  3. 3expert · hard

    Your search head cluster has five members, all running Splunk Enterprise 8.2. You are adding a sixth member. The new server has Splunk Enterprise 9.0 installed. You run `splunk add shcluster-member -mgmt_uri <captain_uri>` and restart, but the member does not appear in `splunk show shcluster-status`. What is the most likely cause?

    Select an answer first
  4. 4application · medium

    You are adding a new search head to a cluster. The new server has Splunk Enterprise installed but is not yet configured. You have already run `splunk add shcluster-member -mgmt_uri https://captain.example.com:8089` and restarted. The member does not appear in the captain's `splunk show shcluster-status`. What is the most likely cause?

    Select an answer first
  5. 5expert · hard

    You are adding a new search head to a cluster. The new member has been configured with `splunk add shcluster-member` and restarted. It appears in `splunk show shcluster-status` as 'Up', but searches run on it fail with an error about missing indexes. Other members can search the same indexes successfully. What is the most likely cause?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Splunk. “SPLK-2002” is a trademark of its owner, used for identification only.