Pre-Summer Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: validbest

Pass the Splunk Core Certified Consultant SPLK-3003 Questions and answers with ValidTests

Exam SPLK-3003 All Questions
Exam SPLK-3003 Premium Access

View all detail and faqs for the SPLK-3003 exam

Viewing page 2 out of 3 pages
Viewing questions 11-20 out of questions
Questions # 11:

Report acceleration has been enabled for a specific use case. In which bucket location is the corresponding CSV file located?

Options:

A.

thawedPath

B.

summaryHomePath

C.

tstatsHomePath

D.

homePath, coldPath

Expert Solution
Questions # 12:

As a best practice which of the following should be used to ingest data on clustered indexers?

Options:

A.

Monitoring (via a process), collecting data (modular inputs) from remote systems/applications

B.

Modular inputs, HTTP Event Collector (HEC), inputs.conf monitor stanza

C.

Actively listening on ports, monitoring (via a process), collecting data from remote systems/applications

D.

splunktcp, splunktcp-ssl, HTTP Event Collector (HEC)

Expert Solution
Questions # 13:

A customer has implemented their own Role Based Access Control (RBAC) model to attempt to give the Security team different data access than the Operations team by creating two new Splunk roles – security and operations. In the srchIndexesAllowed setting of authorize.conf, they specified the network index

under the security role and the operations index under the operations role. The new roles are set up to inherit the default user role.

If a new user is created and assigned to the operations role only, which indexes will the user have access to search?

Options:

A.

operations, network, _internal, _audit

B.

operations

C.

No Indexes

D.

operations, network

Expert Solution
Questions # 14:

A customer has three users and is planning to ingest 250GB of data per day. They are concerned with search uptime, can tolerate up to a two-hour downtime for the search tier, and want advice on single search head versus a search head cluster. (SHC).

Which recommendation is the most appropriate?

Options:

A.

The customer should deploy two active search heads behind a load balancer to support HA.

B.

The customer should deploy a SHC with a single member for HA; more members can be added later.

C.

The customer should deploy a SHC, because it will be required to support the high volume of data.

D.

The customer should deploy a single search head with a warm standby search head and a rsync process to synchronize configurations.

Expert Solution
Questions # 15:

Monitoring Console (MC) health check configuration items are stored in which configuration file?

Options:

A.

healthcheck.conf

B.

alert_actions.conf

C.

distsearch.conf

D.

checklist.conf

Expert Solution
Questions # 16:

In a large cloud customer environment with many (>100) dynamically created endpoint systems, each with a UF already deployed, what is the best approach for associating these systems with an appropriate serverclass on the deployment server?

Options:

A.

Work with the cloud orchestration team to create a common host-naming convention for these systems so a simple pattern can be used in the serverclass.conf whitelist attribute.

B.

Create a CSV lookup file for each severclass, manually keep track of the endpoints within this CSV file, and leverage the whitelist.from_pathname attribute in serverclass.conf.

C.

Work with the cloud orchestration team to dynamically insert an appropriate clientName setting into each endpoint’s local/deploymentclient.conf which can be matched by whitelist in serverclass.conf.

D.

Using an installation bootstrap script run a CLI command to assign a clientName setting and permit

serverclass.conf whitelist simplification.

Expert Solution
Questions # 17:

Which of the following server.conf stanzas indicates the Indexer Discovery feature has not been fully configured (restart pending) on the Master Node?

Question # 17

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Expert Solution
Questions # 18:

How does Monitoring Console (MC) initially identify the server role(s) of a new Splunk Instance?

Options:

A.

The MC uses a REST endpoint to query the server.

B.

Roles are manually assigned within the MC.

C.

Roles are read from distsearch.conf.

D.

The MC assigns all possible roles by default.

Expert Solution
Questions # 19:

In preparation for the deployment of a new environment for a customer, which of the following mappings are correct per PS best practices?

Question # 19

Question # 19

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Expert Solution
Questions # 20:

The data in Splunk is now subject to auditing and compliance controls. A customer would like to ensure that at least one year of logs are retained for both Windows and Firewall events. What data retention controls must be configured?

Options:

A.

maxTotalDataSizeMB and frozenTimePeriodInSecs

B.

coldToFrozenDir and coldToFrozenScript

C.

Splunk Volume and maxTotalDataSizMB

D.

Splunk Volume and frozenTimePeriodInSecs

Expert Solution
Viewing page 2 out of 3 pages
Viewing questions 11-20 out of questions