exam questions

Exam SPLK-2002 All Questions

View all questions & answers for the SPLK-2002 exam

Exam SPLK-2002 topic 1 question 71 discussion

Actual exam question from Splunk's SPLK-2002
Question #: 71
Topic #: 1
[All SPLK-2002 Questions]

Consider a use case involving firewall data. There is no Splunk-supported Technical Add-On, but the vendor has built one. What are the items that must be evaluated before installing the add-on? (Select all that apply.)

  • A. Identify number of scheduled or real-time searches.
  • B. Validate if this Technical Add-On enables event data for a data model.
  • C. Identify the maximum number of forwarders Technical Add-On can support.
  • D. Verify if Technical Add-On needs to be installed onto both a search head or indexer.
Show Suggested Answer Hide Answer
Suggested Answer: AB 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
frappe
Highly Voted 1 year, 7 months ago
Selected Answer: AB
A B D - there is no "maximum" amount of forwarders a TA can support.
upvoted 7 times
b5white
6 months, 3 weeks ago
I can't find any mention of needing any of A, B, or C. Why would I care how many searches there might be or the data model?
upvoted 2 times
Bob_Hob
1 week, 6 days ago
A: For the app to run as intended you might run into concurrency limits with the stock settings. B: you don't want a bunch of new *unexpected* data flowing into one of Splunks default data models. C doesn't make sense because like frappe mentioned the TA doesn't care how many forwarders are supported if it is built right - it is entirely infra dependent. D: Needs to be considered for if there are indexed field extractions or data masking expected
upvoted 1 times
...
...
...
adamsca
Most Recent 4 months, 3 weeks ago
Selected Answer: AB
Correct: A - Identify number of scheduled or real-time searches. B - Validate if this Technical Add-On enables event data for a data model. Incorrect: C - The number of forwarders that the TA can support is not relevant, as the TA is installed on the indexer or search head, not on the forwarder. D - The installation location of the TA depends on the type of data and the use case, so it is not a fixed requirement
upvoted 1 times
...
qtygbapjpesdayazko
8 months, 3 weeks ago
Selected Answer: BD
B, D. TA should not have dashboards or SC or searchs.
upvoted 2 times
...
deepali_2710
10 months ago
A. Identify number of scheduled or real-time searches. B. Validate if this Technical Add-On enables event data for a data model. D. Verify if Technical Add-On needs to be installed onto both a search head or indexer. Before installing a Technical Add-On for firewall data, it is important to evaluate several factors to ensure that the add-on will function correctly and integrate with the organization's existing infrastructure. Some key items that should be evaluated include the number of scheduled or real-time searches that will be performed using the add-on, whether the add-on enables event data for a data model, and whether the add-on needs to be installed onto both a search head or indexer. C, identifying the maximum number of forwarders Technical Add-On can support, may also be important depending on the size and scale of the organization's deployment, but it is not as critical as the other factors mentioned.
upvoted 2 times
marinatedcohort
3 months, 2 weeks ago
Any reference for this?
upvoted 1 times
...
...
lzng3r
11 months, 2 weeks ago
Selected Answer: AB
ABD is the answer
upvoted 1 times
marinatedcohort
3 months, 2 weeks ago
Do you have a reference for this?
upvoted 1 times
...
...
denominator
1 year, 2 months ago
answers ABD seems correct!!!
upvoted 3 times
...
just4learn
1 year, 11 months ago
The answer is A C D
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago