Which option on the Add Data menu is most useful for testing data ingestion without creating inputs.conf?
Answer : A
Which of the following methods will connect a deployment client to a deployment server? (select all that apply)
Answer : A, C
The correct methods to connect a deployment client to a deployment server are A and C.You can either run the commandsplunk set deploy-poll <IP_address/hostname>:<management_port>from the command line of the deployment client1or create and edit a deploymentclient.conf file in$SPLUNK_HOME/etc/system/localon the deployment client2. Both methods require you to specify the IP address, hostname, and management port of the deployment server that you want the client to connect to.
What type of data is counted against the Enterprise license at a fixed 150 bytes per event?
Answer : B
What action is required to enable forwarder management in Splunk Web?
Answer : C
https://docs.splunk.com/Documentation/MSApp/2.0.3/MSInfra/Setupadeploymentserver
'To activate deployment server, you must place at least one app into %SPLUNK_HOME%\etc\deployment-apps on the host you want to act as deployment server. In this case, the app is the 'send to indexer' app you created earlier, and the host is the indexer you set up initially.
When working with an indexer cluster, what changes with the global precedence when comparing to a standalone deployment?
Answer : C
The app local directories move to second in the priority list. This is explained in the Splunk documentation, which states:
In a clustered environment, the precedence of configuration files changes slightly from that of a standalone deployment. The app local directories move to second in the priority list, after the peer-apps local directory. This means that any configuration files in the app local directories on the individual peers are overridden by configuration files of the same name and type in the peer-apps local directory on the master node.
Which Splunk component consolidates the individual results and prepares reports in a distributed environment?
Answer : C
https://docs.splunk.com/Documentation/Splunk/7.3.1/DistSearch/Howuserscancontroldistributedsearches
'From the user standpoint, specifying and running a distributed search is essentially the same as running any other search. Behind the scenes, the search head distributes the query to its search peers, and consolidates the results when presenting them to the user.'
After how many warnings within a rolling 30-day period will a license violation occur with an enforced
Enterprise license?
Answer : D
https://docs.splunk.com/Documentation/Splunk/8.0.5/Admin/Aboutlicenseviolations
'Enterprise Trial license. If you get five or more warnings in a rolling 30 days period, you are in violation of your license. Dev/Test license. If you generate five or more warnings in a rolling 30-day period, you are in violation of your license. Developer license. If you generate five or more warnings in a rolling 30-day period, you are in violation of your license. BUT for Free license. If you get three or more warnings in a rolling 30 days period, you are in violation of your license.'