Courseiva
Back to Splunk Enterprise Certified Architect (SPLK-2002) (SPLK-2002) questions

Scenario-based practice

Hard Difficulty Questions

Practise Splunk Enterprise Certified Architect (SPLK-2002) (SPLK-2002) practice questions — original exam-style scenarios covering every exam domain, with detailed explanations, wrong-answer analysis, and common exam traps.

20
scenario questions
SPLK-2002
exam code
Splunk
vendor

Scenario guide

How to approach hard difficulty questions

These are the questions most candidates get wrong. They require connecting multiple concepts, reading tricky output, or knowing edge-case behaviour that isn't on most study cards. Practising them trains you to operate under uncertainty — a necessary skill on the real exam.

Quick answer

Hard Difficulty Questions questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Related practice questions

Related SPLK-2002 topic practice pages

Scenario questions usually connect to one or more exam topics. Use these links to review the underlying concepts behind the scenario.

Practice set

Practice scenarios

Question 1hardmultiple choice
Full question →

You are configuring Data Model Acceleration on a heavy forwarder. Why is this not a recommended architectural practice?

Question 2hardmultiple choice
Full question →

An indexer cluster is suffering from 'bucket repair' loops. What is the most likely cause related to the bucket lifecycle?

Question 3hardmultiple choice
Full question →

A customer is experiencing 'Search peer [peer-name] is not responding' errors during indexer maintenance. Which configuration parameter in server.conf should be tuned to prevent search failures during rolling restarts?

Question 4hardmultiple choice
Full question →

Which configuration file and stanza are used to define the bucket lifecycle policy for a custom index named 'customer_data'?

Question 5hardmultiple choice
Full question →

A large-scale Splunk deployment is experiencing 'bucket rolling' latency. Upon investigation, you determine that the indexer is waiting for the indexer cluster manager to acknowledge the bucket status. Which indexer clustering setting directly impacts the speed of bucket replication during the rolling process?

Question 6hardmultiple choice
Full question →

If an Indexer Cluster has a replication_factor of 3 and search_factor of 2, how many searchable copies of a bucket are maintained across the cluster?

Question 7hardmultiple choice
Full question →

You need to perform a clean upgrade of an indexer in a cluster. You place the indexer into maintenance mode. What happens to the replication and search factor during this time?

Question 8hardmultiple choice
Full question →

A Splunk administrator needs to identify why a specific search is experiencing high 'Disk Read' wait times. Which tool or log source should be utilized to correlate search IDs with specific disk latency metrics?

Question 9hardmultiple choice
Full question →

A user complains that a search is slow despite having a small time range. The Search Inspector reveals 'event_count' is high, but 'scanned_count' is also high. What is the likely cause?

Question 10hardmultiple choice
Full question →

In a multisite indexer cluster, a bucket with replication factor 3 has its primary copy in Site 1 and secondary copies in Site 2. A network partition occurs. Which setting determines if the indexer will accept new data if it cannot reach the Site 2 indexers?

Question 11hardmultiple choice
Full question →

In a SmartStore architecture, what happens when a bucket is evicted from local cache?

Question 12hardmultiple choice
Full question →

What is the primary architectural trade-off when using very short 'maxHotSpanSecs' values?

Question 13hardmulti select
Full question →

Which TWO of the following are true about Indexer Discovery?

Question 14hardmulti select
Full question →

Which THREE conditions cause a bucket to transition from Warm to Cold?

Question 15hardmultiple choice
Full question →

What is the purpose of the 'homePath.maxDataSizeMB' setting in indexes.conf?

Question 16hardmulti select
Full question →

Which TWO settings are crucial when planning for bucket replication in a clustered environment?

Question 17hardmulti select
Full question →

Which THREE actions occur during the SmartStore bucket lifecycle?

Question 18hardmultiple choice
Full question →

You want to perform a rolling restart of an Indexer Cluster without stopping ingestion. What configuration ensures that indexers remain available?

Question 19hardmultiple choice
Full question →

What is the primary function of the 'search_factor' in an indexer cluster?

Question 20hardmultiple choice
Full question →

You are managing a large Indexer Cluster and need to reduce the time it takes for a new node to catch up. Which setting allows you to limit the amount of bandwidth used during bucket replication?

These SPLK-2002 practice questions are part of Courseiva's free Splunk certification practice question bank. Courseiva provides original exam-style SPLK-2002 questions with detailed explanations, topic-based practice, mock exams, readiness tracking, and study analytics.