SPLK-2002 Deployment Architecture And Clustering Practice Question
When implementing a multisite indexer cluster, what happens if the cluster master becomes unreachable for a short duration?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Indexer peers continue to accept and index data
In an indexer cluster, search heads and indexer peers can continue to operate and process data even if the CM is offline, though bucket replication might be paused.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
All indexing stops immediately
Why it's wrong here
Indexing continues unless the peers themselves fail.
- ✗
Search heads stop returning results
Why it's wrong here
Search heads utilize the last known cluster map.
- ✗
Data replication across sites is forced immediately
Why it's wrong here
Replication is managed by the CM, so it halts until the CM returns.
- ✓
Indexer peers continue to accept and index data
Why this is correct
Peers maintain local autonomy for data ingestion during CM downtime.
About these practice questions
This SPLK-2002 question is part of Courseiva's 185-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed August 2026 · checked against the official Splunk exam blueprint
This SPLK-2002 practice question is part of Courseiva's free Splunk certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SPLK-2002 exam.