Splunk Enterprise Certified Architect (SPLK-2002) Practice Questions
Domain coverage
- Introduction (2%)
- Project Requirements (5%)
- Infrastructure Planning — Index Design (5%)
- Infrastructure Planning — Resource Planning (7%)
- Clustering Overview (5%)
- Forwarder and Deployment Best Practices (6%)
- Performance Monitoring and Tuning (5%)
- Splunk Troubleshooting Methods and Tools (5%)
- Clarifying the Problem (5%)
- Licensing and Crash Problems (5%)
- Configuration Problems (5%)
- Search Problems (5%)
- Deployment Problems (5%)
- Large-scale Splunk Deployment Overview (5%)
- Single-site Indexer Cluster (5%)
- Multisite Indexer Cluster (5%)
- Indexer Cluster Management & Admin (7%)
- Search Head Cluster (5%)
- Search Head Cluster Management & Admin (5%)
- KV Store Collection & Lookup Management (3%)
Sample Questions (13 of 125 shown)
- Raw data = 15 GB per day
- Index files = 35 GB per day
- Replication Factor (RF) = 2
- Search Factor (SF) = 2
You've viewed 3 of 125 questions. Start the free practice exam to answer all questions with instant feedback.
Exam overview
At the pinnacle of the Splunk certification ladder, the Splunk Enterprise Certified Architect (SPLK-2002) credential validates your ability to design, deploy, and troubleshoot large-scale distributed Splunk environments with indexer clusters, search head clusters, and multisite replication. Administered through Pearson VUE, this 90-minute exam requires a scaled passing score of 700/1000 and mandates both an active Splunk Core Certified Power User (SPLK-1002) and Splunk Enterprise Certified Admin (SPLK-1003) certification as prerequisites.
To register, candidates must also complete the Architecting Splunk Enterprise Deployments, Troubleshooting Splunk Enterprise, and Splunk Enterprise Cluster Administration courses on the STEP portal, plus pass the rigorous Splunk Enterprise Deployment Practical Lab — a multi-day hands-on lab assessment. Splunk recommends at least 6 to 12 months of active experience designing and troubleshooting distributed Splunk architectures in enterprise environments, paired with deep familiarity with the Capacity Planning Manual, Managing Indexers and Clusters of Indexers, and Admin Manual.
The SPLK-2002 blueprint spans 20 domains covering the full architect lifecycle. Heavy-weight areas include Resource Planning (7%) with IOPS and storage sizing for Enterprise Security and ITSI, Indexer Cluster Management & Admin (7%) including peer offline states and decommissioning, Forwarder and Deployment Best Practices (6%) with Heavy vs. Universal Forwarder tiers, and Multisite Indexer Cluster (5%) testing site replication factors ($SRF$) and site search factors ($SSF$). Foundational troubleshooting domains cover btool, splunkd.log, and internal indexes for configuration debug (5%) plus the Job Inspector for search performance bottlenecks (5%).
For candidates preparing for the SPLK-2002 exam, our practice materials cover all 20 domains in the same proportions as the real test — from Project Requirements collection and Index Design with SmartStore storage estimation through Resource Planning with IOPS/capacity calculations and Enterprise Security sizing, Clustering Overview with Search Head Cluster foundational requirements, Forwarder tier design with Deployment Server configuration management, Performance Monitoring via limits.conf and props.conf tuning, Troubleshooting with btool, diag files, and internal indexes (_internal, _introspection), Licensing and Crash diagnosis, Configuration debug with file precedence layouts, Search problem isolation using the Job Inspector, Single-site and Multisite Indexer Clusters with $SRF$/$SSF$ factors, Indexer Cluster Management with peer offline and decommission workflows, Search Head Cluster captaincy and Deployer configuration, and KV Store replication and lookup synchronization. Each online practice question includes a detailed answer explanation that walks through the architectural reasoning and cluster mechanics, while the downloadable PDF packages the same question bank for offline review during commutes or in environments without stable internet.
Start your free SPLK-2002 practice test today and master distributed Splunk architecture, clustering, and troubleshooting.
Official Exam Domains & Weighting
To successfully pass the SPLK-2002 exam, candidates must master the following core domains:- Domain 1: Introduction (2%) — Describing a deployment plan and defining the deployment process phases.
- Domain 2: Project Requirements (5%) — Identifying critical information about environment, volume, users, and business requirements, and applying checklists to collect requirements.
- Domain 3: Infrastructure Planning — Index Design (5%) — Designing and sizing indexes, estimating non-SmartStore storage requirements, and identifying relevant app impact.
- Domain 4: Infrastructure Planning — Resource Planning (7%) — Sizing considerations for disk IOPS and capacity, reference hardware for Splunk components, Enterprise Security/ITSI topology, and security/integrity measures.
- Domain 5: Clustering Overview (5%) — Understanding non-SmartStore storage/disk usage in clusters and Search Head Clustering (SHC) foundational requirements.
- Domain 6: Forwarder and Deployment Best Practices (6%) — Designing forwarder tiers (Heavy vs. Universal, load balancing) and managing configuration via Deployment Server.
- Domain 7: Performance Monitoring and Tuning (5%) — Optimizing performance via
limits.conf, managing bucket sizing inindexes.conf, tuningprops.conffor event breaking/timestamping, and search performance optimization.
- Domain 8: Splunk Troubleshooting Methods and Tools (5%) — Using diagnostic resources (
diagfiles) and native system tools.
- Domain 9: Clarifying the Problem (5%) — Tracking issues via
btool,splunkd.log, and identifying internal indexes (_internal,_introspection).
- Domain 10: Licensing and Crash Problems (5%) — Diagnosing license violations, pool alerts, master setup issues, and crash symptoms/dumps.
- Domain 11: Configuration Problems (5%) — Debugging inputs configuration, stanza syntax flaws, and file precedence layouts.
- Domain 12: Search Problems (5%) — Pinpointing slow or stuck searches and using the Job Inspector to find performance bottlenecks.
- Domain 13: Deployment Problems (5%) — Troubleshooting data forwarding discrepancies and client-to-Deployment Server connectivity issues.
- Domain 14: Large-scale Splunk Deployment Overview (5%) — Understanding server roles within clusters and managing License Master in highly available or clustered topologies.
- Domain 15: Single-site Indexer Cluster (5%) — Configuring and spinning up single-site indexer clusters with Manager, Peer, and Search Head nodes.
- Domain 16: Multisite Indexer Cluster (5%) — Configuring multi-site topologies with site replication factors ($SRF$), site search factors ($SSF$), and cluster migration/upgrade paths.
- Domain 17: Indexer Cluster Management & Admin (7%) — Managing storage utilization, handling peer offline states and decommissioning, and master app bundle pushes.
- Domain 18: Search Head Cluster (5%) — Deploying and configuring a dynamic Search Head Cluster (SHC) architecture.
- Domain 19: Search Head Cluster Management & Admin (5%) — Using the Deployer to push configurations, managing captaincy transfer, and adding/decommissioning cluster members.
- Domain 20: KV Store Collection & Lookup Management (3%) — Handling KV Store replication and lookup synchronization across clustered nodes.
What Our Customers Say 125 verified reviews
The progress tracking feature for SPLK-2002 really motivated me. Seeing my improvement over time was incredibly satisfying.
The way the SPLK-2002 questions are broken down by domain is great. Let me focus on my weak spots without wasting time.
Ended up buying three different SPLK-2002 prep resources and this was by far the most helpful one. Don’t waste money on others.
Used the SPLK-2002 test bank for two weeks before my exam date. Felt very prepared going in and the results showed.
I bought access for the SPLK-2002 exam as a gift for my brother. He passed on his first try and said the questions were spot-on.
Honestly, I wouldn’t have passed SPLK-2002 without these. The explanations actually teach you instead of just giving the answer.
Frequently Asked Questions
Unlike lower-level exams, SPLK-2002 tests configuration precedence (btool), hardware math calculations (IOPS, storage limits under replication factors), and cluster state transitions (e.g., peer offline vs. decommission). Understanding .conf file behavior under high-availability constraints is crucial. Our practice materials include cluster state and capacity calculation questions.
The Splunk Enterprise Certified Architect certification is valid for 3 years from issuance. You can recertify either by passing a higher-level exam (such as Splunk Core Certified Consultant) or by retaking the SPLK-2002 exam before expiration.
A 7-day wait for the second attempt, 14 days for the third, and longer cooling-off periods for subsequent attempts. Each retake requires the full $130 fee.
Scaled scoring is used across all forms. You receive an immediate pass/fail printout from Pearson VUE showing performance percentages per domain.
Our mock exam covers all 20 domains with the same weight distribution as the real test — from IOPS/capacity planning calculations and single-site/multisite indexer cluster topology with $SRF$/$SSF$ factors through SHC captaincy mechanics, Deployment Server configuration, btool configuration debugging, Job Inspector search bottleneck analysis, and KV Store replication across clustered nodes. Each question includes detailed architectural reasoning.
Yes. The downloadable PDF contains the same question bank as the online version, including answer explanations covering indexer cluster peer state transitions, SHC Deployer configuration and captaincy transfer, btool precedence debugging, limits.conf and indexes.conf performance tuning, Job Inspector execution cost analysis, and KV Store lookup synchronization. It is designed for offline study.
Candidates frequently report Multisite Indexer Cluster with $SRF$/$SSF$ calculations, Resource Planning with IOPS/storage math, and Indexer Cluster Management (peer offline vs. decommission) as the most demanding. The troubleshooting domains — especially Configuration Problems with file precedence and Search Problems with the Job Inspector — also require significant preparation. Our practice questions include focused drills on these high-difficulty areas.