Exam SPLK-3003 All QuestionsBrowse all questions from this exam
Question 77

A working search head cluster has been set up and used for 6 months with just the native/local Splunk user authentication method. In order to integrate the search heads with an external Active Directory server using LDAP, which of the following statements represents the most appropriate method to deploy the configuration to the servers?

    Correct Answer: A

    The most appropriate method for deploying the configuration to integrate a search head cluster with an external Active Directory server using LDAP is to configure the integration in a base configuration app located in the shcluster-apps directory on the search head deployer. After configuring, the deployment can be done to the search heads using the 'splunk apply shcluster-bundle' command. This method ensures consistency across all search heads in the cluster and simplifies management by using the deployer to push the configuration.

Discussion
chuchoneitorOption: A

I think the correct one is A

RedtonyeahOption: A

A is the correct

M9201715Option: A

Both A and C would work, and from the Services Core Implementation course notes it says that the UI is helpful for LDAP integration because "UI gives useful validation assistance" (p. 19). However, the base config for search heads has all of the LDAP parameters in it, and that's how we had to do it in the Core Implementation bootcamp. So I think A is the better choice

D71

For a single host I would agree that he UI is the preferred technique, but in a cluster, use an app and push it from the deployer. If a DEV system is available, they the UI can be used to create and validate the authentication.conf file.

cornripperOption: A

A is correct. You should have done this in the Core Implementation labs.

matsumoOption: C

C is the correct. It is recommended that LDAP settings be configured through the UI.