Splunk Enterprise Security Certified Analyst — Question 48

A customer has asked for a five-node search head cluster (SHC), but does not have the storage budget to use a replication factor greater than 2. They would like to understand what might happen in terms of the users' ability to view historic scheduled search results if they log onto a search head which doesn't contain one of the 2 copies of a given search artifact.
Which of the following statements best describes what would happen in this scenario?

Answer options

Correct answer: A

Explanation

The correct answer, A, is accurate because the search head will proxy the artifact from another search head that holds it, ensuring the user can access the required search results. Option B is incorrect as the user can still access the results through proxying. Option C is misleading because a restart is unnecessary for synchronization, and D is incorrect as the apply shcluster-bundle command is not needed for this scenario.