Black Friday Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70special

Splunk SPLK-3002 Splunk IT Service Intelligence Certified Admin Exam Exam Practice Test

Page: 1 / 9
Total 90 questions

Splunk IT Service Intelligence Certified Admin Exam Questions and Answers

Testing Engine

  • Product Type: Testing Engine
$37.5  $124.99

PDF Study Guide

  • Product Type: PDF Study Guide
$33  $109.99
Question 1

Which of the following statements is accurate when using multiple policies?

Options:

A.

New policies are applied after the default policy.

B.

Policy processing is applied in a defined order.

C.

An event can be processed by only a single policy.

D.

New policies are applied before the default policy.

Question 2

Besides creating notable events, what are the default alert actions a correlation search can execute? (Choose all that apply.)

Options:

A.

Ping a host.

B.

Send email.

C.

Include in RSS feed.

D.

Run a script.

Question 3

What effects does the KPI importance weight of 11 have on the overall health score of a service?

Options:

A.

At least 10% of the KPIs will go critical.

B.

Importance weight is unused for health scoring.

C.

The service will go critical.

D.

It is a minimum health indicator KPI.

Question 4

When working with a notable event group in the Notable Events Review dashboard, which of the following can be set at the individual or group level?

Options:

A.

Service, status, owner.

B.

Severity, status, owner.

C.

Severity, comments, service.

D.

Severity, status, service.

Question 5

Which of the following actions can be performed with a deep dive?

Options:

A.

Create a Multi-KPI alert from the deep dive's current state to warn of similar situations in the future.

B.

Create a predictive analysis model from the deep dive to warn of future service degradation.

C.

Create an anomaly detection alert to show when the same pattern begins in the future.

D.

Create a custom service analyzer from selected deep dive lanes.

Question 6

What is the minimum number of entities a KPI must be split by in order to use Entity Cohesion anomaly detection?

Options:

A.

3

B.

4

C.

5

D.

2

Question 7

Which of the following are the default ports that must be configured on Splunk to use ITSI?

Options:

A.

SplunkWeb (8405), SplunkD (8519), and HTTP Collector (8628)

B.

SplunkWeb (8089), SplunkD (8088), and HTTP Collector (8000)

C.

SplunkWeb (8000), SplunkD (8089), and HTTP Collector (8088)

D.

SplunkWeb (8088), SplunkD (8089), and HTTP Collector (8000)

Question 8

When a KPI's aggregate value is calculated, which function is called?

Options:

A.

stats

B.

tstats

C.

fieldsummary

D.

eval

Question 9

Which anomaly detection algorithm is included within ITSI?

Options:

A.

Entity cohesion

B.

Standard deviation

C.

Linear regression

D.

Infantile regression

Question 10

How can Service Now incidents be created automatically when a Multi-KPI alert triggers? (select all that apply)

Options:

A.

By creating a custom etc/apps/SA-lTOA/workflow_rules. conf

B.

By linking Entities to Service-Now configuration items.

C.

By creating a notable event aggregation policy with a SNOW incident action.

D.

By editing the associated correlation search and specifying an alert action.

Question 11

Which views would help an analyst identify that a memory usage KPI is going critical? (select all that apply)

Options:

A.

Memory KPI in a glass table.

B.

Memory panel of the OS Host Details view in the Operating System module.

C.

Memory swim lane in a Deep Dive.

D.

Service & KPI tiles in the Service Analyzer.

Question 12

Where are KPI search results stored?

Options:

A.

The default index.

B.

KV Store.

C.

Output to a CSV lookup.

D.

The itsi_summary index.

Question 13

In distributed search, which components need to be installed on instances other than the search head?

Options:

A.

SA-IndexCreation and SA-ITSI-Licensechecker on indexers.

B.

SA-IndexCreation and SA-ITOA on indexers; SA-ITSI-Licensechecker and SA-UserAccess on the license master.

C.

SA-IndexCreation on idexers; SA-ITSI-Licensechecker and SA-UserAccess on the license master.

D.

SA-ITSI-Licensechecker on indexers.

Question 14

When troubleshooting KPI search performance, which search names in job activity identify base searches?

Options:

A.

Indicator - XXXX - Base Search

B.

Indicator - Shared - xxxx - ITSI Search

C.

Indicator - Base - xxxx - ITSI Search

D.

Indicator - Base - XXXX - Shared Search

Question 15

ITSI Saved Search Scheduling is configured to use realtime_schedule = 0. Which statement is accurate about this configuration?

Options:

A.

If this value is set to 0, the scheduler bases its determination of the next scheduled search execution time on the current time.

B.

If this value is set to 0, the scheduler bases its determination of the next scheduled search on the last search execution time.

C.

If this value is set to 0, the scheduler may skip scheduled execution periods.

D.

If this value is set to 0, the scheduler might skip some execution periods to make sure that the scheduler is executing the searches running over the most recent time range.

Question 16

After a notable event has been closed, how long will the meta data for that event remain in the KV Store by default?

Options:

A.

6 months.

B.

9 months.

C.

1 year.

D.

3 months.

Question 17

Which of the following applies when configuring time policies for KPI thresholds?

Options:

A.

A person can only configure 24 policies, one for each hour of the day.

B.

They are great if you expect normal behavior at 1:00 to be different than normal behavior at 5:00

C.

If a person expects a KPI to change significantly through a cycle on a daily basis, don’t use it.

D.

It is possible for multiple time policies to overlap.

Question 18

Which of the following is an advantage of an adaptive time threshold?

Options:

A.

Automatically alerting when KPI value patterns change over time.

B.

Automatically adjusting thresholds as normal KPI values change over time.

C.

Automatically adjusting to holiday schedules.

D.

Automatically predicting future degradation of KPI values over time.

Question 19

Which of the following is a best practice for identifying the most effective services with which to start an iterative ITSI deployment?

Options:

A.

Only include KPIs if they will be used in multiple services.

B.

Analyze the business to determine the most critical services.

C.

Focus on low-level services.

D.

Define a large number of key services early.

Question 20

What is the main purpose of the service analyzer?

Options:

A.

Display a list of All Services and Entities.

B.

Trigger external alerts based on threshold violations.

C.

Allow Analysts to add comments to Alerts.

D.

Monitor overall Service and KPI status.

Question 21

Which capabilities are enabled through “teams”?

Options:

A.

Teams allow searches against the itsi_summary index.

B.

Teams restrict notable event alert actions.

C.

Teams restrict searches against the itsi_notable_audit index.

D.

Teams allow restrictions to service content in UI views.

Question 22

Which of the following describes entities? (Choose all that apply.)

Options:

A.

Entities must be IT devices, such as routers and switches, and must be identified by either IP value, host name, or mac address.

B.

An abstract (pseudo/logical) entity can be used to split by for a KPI, although no entity rules or filtering can be used to limit data to a specific service.

C.

Multiple entities can share the same alias value, but must have different role values.

D.

To automatically restrict the KPI to only the entities in a particular service, select “Filter to Entities in Service”.

Question 23

Which index will contain useful error messages when troubleshooting ITSI issues?

Options:

A.

_introspection

B.

_internal

C.

itsi_summary

D.

itsi_notable_audit

Question 24

Which of the following describes a way to delete multiple duplicate entities in ITSI?

Options:

A.

Via c CSV upload.

B.

Via the entity lister page.

C.

Via a search using the | deleteentity command.

D.

All of the above.

Question 25

Which of the following are deployment recommendations for ITSI? (Choose all that apply.)

Options:

A.

Deployments often require an increase of hardware resources above base Splunk requirements.

B.

Deployments require a dedicated ITSI search head.

C.

Deployments may increase the number of required indexers based on the number of KPI searches.

D.

Deployments should use fastest possible disk arrays for indexers.

Question 26

Which of the following items describe ITSI Deep Dive capabilities? (Choose all that apply.)

Options:

A.

Comparing a service’s notable events over a time period.

B.

Visualizing one or more Service KPIs values by time.

C.

Examining and comparing alert levels for KPIs in a service over time.

D.

Comparing swim lane values for a slice of time.

Question 27

How do you automatically restrict a KPI to only the entities in its service, and generate KPI values for each entity?

Options:

A.

Select “Yes” for both “Split by Entity” and “Filter to Entities in Service”.

B.

Select “No” for “Split by Entity” and “Yes” for “Filter to Entities in Service”.

C.

Select “Yes” for “Split by Entity” and “No” for “Filter to Entities in Service”.

D.

Select “No” for both “Split by Entity” and “Filter to Entities in Service”.

Page: 1 / 9
Total 90 questions