Weekend Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70special

Splunk SPLK-3002 Splunk IT Service Intelligence Certified Admin Exam Exam Practice Test

Page: 1 / 10
Total 96 questions

Splunk IT Service Intelligence Certified Admin Exam Questions and Answers

Testing Engine

  • Product Type: Testing Engine
$37.5  $124.99

PDF Study Guide

  • Product Type: PDF Study Guide
$33  $109.99
Question 1

Which of the following are deployment recommendations for ITSI? (Choose all that apply.)

Options:

A.

Deployments often require an increase of hardware resources above base Splunk requirements.

B.

Deployments require a dedicated ITSI search head.

C.

Deployments may increase the number of required indexers based on the number of KPI searches.

D.

Deployments should use fastest possible disk arrays for indexers.

Question 2

Which of the following items describe ITSI Deep Dive capabilities? (Choose all that apply.)

Options:

A.

Comparing a service’s notable events over a time period.

B.

Visualizing one or more Service KPIs values by time.

C.

Examining and comparing alert levels for KPIs in a service over time.

D.

Comparing swim lane values for a slice of time.

Question 3

Which of the following describes a way to delete multiple duplicate entities in ITSI?

Options:

A.

Via c CSV upload.

B.

Via the entity lister page.

C.

Via a search using the | deleteentity command.

D.

All of the above.

Question 4

In distributed search, which components need to be installed on instances other than the search head?

Options:

A.

SA-IndexCreation and SA-ITSI-Licensechecker on indexers.

B.

SA-IndexCreation and SA-ITOA on indexers; SA-ITSI-Licensechecker and SA-UserAccess on the license master.

C.

SA-IndexCreation on idexers; SA-ITSI-Licensechecker and SA-UserAccess on the license master.

D.

SA-ITSI-Licensechecker on indexers.

Question 5

What is the minimum number of entities a KPI must be split by in order to use Entity Cohesion anomaly detection?

Options:

A.

3

B.

4

C.

5

D.

2

Question 6

Which of the following is the best use case for configuring a Multi-KPI Alert?

Options:

A.

Comparing content between two notable events.

B.

Using machine learning to evaluate when data falls outside of an expected pattern.

C.

Comparing anomaly detection between two KPIs.

D.

Raising an alert when one or more KPIs indicate an outage is occurring.

Question 7

Which of the following is a good use case for creating a custom module?

Options:

A.

Modules are required to create entity and service import searches.

B.

Modules are required to be able to create custom visualizations for deep dives.

C.

Making it easy to migrate KPI base searches and related visualizations to other ITSI installations.

D.

Creating a service template to make it easy to automatically create new services during service and entity import.

Question 8

Which of the following best describes a default deep dive?

Options:

A.

It initially shows the health scores for all services.

B.

It initially shows the highest importance KPIs.

C.

It initially shows all of the KPIs for a selected service.

D.

It initially shows all the entity swim lanes.

Question 9

Which index will contain useful error messages when troubleshooting ITSI issues?

Options:

A.

_introspection

B.

_internal

C.

itsi_summary

D.

itsi_notable_audit

Question 10

Which of the following describes default deep dives?

Options:

A.

Are manually generated and can be accessed via the Service Analyzer.

B.

Include all KPIs of all services.

C.

Are auto-generated and can be accessed via the Service Analyzer.

D.

Include health scores of all services.

Question 11

Besides creating notable events, what are the default alert actions a correlation search can execute? (Choose all that apply.)

Options:

A.

Ping a host.

B.

Send email.

C.

Include in RSS feed.

D.

Run a script.

Question 12

Which of the following is a recommended best practice for ITSI installation?

Options:

A.

ITSI should not be installed on search heads that have Enterprise Security installed.

B.

Before installing ITSI, make sure the Common Information Model (CIM) is installed.

C.

Install the Machine Learning Toolkit app if anomaly detection must be configured.

D.

Install ITSI on one search head in a search head cluster and migrate the configuration bundle to other search heads.

Question 13

Which of the following is a characteristic of base searches?

Options:

A.

Search expression, entity splitting rules, and thresholds are configured at the base search level.

B.

It is possible to filter to entities assigned to the service for calculating the metrics for the service’s KPIs.

C.

The fewer KPIs that share a common base search, the more efficiency a base search provides, and anomaly detection is more efficient.

D.

The base search will execute whether or not a KPI needs it.

Question 14

When changing a service template, which of the following will be added to linked services by default?

Options:

A.

Thresholds.

B.

Entity Rules.

C.

New KPIs.

D.

Health score.

Question 15

How can Service Now incidents be created automatically when a Multi-KPI alert triggers? (select all that apply)

Options:

A.

By creating a custom etc/apps/SA-lTOA/workflow_rules. conf

B.

By linking Entities to Service-Now configuration items.

C.

By creating a notable event aggregation policy with a SNOW incident action.

D.

By editing the associated correlation search and specifying an alert action.

Question 16

In Episode Review, what is the result of clicking an episode’s Acknowledge button?

Options:

A.

Assign the current user as owner.

B.

Change status from New to Acknowledged.

C.

Change status from New to In Progress and assign the current user as owner.

D.

Change status from New to Acknowledged and assign the current user as owner.

Question 17

To use Adaptive Threshholding, what is the minimum requirement for a set of KPI data?

Options:

A.

14 days old.

B.

7 days old.

C.

30 days old.

D.

10 days old.

Question 18

Which deep dive swim lane type does not require writing SPL?

Options:

A.

Event lane.

B.

Automatic lane.

C.

Metric lane.

D.

KPI lane.

Question 19

What should be considered when onboarding data into a Splunk index, assuming that ITSI will need to use this data?

Options:

A.

Use | stats functions in custom fields to prepare the data for KPI calculations.

B.

Check if the data could leverage pre-built KPIs from modules, then use the correct TA to onboard the data.

C.

Make sure that all fields conform to CIM, then use the corresponding module to import related services.

D.

Plan to build as many data models as possible for ITSI to leverage

Question 20

Which scenario would benefit most by implementing ITSI?

Options:

A.

Monitoring of business services functionality.

B.

Monitoring of system hardware.

C.

Monitoring of system process statuses

D.

Monitoring of retail sales metrics.

Question 21

Which of the following statements is accurate when using multiple policies?

Options:

A.

New policies are applied after the default policy.

B.

Policy processing is applied in a defined order.

C.

An event can be processed by only a single policy.

D.

New policies are applied before the default policy.

Question 22

When a KPI's aggregate value is calculated, which function is called?

Options:

A.

stats

B.

tstats

C.

fieldsummary

D.

eval

Question 23

What are valid ITSI Glass Table editor capabilities? (Choose all that apply.)

Options:

A.

Creating glass tables.

B.

Correlation search creation.

C.

Service swapping configuration.

D.

Adding KPI metric lanes to glass tables.

Question 24

Which of the following applies when configuring time policies for KPI thresholds?

Options:

A.

A person can only configure 24 policies, one for each hour of the day.

B.

They are great if you expect normal behavior at 1:00 to be different than normal behavior at 5:00

C.

If a person expects a KPI to change significantly through a cycle on a daily basis, don’t use it.

D.

It is possible for multiple time policies to overlap.

Question 25

Buttercup Retail sells t‑shirts both online and in stores. The IT Operations team is effectively monitoring the digital infrastructure. However, the executive leadership has expressed frustration in understanding what the related business impacts are of IT incidents.

Which of the following entities would give Buttercup Retail executives the most impactful visibility?

Options:

A.

store, product, payment type

B.

store, season, customer age

C.

host, browser type, software version

D.

host, network interface, datacenter

Question 26

What is the default importance value for dependent services’ health scores?

Options:

A.

11

B.

1

C.

Unassigned

D.

10

Question 27

When in maintenance mode, which of the following is accurate?

Options:

A.

Once the window is over, KPIs and notable events will begin to be generated again.

B.

KPIs are shown in blue while in maintenance mode.

C.

Maintenance mode slots are scheduled on a per hour basis.

D.

Service health scores and KPI events are deleted until the window is over.

Question 28

Which ITSI components are required before a module can be created?

Options:

A.

One or more entity import saved searches.

B.

One or more services with KPIs and their associated base searches.

C.

One or more datamodels.

D.

One or more correlation searches and their associated entities.

Page: 1 / 10
Total 96 questions