New Year Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70percent

Splunk SPLK-3002 Splunk IT Service Intelligence Certified Admin Exam Exam Practice Test

Demo: 28 questions
Total 96 questions

Splunk IT Service Intelligence Certified Admin Exam Questions and Answers

Question 1

Where are KPI search results stored?

Options:

A.

The default index.

B.

KV Store.

C.

Output to a CSV lookup.

D.

The itsi_summary index.

Question 2

What are valid ITSI Glass Table editor capabilities? (Choose all that apply.)

Options:

A.

Creating glass tables.

B.

Correlation search creation.

C.

Service swapping configuration.

D.

Adding KPI metric lanes to glass tables.

Question 3

Which step is required to install ITSI on a single Search Head?

Options:

A.

Untar the ITSI package in /etc/apps

B.

Run splunk_apply shcluster-bundle

C.

Use the Splunk -> Manage Apps Dashboard to download and install.

D.

All of the above.

Question 4

When a KPI's aggregate value is calculated, which function is called?

Options:

A.

stats

B.

tstats

C.

fieldsummary

D.

eval

Question 5

There are two Smart Mode configuration settings that control how fields affect grouping. Which of these is correct?

Options:

A.

Text deviation and category deviation.

B.

Text similarity and category deviation.

C.

Text similarity and category similarity.

D.

Text deviation and category similarity.

Question 6

Which of the following can generate notable events?

Options:

A.

Through ad-hoc search results which get processed by adaptive thresholds.

B.

When two entity aliases have a matching value.

C.

Through scheduled correlation searches which link to their respective services.

D.

Manually selected using the Notable Event Review panel.

Question 7

Which of the following are characteristics of service templates? (select all that apply)

Options:

A.

Service templates can be modified after services are instantiated from it.

B.

Service templates contain KPIs and KPI thresholds.

C.

Service templates can contain specific or generic entity rules.

D.

Service templates contain domain specific dashboards and deep dives.

Question 8

How do you automatically restrict a KPI to only the entities in its service, and generate KPI values for each entity?

Options:

A.

Select “Yes” for both “Split by Entity” and “Filter to Entities in Service”.

B.

Select “No” for “Split by Entity” and “Yes” for “Filter to Entities in Service”.

C.

Select “Yes” for “Split by Entity” and “No” for “Filter to Entities in Service”.

D.

Select “No” for both “Split by Entity” and “Filter to Entities in Service”.

Question 9

Which of the following is a good use case for a Multi-KPI alert?

Options:

A.

Alerting when the values of two or more KPIs go into maintenance mode.

B.

Alerting when the trend of two or more KPIs indicates service failure is imminent.

C.

Alerting when two or more KPIs are deviating from their typical pattern.

D.

Alerting when comparing the values of two or more KPIs indicates an unusual condition is occurring.

Question 10

Which of the following items apply to anomaly detection? (Choose all that apply.)

Options:

A.

Use AD on KPIs that have an unestablished baseline of data points. This allows the ML pattern to perform it’s magic.

B.

A minimum of 24 hours of data is needed for anomaly detection, and a minimum of 4 entities for cohesive analysis.

C.

Anomaly detection automatically generates notable events when KPI data diverges from the pattern.

D.

There are 3 types of anomaly detection supported in ITSI: adhoc, trending, and cohesive.

Question 11

Which ITSI components are required before a module can be created?

Options:

A.

One or more entity import saved searches.

B.

One or more services with KPIs and their associated base searches.

C.

One or more datamodels.

D.

One or more correlation searches and their associated entities.

Question 12

Which of the following describes enabling smart mode for an aggregation policy?

Options:

A.

Configure –> Policies –> Smart Mode –> Enable, select “fields”, click “Save”

B.

Enable grouping in Notable Event Review, select “Smart Mode”, select “fields”, and click “Save”

C.

Edit the aggregation policy, enable smart mode, select fields to analyze, click “Save”

D.

Edit the notable event view, enable smart mode, select “fields”, and click “Save”

Question 13

Which of the following applies when configuring time policies for KPI thresholds?

Options:

A.

A person can only configure 24 policies, one for each hour of the day.

B.

They are great if you expect normal behavior at 1:00 to be different than normal behavior at 5:00

C.

If a person expects a KPI to change significantly through a cycle on a daily basis, don’t use it.

D.

It is possible for multiple time policies to overlap.

Question 14

What happens when an anomaly is detected?

Options:

A.

A separate correlation search needs to be created in order to see it.

B.

A SNMP trap will be sent.

C.

An anomaly alert will appear in core splunk, in index=main.

D.

An anomaly alert will appear as a notable event in Episode Review.

Question 15

What should be considered when onboarding data into a Splunk index, assuming that ITSI will need to use this data?

Options:

A.

Use | stats functions in custom fields to prepare the data for KPI calculations.

B.

Check if the data could leverage pre-built KPIs from modules, then use the correct TA to onboard the data.

C.

Make sure that all fields conform to CIM, then use the corresponding module to import related services.

D.

Plan to build as many data models as possible for ITSI to leverage

Question 16

Which of the following is a best practice for identifying the most effective services with which to start an iterative ITSI deployment?

Options:

A.

Only include KPIs if they will be used in multiple services.

B.

Analyze the business to determine the most critical services.

C.

Focus on low-level services.

D.

Define a large number of key services early.

Question 17

Which of the following services often has KPIs but no entities?

Options:

A.

Security Service.

B.

Network Service.

C.

Business Service.

D.

Technical Service.

Question 18

What is the default importance value for dependent services’ health scores?

Options:

A.

11

B.

1

C.

Unassigned

D.

10

Question 19

When creating a custom deep dive, what color are services/KPIs in maintenance mode within the topology view?

Options:

A.

Gray

B.

Purple

C.

Gear Icon

D.

Blue

Question 20

Which of the following statements describe default glass tables in ITSI?

Options:

A.

The Service Health Score default glass table.

B.

There is one default glass table per service.

C.

There is one service template default glass table.

D.

There are no default glass tables.

Question 21

Which scenario would benefit most by implementing ITSI?

Options:

A.

Monitoring of business services functionality.

B.

Monitoring of system hardware.

C.

Monitoring of system process statuses

D.

Monitoring of retail sales metrics.

Question 22

Buttercup Retail sells t‑shirts both online and in stores. The IT Operations team is effectively monitoring the digital infrastructure. However, the executive leadership has expressed frustration in understanding what the related business impacts are of IT incidents.

Which of the following entities would give Buttercup Retail executives the most impactful visibility?

Options:

A.

store, product, payment type

B.

store, season, customer age

C.

host, browser type, software version

D.

host, network interface, datacenter

Question 23

What effects does the KPI importance weight of 11 have on the overall health score of a service?

Options:

A.

At least 10% of the KPIs will go critical.

B.

Importance weight is unused for health scoring.

C.

The service will go critical.

D.

It is a minimum health indicator KPI.

Question 24

Which of the following describes default deep dives?

Options:

A.

Are manually generated and can be accessed via the Service Analyzer.

B.

Include all KPIs of all services.

C.

Are auto-generated and can be accessed via the Service Analyzer.

D.

Include health scores of all services.

Question 25

Which of the following are characteristics of ITSI service dependencies? (select all that apply)

Options:

A.

If a primary service has a dependent service KPI and the KPI's importance level is changed, the dependency is broken.

B.

It is best practice to use the dependent service's built-in 'ServiceHealthScore' KPI to reflect impact to the primary service.

C.

Setting the dependent service KPI importance level will be treated as any other KPI in the primary service's health score.

D.

Impactful dependent services should only be configured to one primary service to avoid false negatives in Multi KPI Alerts.

Question 26

When must a service define entity rules?

Options:

A.

If the intention is for the KPIs in the service to filter to only entities assigned to the service.

B.

To enable entity cohesion anomaly detection.

C.

If some or all of the KPIs in the service will be split by entity.

D.

If the intention is for the KPIs in the service to have different aggregate vs. entity KPI values.

Question 27

Which is the least permissive role required to modify default deep dives?

Options:

A.

itoa_analyst

B.

admin

C.

power

D.

itoa_admin

Question 28

How can admins manually control groupings of notable events?

Options:

A.

Correlation searches.

B.

Multi-KPI alerts.

C.

notable_event_grouping.conf

D.

Aggregation policies.

Demo: 28 questions
Total 96 questions