New Year Sale Discount Flat 70% Offer - Ends in 0d 00h 00m 00s - Coupon code: 70diswrap

Splunk SPLK-3002 Dumps

Page: 1 / 10
Total 96 questions

Splunk IT Service Intelligence Certified Admin Exam Questions and Answers

Question 1

Which of the following is a good use case regarding defining entities for a service?

Options:

A.

Automatically associate entities to services using multiple entity aliases.

B.

All of the entities have the same identifying field name.

C.

Being able to split a CPU usage KPI by host name.

D.

KPI total values are aggregated from multiple different category values in the source events.

Question 2

Which of the following can generate notable events?

Options:

A.

Through ad-hoc search results which get processed by adaptive thresholds.

B.

When two entity aliases have a matching value.

C.

Through scheduled correlation searches which link to their respective services.

D.

Manually selected using the Notable Event Review panel.

Question 3

Which of the following describes a way to delete multiple duplicate entities in ITSI?

Options:

A.

Via c CSV upload.

B.

Via the entity lister page.

C.

Via a search using the | deleteentity command.

D.

All of the above.

Question 4

Which of the following is a valid type of Multi-KPI Alert?

Options:

A.

Score over composite.

B.

Value over time.

C.

Status over time.

D.

Rise over run.

Question 5

Which material would be least useful while planning and designing a service tree for an application team within the company?

Options:

A.

A technical diagram of the application and its interconnections.

B.

An organizational chart of the company.

C.

A report of historical incidents and root cause analysis from the team.

D.

A service topology from an IT Service Management tool.

Question 6

Besides creating notable events, what are the default alert actions a correlation search can execute? (Choose all that apply.)

Options:

A.

Ping a host.

B.

Send email.

C.

Include in RSS feed.

D.

Run a script.

Question 7

What is the main purpose of the service analyzer?

Options:

A.

Display a list of All Services and Entities.

B.

Trigger external alerts based on threshold violations.

C.

Allow Analysts to add comments to Alerts.

D.

Monitor overall Service and KPI status.

Question 8

When must a service define entity rules?

Options:

A.

If the intention is for the KPIs in the service to filter to only entities assigned to the service.

B.

To enable entity cohesion anomaly detection.

C.

If some or all of the KPIs in the service will be split by entity.

D.

If the intention is for the KPIs in the service to have different aggregate vs. entity KPI values.

Question 9

What is the minimum number of entities a KPI must be split by in order to use Entity Cohesion anomaly detection?

Options:

A.

3

B.

4

C.

5

D.

2

Question 10

When changing a service template, which of the following will be added to linked services by default?

Options:

A.

Thresholds.

B.

Entity Rules.

C.

New KPIs.

D.

Health score.

Question 11

Which anomaly detection algorithm is included within ITSI?

Options:

A.

Entity cohesion

B.

Standard deviation

C.

Linear regression

D.

Infantile regression

Question 12

Which scenario would benefit most by implementing ITSI?

Options:

A.

Monitoring of business services functionality.

B.

Monitoring of system hardware.

C.

Monitoring of system process statuses

D.

Monitoring of retail sales metrics.

Question 13

Which of the following is a good use case for creating a custom module?

Options:

A.

Modules are required to create entity and service import searches.

B.

Modules are required to be able to create custom visualizations for deep dives.

C.

Making it easy to migrate KPI base searches and related visualizations to other ITSI installations.

D.

Creating a service template to make it easy to automatically create new services during service and entity import.

Question 14

When installing ITSI to support a Distributed Search Architecture, which of the following items apply? (Choose all that apply.)

Options:

A.

Copy SA-IndexCreation to all indexers.

B.

Copy SA-IndexCreation to the etc/apps directory on the index cluster master node.

C.

Extract installer package into etc/apps directory of the cluster deployer node.

D.

Extract ITSI app package into etc/apps directory of search head.

Question 15

For which ITSI function is it a best practice to use a 15-30 minute time buffer?

Options:

A.

Correlation searches.

B.

Adaptive thresholding.

C.

Maintenance windows

D.

Anomaly detection.

Question 16

Which of the following is part of setting up a new aggregation policy?

Options:

A.

Filtering criteria

B.

Policy version

C.

Review order

D.

Module rules

Question 17

Which index is used to store KPI values?

Options:

A.

itsi_summary_metrics

B.

itsi_metrics

C.

itsi_service_health

D.

itsi_summary

Question 18

In Episode Review, what is the result of clicking an episode’s Acknowledge button?

Options:

A.

Assign the current user as owner.

B.

Change status from New to Acknowledged.

C.

Change status from New to In Progress and assign the current user as owner.

D.

Change status from New to Acknowledged and assign the current user as owner.

Question 19

Which of the following actions can be performed with a deep dive?

Options:

A.

Create a Multi-KPI alert from the deep dive's current state to warn of similar situations in the future.

B.

Create a predictive analysis model from the deep dive to warn of future service degradation.

C.

Create an anomaly detection alert to show when the same pattern begins in the future.

D.

Create a custom service analyzer from selected deep dive lanes.

Question 20

Which step is required to install ITSI on a single Search Head?

Options:

A.

Untar the ITSI package in /etc/apps

B.

Run splunk_apply shcluster-bundle

C.

Use the Splunk -> Manage Apps Dashboard to download and install.

D.

All of the above.

Question 21

How can admins manually control groupings of notable events?

Options:

A.

Correlation searches.

B.

Multi-KPI alerts.

C.

notable_event_grouping.conf

D.

Aggregation policies.

Question 22

Which index contains ITSI Episodes?

Options:

A.

itsi_tracked_alerts

B.

itsi_grouped_alerts

C.

itsi_notable_archive

D.

itsi_summary

Question 23

When creating a custom deep dive, what color are services/KPIs in maintenance mode within the topology view?

Options:

A.

Gray

B.

Purple

C.

Gear Icon

D.

Blue

Question 24

Which of the following is a good use case for a Multi-KPI alert?

Options:

A.

Alerting when the values of two or more KPIs go into maintenance mode.

B.

Alerting when the trend of two or more KPIs indicates service failure is imminent.

C.

Alerting when two or more KPIs are deviating from their typical pattern.

D.

Alerting when comparing the values of two or more KPIs indicates an unusual condition is occurring.

Question 25

After a notable event has been closed, how long will the meta data for that event remain in the KV Store by default?

Options:

A.

6 months.

B.

9 months.

C.

1 year.

D.

3 months.

Question 26

In maintenance mode, which features of KPIs still function?

Options:

A.

KPI searches will execute but will be buffered until the maintenance window is over.

B.

KPI searches still run during maintenance mode, but results go to itsi_maintenance_summary index.

C.

New KPIs can be created, but existing KPIs are locked.

D.

KPI calculations and threshold settings can be modified.

Question 27

What is the range for a normal Service Health score category?

Options:

A.

20-40

B.

40-60

C.

60-80

D.

80-100

Question 28

Which of the following is a problem requiring correction in ITSI?

Options:

A.

Twoormore entitieswiththe same service ID.

B.

Twoormore entitieswiththe same entity ID.

C.

Twoormore entitieswiththe same value in a single alias field.

D.

Twoormore entitieswiththe same entity key value inanyinfo field.

Page: 1 / 10
Total 96 questions