Black Friday Biggest Discount Flat 70% Offer - Ends in 0d 00h 00m 00s - Coupon code: 70diswrap

Splunk SPLK-3002 Dumps

Page: 1 / 9
Total 90 questions

Splunk IT Service Intelligence Certified Admin Exam Questions and Answers

Question 1

When changing a service template, which of the following will be added to linked services by default?

Options:

A.

Thresholds.

B.

Entity Rules.

C.

New KPIs.

D.

Health score.

Question 2

Which of the following is a characteristic of notable event groups?

Options:

A.

Notable event groups combine independent notable events.

B.

Notable event groups are created in the itsi_tracked_alerts index.

C.

Notable event groups allow users to adjust threshold settings.

D.

All of the above.

Question 3

Within a correlation search, dynamic field values can be specified with what syntax?

Options:

A.

fieldname

B.

C.

%fieldname%

D.

eval(fieldname)

Question 4

Which of the following is a good use case for creating a custom module?

Options:

A.

Modules are required to create entity and service import searches.

B.

Modules are required to be able to create custom visualizations for deep dives.

C.

Making it easy to migrate KPI base searches and related visualizations to other ITSI installations.

D.

Creating a service template to make it easy to automatically create new services during service and entity import.

Question 5

Which index contains ITSI Episodes?

Options:

A.

itsi_tracked_alerts

B.

itsi_grouped_alerts

C.

itsi_notable_archive

D.

itsi_summary

Question 6

Which ITSI components are required before a module can be created?

Options:

A.

One or more entity import saved searches.

B.

One or more services with KPIs and their associated base searches.

C.

One or more datamodels.

D.

One or more correlation searches and their associated entities.

Question 7

Which of the following statements describe default glass tables in ITSI?

Options:

A.

The Service Health Score default glass table.

B.

There is one default glass table per service.

C.

There is one service template default glass table.

D.

There are no default glass tables.

Question 8

What is the default importance value for dependent services’ health scores?

Options:

A.

11

B.

1

C.

Unassigned

D.

10

Question 9

Which anomaly detection algorithm is included within ITSI?

Options:

A.

Entity cohesion

B.

Standard deviation

C.

Linear regression

D.

Infantile regression

Question 10

Where are KPI search results stored?

Options:

A.

The default index.

B.

KV Store.

C.

Output to a CSV lookup.

D.

The itsi_summary index.

Question 11

After ITSI is initially deployed for the operations department at a large company, another department would like to use ITSI but wants to keep their information private from the operations group. How can this be achieved?

Options:

A.

Create service templates for each group and create the services from the templates.

B.

Create teams for each department and assign KPIs to each team.

C.

Create services for each group and set the permissions of the services to restrict them to each group.

D.

Create teams for each department and assign services to the teams.

Question 12

Which ITSI functions generate notable events? (Choose all that apply.)

Options:

A.

KPI threshold breaches.

B.

KPI anomaly detection.

C.

Multi-KPI alert.

D.

Correlation search.

Question 13

Which of the following best describes an ITSI Glass Table?

Options:

A.

A view which displays a system topology overlaid with KPI metrics.

B.

A view which describes a topology.

C.

A dashboard which displays a system topology.

D.

A view showing KPI values in a variety of visual styles.

Question 14

Which is the least permissive role required to modify default deep dives?

Options:

A.

itoa_analyst

B.

admin

C.

power

D.

itoa_admin

Question 15

There are two departments using ITSI. Finance and Sales. Analysts in each department should not be allowed to see each other’s services. What are the role configuration steps required to accomplish this?

Options:

A.

itoa_finance_admin, inherited from itoa_admin; itoa_sales_admin, inherited from itoa_team_admin; itoa_finance_analyst, inherited from itoa_analyst; itoa_sales_analyst, inherited from itoa_analyst.

B.

itoa_finance_admin, inherited from itoa_admin; itoa_sales_admin, inherited from itoa_team_admin; itoa_finance_analyst, inherited from itoa_team_analyst; itoa_sales_analyst, inherited from itoa_team_analyst.

C.

itoa_finance_admin, inherited from itoa_admin; itoa_sales_admin, inherited from itoa_team_admin; itoa_finance_analyst, inherited from itoa_analyst; itoa_sales_analyst, inherited from itoa_team_analyst.

D.

itoa_finance_admin, inherited from itoa_team_admin; itoa_sales_admin, inherited from itoa_team_admin; itoa_finance_analyst, inherited from itoa_analyst; itoa_sales_analyst, inherited from itoa_analyst.

Question 16

Which of the following is a recommended best practice for ITSI installation?

Options:

A.

ITSI should not be installed on search heads that have Enterprise Security installed.

B.

Before installing ITSI, make sure the Common Information Model (CIM) is installed.

C.

Install the Machine Learning Toolkit app if anomaly detection must be configured.

D.

Install ITSI on one search head in a search head cluster and migrate the configuration bundle to other search heads.

Question 17

Which of the following statements is accurate when using multiple policies?

Options:

A.

New policies are applied after the default policy.

B.

Policy processing is applied in a defined order.

C.

An event can be processed by only a single policy.

D.

New policies are applied before the default policy.

Question 18

Which glass table feature can be used to toggle displaying KPI values from more than one service on a single widget?

Options:

A.

Service templates.

B.

Service dependencies.

C.

Ad-hoc search.

D.

Service swapping.

Question 19

Which of the following describes entities? (Choose all that apply.)

Options:

A.

Entities must be IT devices, such as routers and switches, and must be identified by either IP value, host name, or mac address.

B.

An abstract (pseudo/logical) entity can be used to split by for a KPI, although no entity rules or filtering can be used to limit data to a specific service.

C.

Multiple entities can share the same alias value, but must have different role values.

D.

To automatically restrict the KPI to only the entities in a particular service, select “Filter to Entities in Service”.

Question 20

When must a service define entity rules?

Options:

A.

If the intention is for the KPIs in the service to filter to only entities assigned to the service.

B.

To enable entity cohesion anomaly detection.

C.

If some or all of the KPIs in the service will be split by entity.

D.

If the intention is for the KPIs in the service to have different aggregate vs. entity KPI values.

Question 21

How can Service Now incidents be created automatically when a Multi-KPI alert triggers? (select all that apply)

Options:

A.

By creating a custom etc/apps/SA-lTOA/workflow_rules. conf

B.

By linking Entities to Service-Now configuration items.

C.

By creating a notable event aggregation policy with a SNOW incident action.

D.

By editing the associated correlation search and specifying an alert action.

Question 22

Which index will contain useful error messages when troubleshooting ITSI issues?

Options:

A.

_introspection

B.

_internal

C.

itsi_summary

D.

itsi_notable_audit

Question 23

Anomaly detection can be enabled on which one of the following?

Options:

A.

KPI

B.

Multi-KPI alert

C.

Entity

D.

Service

Question 24

What is the main purpose of the service analyzer?

Options:

A.

Display a list of All Services and Entities.

B.

Trigger external alerts based on threshold violations.

C.

Allow Analysts to add comments to Alerts.

D.

Monitor overall Service and KPI status.

Question 25

Which of the following services often has KPIs but no entities?

Options:

A.

Security Service.

B.

Network Service.

C.

Business Service.

D.

Technical Service.

Question 26

What are valid ITSI Glass Table editor capabilities? (Choose all that apply.)

Options:

A.

Creating glass tables.

B.

Correlation search creation.

C.

Service swapping configuration.

D.

Adding KPI metric lanes to glass tables.

Question 27

Which of the following items describe ITSI Backup and Restore functionality? (Choose all that apply.)

Options:

A.

A pre-configured default ITSI backup job is provided that can be modified, but not deleted.

B.

ITSI backup is inclusive of KV Store, ITSI Configurations, and index dependencies.

C.

kvstore_to_json.py can be used in scripts or command line to backup ITSI for full or partial backups.

D.

ITSI backups are stored as a collection of JSON formatted files.

Page: 1 / 9
Total 90 questions