New Year Sale Special - Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: mxmas70

Home > Splunk > Splunk IT Service Intelligence Certified Admin > SPLK-3002

SPLK-3002 Splunk IT Service Intelligence Certified Admin Exam Question and Answers

Question # 4

Which views would help an analyst identify that a memory usage KPI is going critical? (select all that apply)

A.

Memory KPI in a glass table.

B.

Memory panel of the OS Host Details view in the Operating System module.

C.

Memory swim lane in a Deep Dive.

D.

Service & KPI tiles in the Service Analyzer.

Full Access
Question # 5

Which of the following is a valid type of Multi-KPI Alert?

A.

Score over composite.

B.

Value over time.

C.

Status over time.

D.

Rise over run.

Full Access
Question # 6

For which ITSI function is it a best practice to use a 15-30 minute time buffer?

A.

Correlation searches.

B.

Adaptive thresholding.

C.

Maintenance windows

D.

Anomaly detection.

Full Access
Question # 7

Which of the following statements is accurate when using multiple policies?

A.

New policies are applied after the default policy.

B.

Policy processing is applied in a defined order.

C.

An event can be processed by only a single policy.

D.

New policies are applied before the default policy.

Full Access
Question # 8

When troubleshooting KPI search performance, which search names in job activity identify base searches?

A.

Indicator - XXXX - Base Search

B.

Indicator - Shared - xxxx - ITSI Search

C.

Indicator - Base - xxxx - ITSI Search

D.

Indicator - Base - XXXX - Shared Search

Full Access
Question # 9

To use Adaptive Threshholding, what is the minimum requirement for a set of KPI data?

A.

14 days old.

B.

7 days old.

C.

30 days old.

D.

10 days old.

Full Access
Question # 10

In which index are active notable events stored?

A.

itsi_notable_archive

B.

itsi_notable_audit

C.

itsi_tracked_alerts

D.

itsi_tracked_groups

Full Access
Question # 11

Which of the following items describe ITSI Backup and Restore functionality? (Choose all that apply.)

A.

A pre-configured default ITSI backup job is provided that can be modified, but not deleted.

B.

ITSI backup is inclusive of KV Store, ITSI Configurations, and index dependencies.

C.

kvstore_to_json.py can be used in scripts or command line to backup ITSI for full or partial backups.

D.

ITSI backups are stored as a collection of JSON formatted files.

Full Access
Question # 12

When in maintenance mode, which of the following is accurate?

A.

Once the window is over, KPIs and notable events will begin to be generated again.

B.

KPIs are shown in blue while in maintenance mode.

C.

Maintenance mode slots are scheduled on a per hour basis.

D.

Service health scores and KPI events are deleted until the window is over.

Full Access
Question # 13

Which of the following items describe ITSI teams? (select all that apply)

A.

Teams should have itoa admin roles added with read-only permissions for services and entities.

B.

Services should be assigned to the 'global' team if all users need access to it.

C.

By default, all services are owned by the built-in 'global' team and administered by the 'itoa_admin' role.

D.

A new team admin role should be created for each team. The new role should inherit the 'itoa_team_admin' role.

Full Access
Question # 14

Which of the following are the default ports that must be configured on Splunk to use ITSI?

A.

SplunkWeb (8405), SplunkD (8519), and HTTP Collector (8628)

B.

SplunkWeb (8089), SplunkD (8088), and HTTP Collector (8000)

C.

SplunkWeb (8000), SplunkD (8089), and HTTP Collector (8088)

D.

SplunkWeb (8088), SplunkD (8089), and HTTP Collector (8000)

Full Access
Question # 15

Which of the following is a characteristic of base searches?

A.

Search expression, entity splitting rules, and thresholds are configured at the base search level.

B.

It is possible to filter to entities assigned to the service for calculating the metrics for the service’s KPIs.

C.

The fewer KPIs that share a common base search, the more efficiency a base search provides, and anomaly detection is more efficient.

D.

The base search will execute whether or not a KPI needs it.

Full Access
Question # 16

Which capabilities are enabled through “teams”?

A.

Teams allow searches against the itsi_summary index.

B.

Teams restrict notable event alert actions.

C.

Teams restrict searches against the itsi_notable_audit index.

D.

Teams allow restrictions to service content in UI views.

Full Access
Question # 17

What is the range for a normal Service Health score category?

A.

20-40

B.

40-60

C.

60-80

D.

80-100

Full Access
Question # 18

Which anomaly detection algorithm fulfills the paired monitoring requirement?

A.

Detection algorithm: Trending anomaly detection

Monitoring requirement: Produce an alert when an entity deviates from its historical behavior.

B.

Detection algorithm: Entity cohesion anomaly detection

Monitoring requirement: Produce an alert when one entity in the KPI is not behaving similar to other entities in the KPI.

C.

Detection algorithm: Trending anomaly detection

Monitoring requirement: Produce an alert when one entity in the KPI is not behaving similar to other entities in the KPI.

D.

Detection algorithm: Entity cohesion anomaly detection

Monitoring requirement: Produce an alert when multiple KPIs in the service deviate from their historical behaviors.

Full Access
Question # 19

Which glass table feature can be used to toggle displaying KPI values from more than one service on a single widget?

A.

Service templates.

B.

Service dependencies.

C.

Ad-hoc search.

D.

Service swapping.

Full Access
Question # 20

Which scenario would benefit most by implementing ITSI?

A.

Monitoring of business services functionality.

B.

Monitoring of system hardware.

C.

Monitoring of system process statuses

D.

Monitoring of retail sales metrics.

Full Access
Question # 21

What is an episode?

A.

A workflow task.

B.

A deep dive.

C.

A notable event group.

D.

A notable event.

Full Access
Question # 22

Which of the following services often has KPIs but no entities?

A.

Security Service.

B.

Network Service.

C.

Business Service.

D.

Technical Service.

Full Access
Question # 23

Which of the following are characteristics of service templates? (select all that apply)

A.

Service templates can be modified after services are instantiated from it.

B.

Service templates contain KPIs and KPI thresholds.

C.

Service templates can contain specific or generic entity rules.

D.

Service templates contain domain specific dashboards and deep dives.

Full Access
Question # 24

Which of the following can generate notable events?

A.

Through ad-hoc search results which get processed by adaptive thresholds.

B.

When two entity aliases have a matching value.

C.

Through scheduled correlation searches which link to their respective services.

D.

Manually selected using the Notable Event Review panel.

Full Access
Question # 25

Which of the following is a recommended best practice for service and glass table design?

A.

Plan and implement services first, then build detailed glass tables.

B.

Always use the standard icons for glass table widgets to improve portability.

C.

Start with base searches, then services, and then glass tables.

D.

Design glass tables first to discover which KPIs are important.

Full Access
Question # 26

There are two Smart Mode configuration settings that control how fields affect grouping. Which of these is correct?

A.

Text deviation and category deviation.

B.

Text similarity and category deviation.

C.

Text similarity and category similarity.

D.

Text deviation and category similarity.

Full Access
Question # 27

Within a correlation search, dynamic field values can be specified with what syntax?

A.

fieldname

B.

C.

%fieldname%

D.

eval(fieldname)

Full Access
Question # 28

Buttercup Retail sells t‑shirts both online and in stores. The IT Operations team is effectively monitoring the digital infrastructure. However, the executive leadership has expressed frustration in understanding what the related business impacts are of IT incidents.

Which of the following entities would give Buttercup Retail executives the most impactful visibility?

A.

store, product, payment type

B.

store, season, customer age

C.

host, browser type, software version

D.

host, network interface, datacenter

Full Access