Summer Special 60% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: bestdeal

Free Splunk SPLK-3002 Practice Exam with Questions & Answers

Questions 1

In distributed search, which components need to be installed on instances other than the search head?

Options:
A.

SA-IndexCreation and SA-ITSI-Licensechecker on indexers.

B.

SA-IndexCreation and SA-ITOA on indexers; SA-ITSI-Licensechecker and SA-UserAccess on the license master.

C.

SA-IndexCreation on idexers; SA-ITSI-Licensechecker and SA-UserAccess on the license master.

D.

SA-ITSI-Licensechecker on indexers.

Splunk SPLK-3002 Premium Access
Questions 2

Which of the following is a good use case for a Multi-KPI alert?

Options:
A.

Alerting when the values of two or more KPIs go into maintenance mode.

B.

Alerting when the trend of two or more KPIs indicates service failure is imminent.

C.

Alerting when two or more KPIs are deviating from their typical pattern.

D.

Alerting when comparing the values of two or more KPIs indicates an unusual condition is occurring.

Questions 3

In Episode Review, what is the result of clicking an episode’s Acknowledge button?

Options:
A.

Assign the current user as owner.

B.

Change status from New to Acknowledged.

C.

Change status from New to In Progress and assign the current user as owner.

D.

Change status from New to Acknowledged and assign the current user as owner.

Questions 4

Which of the following applies when configuring time policies for KPI thresholds?

Options:
A.

A person can only configure 24 policies, one for each hour of the day.

B.

They are great if you expect normal behavior at 1:00 to be different than normal behavior at 5:00

C.

If a person expects a KPI to change significantly through a cycle on a daily basis, don’t use it.

D.

It is possible for multiple time policies to overlap.

Questions 5

What happens when an anomaly is detected?

Options:
A.

A separate correlation search needs to be created in order to see it.

B.

A SNMP trap will be sent.

C.

An anomaly alert will appear in core splunk, in index=main.

D.

An anomaly alert will appear as a notable event in Episode Review.

Questions 6

Which is the least permissive role required to modify default deep dives?

Options:
A.

itoa_analyst

B.

admin

C.

power

D.

itoa_admin

Questions 7

What is the range for a normal Service Health score category?

Options:
A.

20-40

B.

40-60

C.

60-80

D.

80-100

Questions 8

Which of the following describes enabling smart mode for an aggregation policy?

Options:
A.

Configure –> Policies –> Smart Mode –> Enable, select “fields”, click “Save”

B.

Enable grouping in Notable Event Review, select “Smart Mode”, select “fields”, and click “Save”

C.

Edit the aggregation policy, enable smart mode, select fields to analyze, click “Save”

D.

Edit the notable event view, enable smart mode, select “fields”, and click “Save”

Questions 9

When creating a custom deep dive, what color are services/KPIs in maintenance mode within the topology view?

Options:
A.

Gray

B.

Purple

C.

Gear Icon

D.

Blue

Questions 10

Which of the following is a good use case regarding defining entities for a service?

Options:
A.

Automatically associate entities to services using multiple entity aliases.

B.

All of the entities have the same identifying field name.

C.

Being able to split a CPU usage KPI by host name.

D.

KPI total values are aggregated from multiple different category values in the source events.