Weekend Sale 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: sale65best

Free Splunk SPLK-3002 Practice Exam with Questions & Answers | Set: 3

Questions 21

Which ITSI components are required before a module can be created?

Options:
A.

One or more entity import saved searches.

B.

One or more services with KPIs and their associated base searches.

C.

One or more datamodels.

D.

One or more correlation searches and their associated entities.

Splunk SPLK-3002 Premium Access
Questions 22

Which of the following is an advantage of using adaptive time thresholds?

Options:
A.

Automatically update thresholds daily to manage dynamic changes to KPI values.

B.

Automatically adjust KPI calculation to manage dynamic event data.

C.

Automatically adjust aggregation policy grouping to manage escalating severity.

D.

Automatically adjust correlation search thresholds to adjust sensitivity over time.

Questions 23

What is the main purpose of the service analyzer?

Options:
A.

Display a list of All Services and Entities.

B.

Trigger external alerts based on threshold violations.

C.

Allow Analysts to add comments to Alerts.

D.

Monitor overall Service and KPI status.

Questions 24

Which of the following is a recommended best practice for ITSI installation?

Options:
A.

ITSI should not be installed on search heads that have Enterprise Security installed.

B.

Before installing ITSI, make sure the Common Information Model (CIM) is installed.

C.

Install the Machine Learning Toolkit app if anomaly detection must be configured.

D.

Install ITSI on one search head in a search head cluster and migrate the configuration bundle to other search heads.

Questions 25

There are two departments using ITSI. Finance and Sales. Analysts in each department should not be allowed to see each other’s services. What are the role configuration steps required to accomplish this?

Options:
A.

itoa_finance_admin, inherited from itoa_admin; itoa_sales_admin, inherited from itoa_team_admin; itoa_finance_analyst, inherited from itoa_analyst; itoa_sales_analyst, inherited from itoa_analyst.

B.

itoa_finance_admin, inherited from itoa_admin; itoa_sales_admin, inherited from itoa_team_admin; itoa_finance_analyst, inherited from itoa_team_analyst; itoa_sales_analyst, inherited from itoa_team_analyst.

C.

itoa_finance_admin, inherited from itoa_admin; itoa_sales_admin, inherited from itoa_team_admin; itoa_finance_analyst, inherited from itoa_analyst; itoa_sales_analyst, inherited from itoa_team_analyst.

D.

itoa_finance_admin, inherited from itoa_team_admin; itoa_sales_admin, inherited from itoa_team_admin; itoa_finance_analyst, inherited from itoa_analyst; itoa_sales_analyst, inherited from itoa_analyst.

Questions 26

To use Adaptive Threshholding, what is the minimum requirement for a set of KPI data?

Options:
A.

14 days old.

B.

7 days old.

C.

30 days old.

D.

10 days old.

Questions 27

Which of the following are deployment recommendations for ITSI? (Choose all that apply.)

Options:
A.

Deployments often require an increase of hardware resources above base Splunk requirements.

B.

Deployments require a dedicated ITSI search head.

C.

Deployments may increase the number of required indexers based on the number of KPI searches.

D.

Deployments should use fastest possible disk arrays for indexers.