New Year Sale Special - Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: xmaspas7

Easiest Solution 2 Pass Your Certification Exams

SPLK-3002 Splunk IT Service Intelligence Certified Admin Exam Free Practice Exam Questions (2026 Updated)

Prepare effectively for your Splunk SPLK-3002 Splunk IT Service Intelligence Certified Admin Exam certification with our extensive collection of free, high-quality practice questions. Each question is designed to mirror the actual exam format and objectives, complete with comprehensive answers and detailed explanations. Our materials are regularly updated for 2026, ensuring you have the most current resources to build confidence and succeed on your first attempt.

Page: 1 / 2
Total 96 questions

Which of the following describes default deep dives?

A.

Are manually generated and can be accessed via the Service Analyzer.

B.

Include all KPIs of all services.

C.

Are auto-generated and can be accessed via the Service Analyzer.

D.

Include health scores of all services.

When troubleshooting KPI search performance, which search names in job activity identify base searches?

A.

Indicator - XXXX - Base Search

B.

Indicator - Shared - xxxx - ITSI Search

C.

Indicator - Base - xxxx - ITSI Search

D.

Indicator - Base - XXXX - Shared Search

ITSI Saved Search Scheduling is configured to use realtime_schedule = 0. Which statement is accurate about this configuration?

A.

If this value is set to 0, the scheduler bases its determination of the next scheduled search execution time on the current time.

B.

If this value is set to 0, the scheduler bases its determination of the next scheduled search on the last search execution time.

C.

If this value is set to 0, the scheduler may skip scheduled execution periods.

D.

If this value is set to 0, the scheduler might skip some execution periods to make sure that the scheduler is executing the searches running over the most recent time range.

What is an episode?

A.

A workflow task.

B.

A deep dive.

C.

A notable event group.

D.

A notable event.

Which of the following is a characteristic of custom deep dives?

A.

Allows itoa_analyst roles to add comments.

B.

Requires at least 7 days' data to show anomalies.

C.

Combines metric, event, KPI, and service health score lanes.

D.

Uses drilldown to generate notable events via anomaly detection.

What is the default importance value for dependent services’ health scores?

A.

11

B.

1

C.

Unassigned

D.

10

What effects does the KPI importance weight of 11 have on the overall health score of a service?

A.

At least 10% of the KPIs will go critical.

B.

Importance weight is unused for health scoring.

C.

The service will go critical.

D.

It is a minimum health indicator KPI.

Which of the following describes enabling smart mode for an aggregation policy?

A.

Configure –> Policies –> Smart Mode –> Enable, select “fields”, click “Save”

B.

Enable grouping in Notable Event Review, select “Smart Mode”, select “fields”, and click “Save”

C.

Edit the aggregation policy, enable smart mode, select fields to analyze, click “Save”

D.

Edit the notable event view, enable smart mode, select “fields”, and click “Save”

Which of the following items describe ITSI Deep Dive capabilities? (Choose all that apply.)

A.

Comparing a service’s notable events over a time period.

B.

Visualizing one or more Service KPIs values by time.

C.

Examining and comparing alert levels for KPIs in a service over time.

D.

Comparing swim lane values for a slice of time.

Which of the following is an advantage of using adaptive time thresholds?

A.

Automatically update thresholds daily to manage dynamic changes to KPI values.

B.

Automatically adjust KPI calculation to manage dynamic event data.

C.

Automatically adjust aggregation policy grouping to manage escalating severity.

D.

Automatically adjust correlation search thresholds to adjust sensitivity over time.

Which is the least permissive role required to modify default deep dives?

A.

itoa_analyst

B.

admin

C.

power

D.

itoa_admin

Which of the following is a good use case regarding defining entities for a service?

A.

Automatically associate entities to services using multiple entity aliases.

B.

All of the entities have the same identifying field name.

C.

Being able to split a CPU usage KPI by host name.

D.

KPI total values are aggregated from multiple different category values in the source events.

To use Adaptive Threshholding, what is the minimum requirement for a set of KPI data?

A.

14 days old.

B.

7 days old.

C.

30 days old.

D.

10 days old.

Which of the following items describe ITSI teams? (select all that apply)

A.

Teams should have itoa admin roles added with read-only permissions for services and entities.

B.

Services should be assigned to the 'global' team if all users need access to it.

C.

By default, all services are owned by the built-in 'global' team and administered by the 'itoa_admin' role.

D.

A new team admin role should be created for each team. The new role should inherit the 'itoa_team_admin' role.

Buttercup Retail sells t‑shirts both online and in stores. The IT Operations team is effectively monitoring the digital infrastructure. However, the executive leadership has expressed frustration in understanding what the related business impacts are of IT incidents.

Which of the following entities would give Buttercup Retail executives the most impactful visibility?

A.

store, product, payment type

B.

store, season, customer age

C.

host, browser type, software version

D.

host, network interface, datacenter

How should entities be handled during the data audit phase of requirements gathering?

A.

Entity meta-data for info and aliases should be identified and recorded as requirements.

B.

Entities should be noted based upon Service KPI requirements such as 'by host' or 'by product line'.

C.

Entities must be identified for every Service KPI defined and recorded in requirements.

D.

Entities identified should be included in the entity filtering requirements, such as 'by processld' or 'by host'.

Which of the following are the default ports that must be configured on Splunk to use ITSI?

A.

SplunkWeb (8405), SplunkD (8519), and HTTP Collector (8628)

B.

SplunkWeb (8089), SplunkD (8088), and HTTP Collector (8000)

C.

SplunkWeb (8000), SplunkD (8089), and HTTP Collector (8088)

D.

SplunkWeb (8088), SplunkD (8089), and HTTP Collector (8000)

Which of the following is a valid type of Multi-KPI Alert?

A.

Score over composite.

B.

Value over time.

C.

Status over time.

D.

Rise over run.

When must a service define entity rules?

A.

If the intention is for the KPIs in the service to filter to only entities assigned to the service.

B.

To enable entity cohesion anomaly detection.

C.

If some or all of the KPIs in the service will be split by entity.

D.

If the intention is for the KPIs in the service to have different aggregate vs. entity KPI values.

Which of the following services often has KPIs but no entities?

A.

Security Service.

B.

Network Service.

C.

Business Service.

D.

Technical Service.

Page: 1 / 2
Total 96 questions
Copyright © 2014-2026 Solution2Pass. All Rights Reserved