Month End Sale - Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: xmaspas7

Easiest Solution 2 Pass Your Certification Exams

SPLK-3002 Splunk IT Service Intelligence Certified Admin Exam Free Practice Exam Questions (2025 Updated)

Prepare effectively for your Splunk SPLK-3002 Splunk IT Service Intelligence Certified Admin Exam certification with our extensive collection of free, high-quality practice questions. Each question is designed to mirror the actual exam format and objectives, complete with comprehensive answers and detailed explanations. Our materials are regularly updated for 2025, ensuring you have the most current resources to build confidence and succeed on your first attempt.

Page: 1 / 2
Total 90 questions

Which of the following best describes a default deep dive?

A.

It initially shows the health scores for all services.

B.

It initially shows the highest importance KPIs.

C.

It initially shows all of the KPIs for a selected service.

D.

It initially shows all the entity swim lanes.

Which glass table feature can be used to toggle displaying KPI values from more than one service on a single widget?

A.

Service templates.

B.

Service dependencies.

C.

Ad-hoc search.

D.

Service swapping.

Which of the following describes entities? (Choose all that apply.)

A.

Entities must be IT devices, such as routers and switches, and must be identified by either IP value, host name, or mac address.

B.

An abstract (pseudo/logical) entity can be used to split by for a KPI, although no entity rules or filtering can be used to limit data to a specific service.

C.

Multiple entities can share the same alias value, but must have different role values.

D.

To automatically restrict the KPI to only the entities in a particular service, select “Filter to Entities in Service”.

Which of the following is a recommended best practice for ITSI installation?

A.

ITSI should not be installed on search heads that have Enterprise Security installed.

B.

Before installing ITSI, make sure the Common Information Model (CIM) is installed.

C.

Install the Machine Learning Toolkit app if anomaly detection must be configured.

D.

Install ITSI on one search head in a search head cluster and migrate the configuration bundle to other search heads.

Which of the following actions can be performed with a deep dive?

A.

Create a Multi-KPI alert from the deep dive's current state to warn of similar situations in the future.

B.

Create a predictive analysis model from the deep dive to warn of future service degradation.

C.

Create an anomaly detection alert to show when the same pattern begins in the future.

D.

Create a custom service analyzer from selected deep dive lanes.

To use Adaptive Threshholding, what is the minimum requirement for a set of KPI data?

A.

14 days old.

B.

7 days old.

C.

30 days old.

D.

10 days old.

What are valid considerations when designing an ITSI Service? (Choose all that apply.)

A.

Service access control requirements for ITSI Team Access should be considered, and appropriate teams provisioned prior to creating the ITSI Service.

B.

Entities, entity meta-data, and entity rules should be planned carefully to support the service design and configuration.

C.

Services, entities, and saved searches are stored in the ITSI app, while events created by KPI execution are stored in the itsi_summary index.

D.

Backfill of a KPI should always be selected so historical data points can be used immediately and alerts based on that data can occur.

Which of the following can generate notable events?

A.

Through ad-hoc search results which get processed by adaptive thresholds.

B.

When two entity aliases have a matching value.

C.

Through scheduled correlation searches which link to their respective services.

D.

Manually selected using the Notable Event Review panel.

Which of the following applies when configuring time policies for KPI thresholds?

A.

A person can only configure 24 policies, one for each hour of the day.

B.

They are great if you expect normal behavior at 1:00 to be different than normal behavior at 5:00

C.

If a person expects a KPI to change significantly through a cycle on a daily basis, don’t use it.

D.

It is possible for multiple time policies to overlap.

Which of the following are the default ports that must be configured on Splunk to use ITSI?

A.

SplunkWeb (8405), SplunkD (8519), and HTTP Collector (8628)

B.

SplunkWeb (8089), SplunkD (8088), and HTTP Collector (8000)

C.

SplunkWeb (8000), SplunkD (8089), and HTTP Collector (8088)

D.

SplunkWeb (8088), SplunkD (8089), and HTTP Collector (8000)

What happens when an anomaly is detected?

A.

A separate correlation search needs to be created in order to see it.

B.

A SNMP trap will be sent.

C.

An anomaly alert will appear in core splunk, in index=main.

D.

An anomaly alert will appear as a notable event in Episode Review.

Which of the following is a valid type of Multi-KPI Alert?

A.

Score over composite.

B.

Value over time.

C.

Status over time.

D.

Rise over run.

Which of the following describes a way to delete multiple duplicate entities in ITSI?

A.

Via c CSV upload.

B.

Via the entity lister page.

C.

Via a search using the | deleteentity command.

D.

All of the above.

Which is the least permissive role required to modify default deep dives?

A.

itoa_analyst

B.

admin

C.

power

D.

itoa_admin

Which index contains ITSI Episodes?

A.

itsi_tracked_alerts

B.

itsi_grouped_alerts

C.

itsi_notable_archive

D.

itsi_summary

What is the range for a normal Service Health score category?

A.

20-40

B.

40-60

C.

60-80

D.

80-100

Which of the following describes a realistic troubleshooting workflow in ITSI?

A.

Correlation Search –> Deep Dive –> Notable Event

B.

Service Analyzer –> Notable Event Review –> Deep Dive

C.

Service Analyzer –> Aggregation Policy –> Deep Dive

D.

Correlation search –> KPI –> Aggregation Policy

Which of the following describes enabling smart mode for an aggregation policy?

A.

Configure –> Policies –> Smart Mode –> Enable, select “fields”, click “Save”

B.

Enable grouping in Notable Event Review, select “Smart Mode”, select “fields”, and click “Save”

C.

Edit the aggregation policy, enable smart mode, select fields to analyze, click “Save”

D.

Edit the notable event view, enable smart mode, select “fields”, and click “Save”

In maintenance mode, which features of KPIs still function?

A.

KPI searches will execute but will be buffered until the maintenance window is over.

B.

KPI searches still run during maintenance mode, but results go to itsi_maintenance_summary index.

C.

New KPIs can be created, but existing KPIs are locked.

D.

KPI calculations and threshold settings can be modified.

Which step is required to install ITSI on a single Search Head?

A.

Untar the ITSI package in /etc/apps

B.

Run splunk_apply shcluster-bundle

C.

Use the Splunk -> Manage Apps Dashboard to download and install.

D.

All of the above.

Page: 1 / 2
Total 90 questions
Copyright © 2014-2025 Solution2Pass. All Rights Reserved