Splunk IT Service Intelligence Admin (SPLK-3002) Certification Sample Questions
Getting knowledge of the Splunk SPLK-3002 exam structure and question format is vital in preparing for the Splunk IT Service Intelligence Certified Admin certification exam. Our Splunk IT Service Intelligence Admin sample questions offer you information regarding the question types and level of difficulty you will face in the real exam. The benefit of using these Splunk SPLK-3002 sample questions is that you will get to check your preparation level or enhance your knowledge by learning the unknown questions. You will also get a clear idea of the exam environment and exam pattern you will face in the actual exam with the Splunk IT Service Intelligence Certified Admin Sample Practice Test. Therefore, solve the Splunk IT Service Intelligence Administrator sample questions to stay one step forward in grabbing the Splunk IT Service Intelligence Certified Administrator credential.
These Splunk SPLK-3002 sample questions are simple and basic questions similar to the actual Splunk IT Service Intelligence Admin questions. If you want to evaluate your preparation level, we suggest taking our Splunk IT Service Intelligence Certified Admin Premium Practice Test. You might face difficulties while solving the real-exam-like questions. But, you can work hard and build your confidence on the syllabus topics through unlimited practice attempts.
Splunk SPLK-3002 Sample Questions:
How should base searches be designed for this service?
a) One base search for each of the six KPIs, so that every metric is calculated and can be tuned entirely on its own.
b) A single base search spanning both logs, so that all six KPIs draw on one search and the search count is as low as it can be.
c) One base search over the access log to feed those four KPIs, and a second over the gateway log.
d) No base search here, since base searches only help once the service's entity rules exist and the KPIs can be filtered to them.
02. A retailer's customer-facing ordering service is modeled in ITSI with its own KPIs. The database platform and the payment platform it relies on are monitored today only as a loose collection of host searches that nobody has organized into ITSI objects.
The team wants the ordering service's health score to move when either of those platforms degrades. Which three must be in place?
(Choose three.)
a) The database platform and the payment platform are each modeled as services in ITSI.
b) Each of those services carries KPIs of its own, so that it has a health score to contribute.
c) A correlation search raises a notable event when both platforms degrade.
d) The ordering service declares a dependency on each of them in its own configuration.
03. An operations group has asked to be taken off an internal reporting service, which they consider noisy and which belongs to another department. That department already holds the service in its own service-level team.
The ITSI administrator removes the service from the operations group's team. What does that change, and what does it leave untouched?
a) The group no longer sees the service; the alerting it drives is suppressed, and stays suppressed until the service is put back into a team.
b) The group no longer sees the service, and its KPI searches stop running for them, so the events that had been reaching them are no longer generated at all.
c) The group no longer sees the service; its KPIs and notable events carry on.
d) The group no longer sees the service, and its health score stops being calculated for it.
04. A database service is watched from two saved views: the default deep dive ITSI provides for that service, and a custom deep dive that was saved last quarter with three chosen lanes. A replication-lag KPI is added to the service this morning.
Which two statements describe what the team sees the next time each of those views is opened?
(Choose two.)
a) The default deep dive draws a lane for replication lag, because it is built from the service's KPI list at the moment it is opened.
b) Both views pick up the replication-lag lane, since every deep dive reads the service's current KPI list each time it is opened rather than holding a list of its own.
c) The custom deep dive still opens with the three lanes it was saved with, since they are what was saved.
d) Neither view draws replication lag until a lane for it is added by hand, because deep dives hold lanes rather than KPI lists.
05. Two services - internal file sharing and customer portal - each carry a CPU utilization KPI, and both KPIs are fed by the same base search over the whole hypervisor estate.
Both services report an identical CPU figure, and the file-sharing service's health worsens on the evenings when the portal's hosts are busiest.
What accounts for this?
a) The two services have no dependency defined between them, so ITSI cannot separate their health scores and reports the higher-level figure on both.
b) Both KPIs use adaptive thresholds learned from the same history, so identical values map onto identical severities.
c) Sharing one base search between two services is not supported in ITSI, so the second service configured simply reads the first service's results instead of calculating its own.
d) The shared search returns the whole estate, and neither KPI has been filtered to the entities belonging to its own service.
06. A platform team is briefed before ITSI is added to the Splunk deployment they already run, and asks what the installation itself will bring with it. Which description identifies what ITSI adds, rather than what it reuses from the platform?
a) A scheduler of its own, which ITSI uses to run its searches.
b) The ITSI app and its supporting components, along with the searches that produce and record its KPI results.
c) The forwarders and data inputs for the hosts behind each service, together with the indexes that hold the events those inputs collect.
d) An indexing tier of its own, so that its searches never read the same indexes the platform's other users search.
07. An administrator is writing up how alerting is put together for a newly launched online ordering service, so that the operations team understands where its notable events come from. Which two statements about ITSI correlation searches are accurate?
(Choose two.)
a) The notable events it raises stay available to review for as long as the deployment's retention settings keep them.
b) A correlation search evaluates the ordering service's KPIs against their thresholds and updates the service health score whenever one of them is breached.
c) A correlation search runs on a schedule, so a matching condition becomes a notable event when the search next runs.
d) A correlation search assigns each notable event it raises to the episode that event will be reviewed in.
08. One aggregation policy currently matches every notable event a deployment raises. The network team and the storage team each work their own incidents, and both are now being assigned the same episode, which holds network events and storage events together. Neither team can close it without touching work that belongs to the other.
What should the administrator change?
a) Put the network services and the storage services into separate ITSI teams, so that each team's users can see only their own services.
b) Have each team's correlation searches raise their events into separate episodes.
c) Give each team its own custom view of notable events, filtered to the events that team owns, so each sees only the work it is responsible for.
d) Split the policy into two, each matching only one team's events, so each team's events form episodes of their own.
09. A video-streaming provider has an approved design for an edge delivery service. The design names the six edge cache nodes that make up the service, four KPIs, and the entity rule that assigns those nodes to it.
The implementer has created the service and its four KPIs. Each KPI is returning a figure calculated from every cache node in the estate, not from the six named in the design.
Which two changes bring the implementation into line with the design?
(Choose two.)
a) Apply a service template to the edge delivery service so that the six cache nodes inherit the KPI definitions the design specifies.
b) Set the four KPIs to filter to the entities assigned to the service, so that each one measures only those six cache nodes and not the wider estate.
c) Raise the thresholds on the four KPIs so that the readings contributed by cache nodes outside the service stop pushing it into a worse severity.
d) Import the cache nodes as entities and define the rule that assigns the six named in the design to this service.
10. A glass table for the corporate email service carries a shape bound to the service itself and, beside it, shapes bound to three of that service's KPIs: mailbox login success, message queue latency and message store availability. The email service declares no dependencies on other services.
During the morning the service shape steps to a worse severity while all three KPI shapes stay where they were. What accounts for what the operator is seeing?
a) A KPI of the email service that is not on this table has degraded, since the score rolls up every KPI the service carries and not only the drawn ones.
b) A service that the email service depends on has degraded, and the health of a depended-on service is carried into the score of the service that depends on it, which is what moved the shape.
c) The thresholds behind the three drawn KPIs are set so wide that readings which have genuinely degraded are still reported at a good severity, so their shapes have stayed where they were.
d) The service shape reports a condition of the service itself, separate from its KPIs, so it can move while every KPI stays as it was.
Answers:
|
Question: 01 Answer: c |
Question: 02 Answer: a, b, d |
Question: 03 Answer: c |
Question: 04 Answer: a, c |
Question: 05 Answer: d |
|
Question: 06 Answer: b |
Question: 07 Answer: a, c |
Question: 08 Answer: d |
Question: 09 Answer: b, d |
Question: 10 Answer: a |
Note: For any error in Splunk IT Service Intelligence Certified Admin (SPLK-3002) certification exam sample questions, please update us by writing an email on feedback@certfun.com.
- SPLK-3002 Questions |
- SPLK-3002 Quiz |
- SPLK-3002 |
- Splunk IT Service Intelligence Admin Certification |
- Splunk SPLK-3002 Question Bank |
- IT Service Intelligence Administrator Mock Exam |
- IT Service Intelligence Administrator |
- Splunk IT Service Intelligence Administrator Certification |
- IT Service Intelligence Admin Sample Questions |
- Splunk SPLK-3002 Practice Test Free |
- IT Service Intelligence Administrator Certification Sample Questions
