
Latest [Nov 01, 2021] SPLK-3002 Exam Questions – Valid SPLK-3002 Dumps Pdf
SPLK-3002 Practice Test Questions Answers Updated 54 Questions
Splunk SPLK-3002 Exam Syllabus Topics:
| Topic | Details |
|---|---|
| Topic 1 |
|
| Topic 2 |
|
| Topic 3 |
|
| Topic 4 |
|
| Topic 5 |
|
| Topic 6 |
|
| Topic 7 |
|
| Topic 8 |
|
| Topic 9 |
|
| Topic 10 |
|
| Topic 11 |
|
| Topic 12 |
|
| Topic 13 |
|
| Topic 14 |
|
| Topic 15 |
|
NEW QUESTION 15
Which of the following is a best practice when configuring maintenance windows?
- A. Develop a strategy for configuring a service's notable event generation when the service's maintenance window is open.
- B. Give the maintenance window a buffer, for example, 15 minutes before and after actual maintenance work.
- C. Change the color of services and entities that are part of an open maintenance window in the service analyzer.
- D. Disable any glass tables that reference a KPI that is part of an open maintenance window.
Answer: B
Explanation:
Explanation
It's a best practice to schedule maintenance windows with a 15- to 30-minute time buffer before and after you start and stop your maintenance work.
NEW QUESTION 16
Which of the following items apply to anomaly detection? (Choose all that apply.)
- A. Anomaly detection automatically generates notable events when KPI data diverges from the pattern.
- B. Use AD on KPIs that have an unestablished baseline of data points. This allows the ML pattern to perform it's magic.
- C. A minimum of 24 hours of data is needed for anomaly detection, and a minimum of 4 entities for cohesive analysis.
- D. There are 3 types of anomaly detection supported in ITSI: adhoc, trending, and cohesive.
Answer: A,C
NEW QUESTION 17
Which of the following applies when configuring time policies for KPI thresholds?
- A. They are great if you expect normal behavior at 1:00 to be different than normal behavior at 5:00
- B. If a person expects a KPI to change significantly through a cycle on a daily basis, don't use it.
- C. It is possible for multiple time policies to overlap.
- D. A person can only configure 24 policies, one for each hour of the day.
Answer: C
Explanation:
Explanation
If you're creating multiple time policies that require the same threshold values, you can save time by copying the threshold levels and their corresponding values from one policy to another.
NEW QUESTION 18
Which of the following is an advantage of using adaptive time thresholds?
- A. Automatically adjust KPI calculation to manage dynamic event data.
- B. Automatically adjust correlation search thresholds to adjust sensitivity over time.
- C. Automatically adjust aggregation policy grouping to manage escalating severity.
- D. Automatically update thresholds daily to manage dynamic changes to KPI values.
Answer: D
NEW QUESTION 19
There are two departments using ITSI. Finance and Sales. Analysts in each department should not be allowed to see each other's services. What are the role configuration steps required to accomplish this?
- A. itoa_finance_admin, inherited from itoa_team_admin; itoa_sales_admin, inherited from itoa_team_admin; itoa_finance_analyst, inherited from itoa_analyst; itoa_sales_analyst, inherited from itoa_analyst.
- B. itoa_finance_admin, inherited from itoa_admin; itoa_sales_admin, inherited from itoa_team_admin; itoa_finance_analyst, inherited from itoa_team_analyst; itoa_sales_analyst, inherited from itoa_team_analyst.
- C. itoa_finance_admin, inherited from itoa_admin; itoa_sales_admin, inherited from itoa_team_admin; itoa_finance_analyst, inherited from itoa_analyst; itoa_sales_analyst, inherited from itoa_team_analyst.
- D. itoa_finance_admin, inherited from itoa_admin; itoa_sales_admin, inherited from itoa_team_admin; itoa_finance_analyst, inherited from itoa_analyst; itoa_sales_analyst, inherited from itoa_analyst.
Answer: C
NEW QUESTION 20
Which of the following describes enabling smart mode for an aggregation policy?
- A. Edit the notable event view, enable smart mode, select "fields", and click "Save"
- B. Edit the aggregation policy, enable smart mode, select fields to analyze, click "Save"
- C. Enable grouping in Notable Event Review, select "Smart Mode", select "fields", and click "Save"
- D. Configure -> Policies -> Smart Mode -> Enable, select "fields", click "Save"
Answer: D
Explanation:
Explanation
1. From the ITSI main menu, click Configuration > Notable Event Aggregation Policies.
2. Select a custom policy or the Default Policy.
3. Under Smart Mode grouping, enable Smart Mode.
4. Click Select fields. A dialog displays the fields found in your notable events from the last 24 hours.
NEW QUESTION 21
In distributed search, which components need to be installed on instances other than the search head?
- A. SA-IndexCreation and SA-ITOA on indexers; SA-ITSI-Licensechecker and SA-UserAccess on the license master.
- B. SA-IndexCreation and SA-ITSI-Licensechecker on indexers.
- C. SA-IndexCreation on idexers; SA-ITSI-Licensechecker and SA-UserAccess on the license master.
- D. SA-ITSI-Licensechecker on indexers.
Answer: B
Explanation:
Explanation
SA-IndexCreation is required on all indexers. For non-clustered, distributed environments, copy SA-IndexCreation to $SPLUNK_HOME/etc/apps/ on individual indexers.
NEW QUESTION 22
When deploying ITSI on a distributed Splunk installation, which component must be installed on the search head(s)?
- A. SA-ITOA
- B. SA-ITSI-Licensechecker
- C. All ITSI components
- D. ITSI app
Answer: B
Explanation:
Explanation
Install SA-ITSI-Licensechecker and SA-UserAccess on any license master in a distributed or search head cluster environment. If a search head in your environment is also a license master, the license master components are installed when you install ITSI on the search heads.
NEW QUESTION 23
How do you automatically restrict a KPI to only the entities in its service, and generate KPI values for each entity?
- A. Select "Yes" for both "Split by Entity" and "Filter to Entities in Service".
- B. Select "No" for both "Split by Entity" and "Filter to Entities in Service".
- C. Select "Yes" for "Split by Entity" and "No" for "Filter to Entities in Service".
- D. Select "No" for "Split by Entity" and "Yes" for "Filter to Entities in Service".
Answer: A
NEW QUESTION 24
Which scenario would benefit most by implementing ITSI?
- A. Monitoring of system hardware.
- B. Monitoring of business services functionality.
- C. Monitoring of system process statuses
- D. Monitoring of retail sales metrics.
Answer: B
NEW QUESTION 25
When installing ITSI to support a Distributed Search Architecture, which of the following items apply?
(Choose all that apply.)
- A. Extract ITSI app package into etc/apps directory of search head.
- B. Copy SA-IndexCreation to the etc/apps directory on the index cluster master node.
- C. Copy SA-IndexCreation to all indexers.
- D. Extract installer package into etc/apps directory of the cluster deployer node.
Answer: C
Explanation:
Explanation
Copy SA-IndexCreation to $SPLUNK_HOME/etc/apps/ on all individual indexers in your environment.
NEW QUESTION 26
Which index contains ITSI Episodes?
- A. itsi_notable_archive
- B. itsi_grouped_alerts
- C. itsi_tracked_alerts
- D. itsi_summary
Answer: A
NEW QUESTION 27
When must a service define entity rules?
- A. If some or all of the KPIs in the service will be split by entity.
- B. If the intention is for the KPIs in the service to filter to only entities assigned to the service.
- C. If the intention is for the KPIs in the service to have different aggregate vs. entity KPI values.
- D. To enable entity cohesion anomaly detection.
Answer: B
Explanation:
Explanation
Provide a value to filter the service to a specific set of entities. These entity rule values are meant to be custom for each service.
NEW QUESTION 28
Within a correlation search, dynamic field values can be specified with what syntax?
- A. <fieldname /fieldname>
- B. fieldname
- C. %fieldname%
- D. eval(fieldname)
Answer: B
NEW QUESTION 29
Which of the following are deployment recommendations for ITSI? (Choose all that apply.)
- A. Deployments should use fastest possible disk arrays for indexers.
- B. Deployments often require an increase of hardware resources above base Splunk requirements.
- C. Deployments require a dedicated ITSI search head.
- D. Deployments may increase the number of required indexers based on the number of KPI searches.
Answer: B,C,D
Explanation:
Explanation
You might need to increase the hardware specifications of your own Enterprise Security deployment above the minimum hardware requirements depending on your environment.
Install Splunk Enterprise Security on a dedicated search head or search head cluster.
The Splunk platform uses indexers to scale horizontally. The number of indexers required in an Enterprise Security deployment varies based on the data volume, data type, retention requirements, search type, and search concurrency.
NEW QUESTION 30
......
SPLK-3002 dumps Sure Practice with 54 Questions: https://www.practicevce.com/Splunk/SPLK-3002-practice-exam-dumps.html
Get New SPLK-3002 Certification – Valid Exam Dumps Questions: https://drive.google.com/open?id=1yvVf3Tiq3RYxh7qUORwBDNQ9P4kgqHai