Your network management system (NMS) is
currently indicating the following unrelated issues:A router in a remote site
is down.An interface on a core switch is down.An interface on a core switch has
disappeared.A switch in a remote site is down.Which scenario is most likely to
be true?
A.A router in a remote site is down.
B.An interface on a core switch is down.
C.An interface on a core switch has
disappeared.
D.A switch in a remote site is down.
Correct Answer:B
What is the most reliable method of detecting
network issues?
A.listening for SNMP traps
B.listening for Syslog messages
C.conducting SNMP polling
D.monitoring traffic with NetFlow
Correct Answer:C
Without regard to reliability, what is the
fastest method for detecting network faults?
A.listening for SNMP traps
B.querying with SNMP
C.analyzing traffic with NetFlow
D.querying with WMI
Correct Answer:A
You need to know when the aggregate size of
SQL log files has crossed a threshold.How can you accomplish this?
A.monitor the usage of the drive the SQL logs
reside on
B.use NetFlow to monitor the amount of SQL
traffic to the SQL server
C.monitor Windows Events to track SQL log
messages
D.use NetFlow to monitor the number of
messages sent to the logs
Correct Answer:A
Why are management loop back interfaces
important when managing routers, switches, and firewalls?
A.They have an IP address of 127.0.0.1, and
therefore, are not routable.
B.They are always available, even if the
device is down.
C.They provide unique statistics on interface
traffic.
D.They are "up" and reachable as
long as the device itself is reachable.
Correct Answer:D
While diagnosing a network issue, you find
that you are able to reach the troubled device when testing from the same VLAN,
but you are not able to reach that device when testing from a separate VLAN.At
which layer of the OSI model is the issue occurring?
A.1
B.2
C.3
D.4
Correct Answer:C
You are using a protocol analyzer to capture
a packet trace in order to troubleshoot a specific network problem.Which change
must you make on the Ethernet switch in order to facilitate the packet capture?
A.mirror or span traffic to the switch's
console port
B.update access lists to allow layer 2 traffic
to be transferred to the capture port
C.mirror or span traffic to the port where
your analyzer is connected
D.add the port where your analyzer is
connected to the target VLAN
Correct Answer:C
Users are complaining that they are unable to
access the corporate Microsoft Exchange Server. Orion has detected the
following: The switch port connected to the Exchange Server is
"shutdown". User experience monitors for the Outlook Web Access
component are failing. The Exchange Server is "down" .The services
that make up Microsoft Exchange are "down". What is the root cause of
the users' inability to access the Exchange Server?
A.The switch port connected to the Exchange
Server is "shutdown".
B.User experience monitors for the Outlook
Web Access (OWA) component are failing.
C.The Exchange Server is "down".
D.The services that make up Microsoft
Exchange are "down".
Correct Answer:A
Users at both the New York and Los Angeles
sites are complaining that VoIP is not working. Other network services at those
sites and users at other sites seem to be unaffected.What are the first two
things you should investigate to find the cause of this issue? (Choose two.)
A.the current status of the New York and Los
Angeles sites
B.the current bandwidth utilization for the
circuits to New York and Los Angeles
C.the current CPU load for the routers in New
York and Los Angeles
D.recent changes to the router configurations
in New York and Los Angeles
E.the software versions on the Call Managers
supporting New York and Los Angeles
Correct Answer:BD
Your company outsources CRM to a SaaS
company. Users are complaining that the CRM is down. You verify that Internet
connectivity is good and that other Internet sites can be accessed. You contact
the CRM provider and find that none of their other customers are having issues.
You attempt to ping this IP address from your network management system (NMS),
but the ping fails. After reviewing recent changes to your outside router's
configuration, you find that several access control lists (ACLs) have been
updated.What should you do to verify that the problem is related to the ACL
updates?
A.remove the ACLs and retest for connectivity
to the CRM
B.contact your ISP to see if they can access
the CRM from their site
C.telnet to the outside router and ping the
CRM from the router's outside interface
D.re-ping the CRM from your NMS with a
special flag so the ping will pass through the ACLs
Correct Answer:C
Users complain that access to the Internet is
down. You review your network management system (NMS)and find the following:The
core router rebooted last night.Network traffic on your Internet gateway is at
5%The configuration on your firewall was just rolled back.The corporate mail
server is down.Which issue should you investigate first?
A.The core router rebooted last night.
B.Network traffic on your Internet gateway is
at 5%.
C.The configuration on your firewall was just
rolled back.
D.The corporate mail server is down.
Correct Answer:C
Austin and New York offices are connected
through an MPLS cloud.You receive a trouble ticket stating that a video
conference room in the Austin office cannot connect to the video conference
room in the NewYork office.You verify the following information:Trace routes
from Austin to New York can make it to the last hop, which is your NYC router.The
Austin conference subnet can reach other subnets within the New York office.What
is a possible root cause for the lack of connectivity between conference
stations?
A.An access control list (ACL) is blocking
ICMP traffic from Austin to New York.
B.The New York video conference device is
missing a default route.
C.BGP is not set up correctly.
D.The MPLS interface in your New York office
is shutdown.
Correct Answer:B
Orion NPM is showing that a router in a
remote site is down. However, Orion indicates that other devicesat that site
are up.What is the most likely cause?
A.ICMP replies have been disabled on the
router.
B.The router Ethernet port is unplugged.
C.SNMP replies have been disabled on the
router.
D.Orion NPM is misconfigured.
Correct Answer:A
Wireless users are complaining of sporadic
network access issues. After reviewing the data collected by Orion, it seems
that there is one specific wireless user that is causing the issue and that
every WAP that they connect to is adversely affected.What should you do to
resolve this issue?
A.block this user's MAC address from
connecting to your WAPs
B.block this user's IP address from
connecting to your WAPs
C.implement QoS to De-prioritize this user's
network traffic
D.increase the bandwidth allocation for the
connections to the WAPs from the wired network
Correct Answer:A
Users of a remote site are complaining that
network performance is intermittently slow. You review the current status of
their network with Orion NPM and do not see any issues.What should you do next?
A.analyze the performance of the remote site
over the last 30 days to look for problems
B.monitor the performance of the remote site
for the next 30 days to look for problems
C.install a protocol analyzer or probe at the
remote site to capture detailed performance data
D.block access from the site to non-business
related Internet sites to boost network performance
Correct Answer:A
Users at a remote site in Paris are
complaining that access to the company CRM is slow. Orion is collecting data on
this performance, but you need a more real-time perspective on the problem.What
should you do?
A.install an Orion polling engine to collect
real-time data at the site in Paris
B.increase the polling interval in Orion for
monitoring of devices in Paris
C.launch a real-time tool to measure and
analyze performance while the problem is occurring
D.use the Polling Engine Tuner to increase
the Max Polls Per Second settings in Orion
Correct Answer:C
Orion is displaying a device as
"down" and is unable to communicate with the device via ICMP.
However,you are able to ping that device from the command-line on the Orion
server. Orion is displaying other devices as being "up"what is a
possible cause of this issue?
A.The Orion polling engine has stopped and
needs to be restarted.
B.Orion is using a different version of ICMP
than the one CLI is using.
C.The Orion ICMP messages have the discard eligible
bit set.
D.ICMP messages with content in the payload
portion of the packets are being blocked.
Correct Answer:D
One of your network administrators has
deployed a new access control list (ACL) that blocks UDP port 69.As a result of
this change, what might the network management system (NMS) NO longer be able
to do?
A.poll devices for status
B.collect Syslog messages from your devices
C.collect SNMP traps from your devices
D.update IOS on your devices
Correct Answer:D
While troubleshooting issues on your network,
you notice that route paths frequently change.Which change to your OSPF
configuration would capture this issue in Syslog?
A.log-ospf-statistics
B.log-status-changes
C.default-route-originate
D.log-adjacency-changes
Correct Answer:D
Home office users (telecommuters) are
complaining that they can no longer access the corporate intranet site.What
should you review to investigate this issue?
A.configuration of the laptops and home
routers for each of the remote users
B.recent configuration changes to access
control lists (ACLs) and VPN profiles
C.recent performance metrics for the intranet
server and VPN concentrator
D.recent announcements by the users' various
ISP.
Correct Answer:B
Your company leverages Internet-based VPNs to
provide connectivity to remote offices. At these sites, the users are connected
directly to a layer 2 switch, which is then connected to a VPN concentrator
that also provides basic routing functions.How should you analyze the traffic
going to and from a remote site?
A.leverage NetFlow data from the outside
interface of the VPN concentrator at the remote site
B.leverage NetFlow data from the outside
interface of the VPN concentrator at your main site
C.deploy a protocol analyzer to the remote
site between the switch and the concentrator
D.deploy a protocol analyzer to the main site
between the VPN concentrator and the Internet
Correct Answer:C
A device is NOT responding to pings.What can
you determine from this information?
A.The device may be down.
B.The device is down.
C.The device is a firewall.
D.There is no route to the device.
Correct Answer:A
Users at a remote site report that Internet
access is slower than usual.What should you check to investigate the cause of
this issue?
A.availability reports
B.CPU reports
C.memory reports
D.bandwidth reports
Correct Answer:D
Lower than normal throughput is being
experienced between two routers.What can be seen on the router interface that
may be contributing to this issue?
A.discards due to router access control lists
(ACLs)
B.drops from malformed packets
C.when the traffic change occurred
D.routing changes
Correct Answer:B
You believe that a QoS misconfiguration may be
causing poor performance on your network.What should you check to verify that
QoS is the root cause?
A.response and errors
B.CPU and memory
C.bandwidth and availability
D.bandwidth and packet drops
Correct Answer:D
While isolating a bandwidth issue using your
network management system (NMS), you discover that the percent utilization for
an interface is over 100%.What is a possible cause?
A.There is a duplex mismatch on this
interface.
B.The NMS is configured with the wrong
interface speed.
C.The NMS is monitoring too many interfaces.
D.Packet loss is exceptionally high on this
interface.
Correct Answer:B
After making a configuration change to a
gateway router, all of the devices past that router appear down inthe network
management system (NMS). However, the NMS is still gathering CPU and memory
statisticson the devices.What is the first thing you should do to diagnose the
issue?
A.check the configurations of each affected
device
B.check the gateway router configuration for
an access list change
C.check the devices to see if any antivirus is
blocking ICMP
D.check the gateway router configuration to
make sure a default route exists
Correct Answer:B
What is different about how network traffic
statistics are collected using SNMP versus NetFlow?
A.NetFlow is push-based.
B.SNMP samples network traffic.
C.NetFlow traffic is encrypted.
D.SNMP traffic is real-time.
Correct Answer:A
Your network management system (NMS) reports
memory consumption on a server to be 95%. You connect to the server and see a
memory consumption of 80%.What is a possible cause for this inconsistency?
A.WMI has been mis configured on the server.
B.The NMS is using the wrong version of SNMP
to poll the server.
C.The NMS is displaying an average, whereas the
server is displaying real-time data.
D.The NMS is displaying real-time data,
whereas the server is displaying an average.
Correct Answer:C
The network management system (NMS)
has detected that a router has an interface going up and down unexpectedly. You do
not have permissions to log in to the router.Which data, gathered by the NMS,
should you review to help determine the cause?
A.interface utilization
B.Syslog messages
C.previously saved configurations
D.CPU utilization
Correct Answer:B
The application server team reports that the
SQL servers are NOT responding as they normally do. You check the interfaces on
the SQL servers and see that their bandwidth utilization is within normal
limits.What is a likely cause for this SQL application performance disruption?
A.access list change
B.high latency
C.SNMP community string change
D.low interface discards
Correct Answer: B
You notice that several routers are showing
an increase in CPU and memory utilization that is starting to concern you.What
will likely happen if this trend continues?
A.Latency through the routers will increase.
B.The network management system (NMS) will
stop monitoring the routers.
C.Access control lists (ACLs) will be
bypassed by the routers.
D.The routers will deprioritize and drop
packets over 1500 bytes.
Correct Answer: A
The application team at your company has
informed you that they have deployed a new desktop application that
communicates over a specific set of ports. What is the first step to determining
the impact this application is having on your network?
A. check ping times of all of the servers
B .monitor the new application processes on
the servers
C. reconfigure the SNMP agents to use the
application ports
D. configure
the NetFlow collector to monitor the application ports
Correct
Answer: D
You have a hub and spoke network with three
sites. The application servers all located within the headquarters, which is
the hub of the network. Users in spoke site A complain that they cannot get to
the company's accounting server. Users in spoke site Bare not affected. Which
two steps should you take in troubleshooting this issue? (Choose two.)
A. verify that users at the head quarter scan
reach the accounting server
B. verify
that users in site A can access other resources outside of their site
C. verify that users in site B can access
resources in the headquarters
D. verify that the accounting server is
online
E. verify
that the accounting server can access site A
Correct
Answer: BE
You are using NetFlow to analyze the traffic
on your network. You notice that you have a large amount of traffic originating
from various systems in your network destined to a single unrecognized off-net
IP address during otherwise off-peak hours. What is the most likely cause?
A. a new, popular YouTube video being sent
around the office
B. a malware
or virus breakout on your network
C. automated server backups occurring within
your network
D. higher than average VoIP usage from your overseas
sites
Correct
Answer: B
What is a potential root cause of a slow
response time across a WAN circuit?
A. interface re-indexing on a WAN router
B. high disk queue length on the SQL server
C. database
replication across the circuit
D. large database re-indexing
Correct
Answer: C
You are investigating sudden slowness
throughout the network. The routing tables are changing continuously and routes
to many areas of the network are appearing and disappearing with each update .How
should you investigate the cause of this issue?
A.examine the available memory
B.analyze routing protocol packets
C.look for switch ports that are off
D.look for WAN interfaces changing status
Correct Answer:D
What is the most direct way to measure an
application's performance?
A.ping the application server
B.collect application data in NetFlow
C.time application transactions
D.collect application server CPU and memory
statistics
Correct Answer:C
When monitoring the performance of the WAN
connection to a remote site, you notice that latency variesfrom 10 to 1700
milliseconds and that bandwidth utilization is commonly over 90%.Which type of
traffic would be the most adversely affected by this situation?
A.email
B.SNMP polling
C.VoIP
D.Syslog
Correct Answer:C
An executive in your company wants to see
reports from the Orion website. However, Sarbanes Oxley(SOX) rules preclude you
from giving them an account for the website. Which type of access should you
use to allow them to see reports that are sent to them?
A.PassLink
B.PassThrough
C.Guest
D.DirectLink
Correct Answer:D
You have created a new account in the Orion
NPM website that requires that only nodes that contain the string 'Core' in
their host name should be seen. Which two steps should you take in Orion NPM to
accomplish this? (Choose two.)
A.add an Account Limitation based on Node
Name Pattern
B.set the pattern to Core*
C.add an Account Limitation based on Machine
Type pattern
D.set the pattern to *Core*
E.add an Account Limitation based on Single
Network Node
F.set the pattern to *Core
Correct Answer:AD
An Orion NPM web user has requested that a
link to an external website be added to the Orion WebConsole when looking at
devices. However, you want to avoid making global changes toall web users.Which
two steps are required to accomplish this task? (Choose two.)
A.add the resource User Links to the Network
Summary view
B.add the resource Custom HTML or Test to the
Interface Details view
C.assign a custom Node Details view to this
user's account
D.add the resource User Defined Links to the
Node Details view
E.assign an Account Limitation to all other
user accounts
Correct Answer:CD
An Orion NPM user wants to be able to make
changes to the resources as they view them on the Orion Web Console.What must be
done to the user's account?
A.Allow Node Management Rights must be
actived.
B.Allow Admin Rights must be disabled.
C.Allow View Customization must be enabled.
D.An Account Limitation must be defined.
Correct Answer:C
While growing the network monitoring team,
what is the most appropriate way to ensure that the Orion NPM is not over
utilized?
A .create an administrator account for all
users
B. have all users access the server remotely
C. deploy an additional poller
D. deploy an
additional web server
Correct
Answer: D
When planning the deployment of the database
server for Orion NPM, what are two primary considerations? (Choose two.)
A. database clustering
B.RAID
configurations
C.CPU and
memory size
D. type of NIC card used
E. type of RAM
Correct
Answer: BC
As your Orion NPM deployment grows, you need
to add pollers to the system, but due to budgetary constraints, you are unable
to do so. What should you do in the short term to allow you to add a few more elements?
A. adjust
polling intervals
B. adjust data retention
C. reduce the number of reports
D. reduce the number of users
Correct
Answer: A
Which two actions are required to integrate
Engineer's Toolset with the Orion Web Console? (Choose two.)
A.install Tool set on the user's machine
B.install Orion Web Console on the user's
machine
C.enable Allow Administrator Rights on the
user's account
D.enable Allow Browser Integration on the
user's account
E.enable Advanced Customization on the user's
account
Correct Answer:AD
What are two supported ways to integrate
Orion NPM with other network management solutions? (Choose two.)
A.TCL/TK
B.Python API
C.J2EE
D.Syslog
E.SNMP traps
Correct Answer:DE
Which two types of data does Orion NetFlow
Traffic Analyzer collect from network devices? (Choose two.)
A.NBAR
B.NetFlow
C.IP service level agreement (SLA)
D.SNMP
E.sFlow
Correct Answer:BE
Which Orion NPM module allows you to create
user-experience monitors?
A.NetFlow Traffic Analyzer
B.Network Configuration Manager
C.Application Performance Monitor
D.IP Address Manager
Correct Answer:C
You want to monitor a specific device
attribute that Orion NPM does not support by default. Which type of content should
you download from the Thwack Content Exchange?
A.Universal Device Pollers (UnDP)
B.Device Templates
C.Application Monitor Templates
D.Custom Reports
Correct Answer:A
What is the most efficient way to share a
custom report with other Orion NPM users?
A.export a report from Report Writer and then
upload it to the Thwack content sharing zone
B.download a model report from Thwack, and
then paste it in your custom SQL query
C.upload a report to Thwack directly from
System Manager
D.upload a report to Thwack from the Orion
Web Console Report view
Correct Answer:A
When adding a node to Orion NPM, which user
interface allows you to assign a Universal Device Poller (UnDP) as part of the
same workflow?
A.System Manager
B.Web Node Management
C.Network Discovery Wizard
D.Seed File
Correct Answer:B
What should the network engineer do during
scheduled down time to prevent Orion NPM from triggering alerts on the affected
devices?
A.edit the alerts to exclude the devices
B.UN manage the devices
C.suppress any alerts that might be triggered
by the devices
D.suppress the devices
Correct Answer:B
Your company has asked you to expand your
network management to include a new site with several hundred devices, although
you are not sure how many. Using Orion Network Discovery, your top priority is completeness
of discovery.Which two Orion discovery settings should you use to achieve your
goal? (Choose two.)
A.exclude any new subnets found during the
network discovery
B.include any new subnets found during the
network discovery
C.include specific IP addresses through a
seed file
D.decrease the overall speed of the discovery
process
E.decrease the number of SNMP retries
F.increase the overall speed of the discovery
process
Correct Answer:B,D
When you look at utilization graphs for a
given interface, they show greater than 100% utilization. Which interface
configuration change will correct this issue?
A.decrease polling interval
B.increase custom bandwidth
C.increase polling interval
D.decrease custom bandwidth
Correct Answer:B