299-01 - Riverbed Certified Solutions Professional - Network Performance Management Exam
Go back to Riverbed
How do all the Cascade components stay time synchronized?
The Profiler, ideally, points to an NTP server (although it can use local time as well), the Gateway and Sensor get their time information from the Profiler which acts as their NTP Server.
What data do I need from netflow sources for the Cascade Profiler report-by "network segments" to work correctly?
NetflowV9 with TTL export configured.
On Cascade Profiler, what is the purpose of a Service Segment when creating a new service?
A service segment is defined by its components and the applications and/or ports in use between them.
Additional data sources that Cascade Profiler can leverage besides flow data arE. (Select 3)
Active Directory information for successful/failed login association to IPs
DHCP for host IP to MAC address association.
SNMP polling to routers and switches for MAC address and physical switch port association.
In defining a user defined policy on Cascade Profiler that triggers when the aggregate connection rate from any internal host to all external hosts exceeds a certain threshold, one has entered "within internal" for host/group A and "outside internal" for host/group B. How should the statistics be tracked for host/group A and B?
host/group A "track per host" host/group B "track in aggregate".
One advantage of using a trace clip for analysis within Cascade Pilot instead of its parent capture job trace is:
The trace clip is likely smaller in size, so views load faster.
What report on Cascade Profiler would be used to show both sides of a conversation and the ports they communicated on?
Host Pairs and Ports
Which configuration screen or screens are edited on the Cascade Shark to change names used by certain ports within various views on Cascade Pilot:
Port/Protocols Names and Port/Protocols Groups under the Port/Protocol Definition menu
How does Cascade Profiler track URL's?
Customer defined URL's are mapped to an application name which can then be shown on the dashboard, searched via reporting, or used in Analytic definitions.
Cascade Profiler Dashboard can be configured to show: (Select 3)
The top applications for the previous week.
Bandwidth for a host group over the previous day.
Connections for interfaces from devices sending flow data.
For an analytic policy that monitors TCP retransmission bandwidth, which of the following best describes what is minimally required before a baseline can be established?
Three days of historical traffic between the clients and servers defined on the policy, where retransmissions were reported in more than 50% of the 15 min windows over the three day period.
How many SNMP recipients can receive a single event notification for Cascade Profiler?
Which Cascade device is capable of sending flow data to more than one Cascade Profiler? (Select 3)
A Cascade Shark appliance
A Cascade Gateway
A Cascade Express Profiler
Which of the following best describes any limits that are enforced on the number of service, performance and availability policies that are supported on any Cascade Profiler?
Stratified policy limits ranging from 5000 for Cascade Profiler Express platforms to 10,000 for Cascade Enterprise Profiler platforms
Voice over IP (VoIP) monitoring by Network Performance Management systems typically includes, but is not limited to, the following metrics (select 3):
MOS scores voice quality issues
Which of the following is information that Netflow v5 provides to the Cascade solution? (Select 2)
End time of Flow
Layer 4 Protocol Type
What does Cascade use as the flow key to identify a unique flow?
sourceIP, destIP, protocol, sourcePort, destPort
Trace clips in Cascade Pilot allow you to:
Save a time window and apply Views to analyze a portion of a Capture Job.
Cascade dependency mapping (Connection Graphs) have multiple 'layouts' for showing dependencies. Which of the following is not an option?
Which of the following types of hosts are included in Cascade grouping on Cascade Profiler?
Internal hosts only
Within Cascade Pilot, when packet capture (pcap) files have associated trending/indexing data the following are true (select 2)
Views that take advantage of the trending/indexing data load faster.
The file icon includes a colored-lightning bolt.
Hosts that do not match group definitions within a group type are:
Not placed into a group within the group type.
If unable to connect to the Cascade Shark Appliance from the Cascade Pilot console it could be becausE. (Select 2)
The correct communication port(s) are NOT open on the firewall between Cascade Pilot and Cascade Shark.
You may be running Cascade Pilot-Personal-Edition (PE). You need the full version of Cascade Pilot to connect to Cascade Shark.
Cascade Performance analytic event detail reports include multiple tables that are ordered by:
The client or server that has changed the most (for the table metric) from the baseline (for example, impact).
What information is required to configure the Switch Port Discovery feature in the Cascade Profiler? (Select 2)
IP address of the outermost switches
IP address of the lookup router
On Cascade Profiler, Which of the following account role permissions is not unique to administrator accounts?
Creating or modifying custom host groups.
An interactive view within Cascade Pilot is useful for:
Interactively connecting charts from 2 or more views.
The Cascade Shark de-duplication mode should be used:
To de-duplicate duplicate packets that may be collected by the Cascade Shark caused by the way Port Mirroring is configured on a switch.
How many signatures can a Layer-7 Fingerprint have?
Which parameters can be used to set up an Application Performance analytic on Cascade Profiler?
Applications, Ports/Protocols, QOS, Servers, Clients
Within the Cascade Pilot GUI, the following filter types are availablE. (Select 3)
Wireshark display filter
Cascade Pilot Filter
A router that has been recently configured to send NetFlow to a Cascade Gateway has yet to appear in the Devices/Interfaces page on the Cascade Profiler. What are the most likely thing to check?
All of the above.
Which version of SNMP is supported for Switch Port Discovery on Cascade Profiler?
SNMPv1 and SNMPv2
Which Cascade device actually polls for the SNMP information in the switch port Discovery process?
What is the maximum number of Cascade Profilers that can be configured in the Cascade Shark appliance as receivers of flows?
How is QoS data obtained in a Cascade Profiler? (Select 2)
From packets via the Cascade Sensor or Shark
From NetFlow and other standard flow protocols
What is the chart granularity possible through the Cascade Pilot UI? (Select 2)
1 millisecond for specific Views.
Generally minimum 1 second, maximum 1 day.
If you use overlapping IP address ranges (for example 10.0.0.0/8, 10.1.2/16, and 10.2.3/24) in a host group definition on Cascade Profiler which of the following is true?:
The Profiler assigns a host to the custom group whose definitions has the longest matching prefix.
Within the Cascade Pilot GUI, filtered items are often indicated:
With a funnel icon.
You can analyze data on Cascade Pilot received from live interfaces iF. (Select 2)
Cascade Pilot is started with administrator privileges.
You have privileges to do so in your user profile.
If a VLAN SPAN (VLAN101) is configured and monitored by Cascade Shark, which of the following is true? (Select 2)
Both inter and intra VLAN101 traffic will be monitored.
It is a best practice to configure the Cascade Shark monitoring port (the SPAN destination) with 'deduplication' enabled.
If a report table on Cascade Profiler includes the "Server Delay" column but shows no value for "Server Delay" in some cells, what are the possible causes? (Select 3)
The time span of the report does not cover any connection set-up points
The protocol used by the application in not TCP-based.
Application traffic was not seen by a Cascade Sensor.
When designing a Cascade deployment which of the following is important to consider about sizing?
The primary measures are flow-rate and topology. Flow-rate drives the size of the solution; topology can determine the placement of Sensors. As a secondary sizing method we can use host count and rule-of-thumb host/flows ratio to estimate the flow-rate.
What are three ways Cascade Shark can monitor packet data in an environment: (Select 3)
Connect a capture port to a Port mirroring monitor port (also referred to as a SPAN port).
Connect two capture ports to a passive network tap on a live link. One capture port is used for each direction of the link.
Connect two capture ports across a link connected to a SPAN port already being used for packet capture to another type of monitoring device and place Cascade Shark in "passthru" mode.
Why should all flow exporting devices use the same NTP (Network Time Protocol ) source?
Essential for the flow de-duplication process.
On an Enterprise Profiler, which Cascade software module usually runs on hardware with another software module, but can be placed on its own hardware to support extremely large clusters?
Which of the following is a valid group definition on Cascade Profiler? (Select 4)
What is the maximum limit of configurable flows that can be exported from the Cascade Shark appliance? (Select 2)
500,000 flows per minute per port
600,000 flows per minute total
The "Policies Usage" that is reported under System Information pertains to which of the following:
All Service-based policies plus all Performance and Availability analytic policies
When links in a network are using WAN optimization, it is best if the Cascade Profiler or Express receives data from a _________or _________ monitoring traffic on the LAN side of the Steelhead that is located on the server side of the optimized connection. This is necessary in order to determine server delay. (Select 2)