Summer Sale Special Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: v4s65

299-01 Exam Dumps - Riverbed Certified Solutions Professional - Network Performance Management

Question # 4

The default group type for all Security Policies is:

A.

Application_Servers

B.

ByFunction

C.

ByLocation

D.

Automatic

Full Access
Question # 5

The "Policies Usage" that is reported under System – Information pertains to which of the following:

A.

All Service-based application performance policies

B.

All Service-based policies plus all Performance and Availability analytic policies

C.

All Service-based policies plus all Performance and Availability analytic policies plus all User-Defined Policies

D.

All Service-based policies plus all Performance and Availability analytic policies plus all User-Defined Policies plus all Security policies

E.

None of the above

Full Access
Question # 6

In the Cascade Profiler GUI, what is a Port Group?

A.

A combination of IP Address and Port Number

B.

One or more protocol/port combinations mapped to a name

C.

Names mapped to IP subnets

D.

Layer-2 switch ports grouped into a logical name

E.

NetFlow interfaces grouped into a logical name

Full Access
Question # 7

When creating an analytic service, the discovery process requires a minimum of:

A.

At least three days of data available.

B.

At least three weeks of data available.

C.

The application specialist available.

D.

Some historical data and some starting point (a server, port, application).

E.

A customer network diagram available.

Full Access
Question # 8

What are two differences between NetFlow version 5 and NetFlow version 9 (select 2)

A.

NetFlow version 5 generally support ingress flow export only; NetFlow version 9 supports both ingress and egress export.

B.

NetFlow version 5 is used for Switches, NetFlow version 9 is used for Routers.

C.

NetFlow version 9 includes information about CPU, Power-status and other router performance characteristics; NetFlow version 5 does not.

D.

NetFlow version 9 includes the ability to export the Time-To-Live (TTL); NetFlow version 5 does not.

E.

NetFlow version 9 includes the ability to export the packet latency, NetFlow version 5 does not.

Full Access
Question # 9

Trace clips in Cascade Pilot allow you to:

A.

Save a time window to a trace file for post-capture analysis.

B.

Save a time window and apply Views to analyze a portion of a Capture Job.

C.

Analyze an indexed capture job with Views that support indexing.

D.

Clip a trace file to your desktop.

Full Access
Question # 10

In the Cascade Profiler Dashboard GUI, what types of content blocks can you create? (Select 4)

A.

Watched items (where items are hosts, interface, etc.)

B.

Top items (where items are hosts, interface, etc.)

C.

Top usernames

D.

Unacknowledged Events

E.

Current Events

F.

Last Day Events

Full Access
Question # 11

On Cascade Profiler, in terms of retention of completed reports and reporting sources (one minute flow and rollup files), which of the following is true? (Select 4)

A.

One minute flow records are deleted from the file system FIFO (oldest first) once the appliance has filled the space that is allocated.

B.

There is a fixed amount of space on the filesystem for completed reports.

C.

A report template can be marked "keep until I delete it" so that any reports that are scheduled with this template are not automatically deleted from the filesystem.

D.

When the flows or rollup records have been deleted from the filesystem, any saved report that was generated from those flow sources is no longer available.

E.

Users have the ability to allocate additional space to the 1 min flow logs in order to increase retention. This is done at the expense of other rollup resolutions.

Full Access
Question # 12

What does Cascade use as the flow key to identify a unique flow?

A.

sourceIP, destIP, protocol, sourcePort, destPort, QoS

B.

sourceIP, destIP, protocol, destPort

C.

sourceIP, destIP, protocol, sourcePort, destPort

D.

destIP, protocol, destPort

E.

sourceIP, destIP, protocol

Full Access
Question # 13

What is the typical retention time of packets of a CSK-01100 Cascade Shark appliance with 1 capture job?

A.

About 34 hours with a captured length of 65535 bytes and a packet rate of 400kbps

B.

About 9 hours with a captured length of 1000 bytes and an average traffic rate of 1Gbps.

C.

About 18 hours with a captured length of 65535 bytes and an average traffic rate of 500Mbps.

D.

About 20 hours with a captured length of 500 bytes and an average packet rate of 400kbps.

Full Access
Question # 14

For switch port Discovery on Cascade Profiler what device provides the MAC to IP address mapping?

A.

ARP table on a layer 3 device (router)

B.

CAM (Content Addressable Memory) on a layer 2 device (switch)

C.

Both the ARP and CAM tables from a layer 2 device (switch)

D.

All of the above

E.

None of the above

Full Access
Question # 15

On Cascade Profiler, can you run a traffic report that shows all traffic from inside the network to outside the network, but excludes a proxy server?

A.

No, this cannot be done with Cascade.

B.

Set up the query to ask for all hosts between: Hosts "Within" a group "ByInternalHosts: All" (where All is a host grouping containing all inside address space) and for Peers set to "Outside oF. ByInternalHosts:All".

C.

Configure query as B above but also add the Proxy Server to the "Outside" list.

D.

Configure query as B above but also add the Proxy Server as a "not" in the Traffic Expression field. The expression to add would be "not host proxyhost " where proxyhost is the IP Address of the proxy.

Full Access
Question # 16

Cascade Profiler Dashboard can be configured to show: (Select 3)

A.

The top applications for the previous week.

B.

Only the IPs that a user is authorized to see.

C.

Bandwidth for a host group over the previous day.

D.

Bandwidth for interfaces from devices NOT sending flow data.

E.

Connections for interfaces from devices sending flow data.

Full Access
Question # 17

How does Cascade acquire the Interface Name (ifname) and interface speed (ifspeed) for interfaces reporting to Cascade?

A.

SNMP polling from the Gateway

B.

SNMP polling from the Profiler

C.

SYSLOG

D.

All of the above

E.

None of the above

Full Access
Question # 18

Within Cascade Pilot, Sequence Diagrams allow you to display information between two end points. You have a choice of displaying information for two different layers in the network stack. Descriptions of the sequence diagrams for the two Layers follow: (Select 2)

A.

Layer 1 information. For example, for Ethernet tap points this includes signal levels and attenuation.

B.

Layer 2 information. For example, for Ethernet with 802.1Q encapsulation this includes the VLAN identifier and frame size between MAC Addresses

C.

Layer 3 information. For example, for IPv4 this includes the protocol, time-to-live (TTL), and IP Identifier between IP Addresses

D.

Layer 4 Transport information. For example, for TCP this includes TCP flags, size in bytes, and sequence number between IP Addresses.

E.

Application header information. For example, for Web traffic this includes HTTP methods and message numbers (e.g. "200", "404").

Full Access
Question # 19

A router that has been recently configured to send NetFlow to a Cascade Gateway has yet to appear in the Devices/Interfaces page on the Cascade Profiler. What are the most likely thing to check?

A.

Traffic is being sent across the router's interfaces configured for flow export.

B.

There are no firewalls blocking communication between router and Cascade Gateway.

C.

There are no firewalls blocking communication between Cascade Gateway and Cascade Profiler.

D.

The port being used for export on the router matches that which has been configured on the Cascade Gateway.

E.

All of the above.

Full Access
Question # 20

When initializing data for service metrics or analytics, for what minimum percent of the time must relevant and valid data be present for the service to properly initialize?

A.

25%

B.

50%

C.

75%

D.

100%

E.

None of the above

Full Access
Question # 21

The Cascade Shark de-duplication mode should be used:

A.

To de-duplicate duplicate flows sent to the Cascade Profiler appliance caused by the way different Cascade Shark ports may see the same UDP/TCP sessions.

B.

To de-duplicate duplicate flows sent to the Cascade Profiler appliance caused by use of the Aggregating Port seeing the same UDP/TCP sessions.

C.

To de-duplicate duplicate packets that may be collected by the Cascade Shark caused by the way Port Mirroring is configured on a switch.

D.

To de-duplicate duplicate packets that may be collected by the Cascade Shark caused by the way filtering is used on a capture job.

E.

All of the above

Full Access
Question # 22

What conditions might prevent successful SNMP polling of a flow source? (Select 2)

A.

An ACL might exist on the flow source (router) and the Cascade Standard Profiler IP address is not in it.

B.

SNMP is not enabled.

C.

The correct IP address of the flow source was not entered into the GUI.

D.

The SNMP read string provided and entered might not be correct.

E.

The flow source is not using the same NTP source as the Cascade Gateway.

Full Access
Question # 23

A user wants to use the link congestion analytic policy on Cascade Profiler to monitor five key WAN links for an increase in traffic outside of the expected traffic that includes TCP/80, TCP/443, TCP25, and UDP/53. Can the link congestion policy be used for this scenario?

A.

No, because a link analytic can monitor only a single interface.

B.

Yes, one can define separate link congestion analytic policies for each WAN interface.

C.

No, because one can only define specific ports to include on a link congestion policy.

D.

Yes, because one can define a port group that includes every UDP and TCP port except for those that include the expected traffic, and that port group can be used for the link congestion analytic policy.

E.

No, and both A and C include valid reasons.

Full Access
Question # 24

On the Cascade Shark appliance, packet de-duplication should be enabled when:

A.

Capturing packets from a SPAN-Port/Port-Mirror whose configuration may generate duplicate packets

B.

Capturing packets from an aggregating TAP

C.

Removing duplicate flows across multiple interfaces

D.

Capturing packets from a 10GB link

Full Access
Question # 25

If a report table on Cascade Profiler includes the "Server Delay" column but shows no value for "Server Delay" in some cells, what are the possible causes? (Select 3)

A.

The time span of the report does not cover any connection set-up points

B.

Server delay is zero.

C.

The protocol used by the application in not TCP-based.

D.

Application traffic was not seen by a Cascade Sensor.

E.

The server plug-in is needed to measure "Server Delay" and not functioning correctly.

Full Access
Question # 26

An interactive view within Cascade Pilot:

A.

Can be created from a single applied View.

B.

Can work on local trace files only.

C.

Can include more than two charts.

D.

Is not available in the regular Cascade Pilot installation.

Full Access
Question # 27

For DNS reverse lookup, Cascade Profiler caches as follows:

A.

Cache the most recent 500 IPs.

B.

Obey DNS TTLs.

C.

Cascade does not cache DNS responses.

D.

For 24 hours.

Full Access
Question # 28

Which of the following are valid syntax for host group definitions on Cascade Profiler? (Select 2)

A.

192.168.66.* Web Servers

B.

192.168.0.100/255.255.0.255 Database_Servers

C.

192.168.14.0/24 Mail_Servers

D.

192.168.*.* Boston

Full Access
Question # 29

What can be configured on the Cascade Profiler to detect utilization for an interface? (Select 2)

A.

Manually configure the interface speeds on the Devices/Interfaces page.

B.

Configure and enable SNMP access to the reporting devices on the Devices/Interfaces page.

C.

Enable NBAR on the routers.

D.

Check the "Interface Utilization" box under the Devices/Interfaces page for each router and/or Steelhead desired.

E.

Configure the appropriate Device Interface Analytic.

Full Access
Question # 30

What must happen prior to running WAN Optimization reports on Cascade Profiler?

A.

Host Groups must be configured.

B.

Cascade Profiler must be successfully polling Steelhead appliances via SNMP.

C.

The WAN-Steelhead interface group must be populated with WAN interfaces for all Steelhead appliances.

D.

The Profiler baseline collection must be complete.

E.

A WAN Optimization reporting template must be configured.

Full Access
Question # 31

Within Cascade Pilot, Sequence Diagrams represent TCP Errors in which of the following ways: (Select 2)

A.

By listing lost packets in the expert window

B.

By using dotted-dashed lines for out-of-sequence segments

C.

By placing error names on the messages within the diagram

D.

By color-coding the messages on the diagram

E.

By using a thicker line for messages that include errors

Full Access
Question # 32

Which Cascade device is capable of sending flow data to more than one Cascade Profiler? (Select 3)

A.

A Cascade Standard Profiler

B.

An Cascade Enterprise Class Profiler (only from the Dispatcher Module)

C.

A Cascade Shark appliance

D.

A Cascade Gateway

E.

A Cascade Express Profiler

Full Access
Question # 33

The Cascade Profiler account roles arE. (Select 5)

A.

Administrator

B.

Operator

C.

Monitor

D.

Dashboard Viewer

E.

dbadmin

F.

Event Viewer

Full Access
Question # 34

Cascade provides a means for contacting other network devices for additional information about a host or user of interest. Right-clicking a host name, IP address, MAC address or port number and choosing _________________ from the shortcut menu sends a query to the other network device.

A.

View Packets

B.

Error Report

C.

Restart Service

D.

View Switch Port

E.

External Link

Full Access
Question # 35

When troubleshooting a Steelhead deployment with Cascade you suspect that you may have packet ricochet. Since you are exporting CascadeFlow from the Steelheads to the Cascade how can you use Profiler to see if there actually is packet ricochet?

A.

Identify connection duration.

B.

Look for high server side packet counts.

C.

Look for high number of reset.

D.

Run a report with a Connection Graph.

E.

Run a report on the WAN Interface of the Steelhead.

F.

Run a report with Flow List and look at the topology columns.

Full Access
Question # 36

Which of the following are true about Trend/Index data on a Cascade Shark appliancE. (Select 3)

A.

Allows Cascade Pilot to load views that take advantage of the Index more quickly.

B.

Includes the number of bytes and packets for each conversation seen by the Cascade Shark appliance.

C.

It is configured on a per-port basis.

D.

It is configured using the sa-wizard as part of the initial configuration.

E.

It is enabled by default per capture job.

Full Access