Sie sind auf Seite 1von 120
Vendor : Riverbed Exam Code : 199 - 01 Version : 9.0 Cheat-Test ,help you

Vendor

: Riverbed

Exam Code : 199-01

Version : 9.0

Cheat-Test,help you pass any IT exam!

Topic 1, Volume A

Cheat-Test.com Q: 1

You can monitor your Steelhead appliance disk performance using which reports? (Select 2)

A. Data Store Cost

B. Data Store Performance

C. Disk Load

D. SDR Hit

E. Disk Pressure

F. Disk Alarm

Answer: A,C

Cheat-Test.com Q: 2

What happens to traffic when a Steelhead appliance reports admission control?

A. Traffic will be interrupted

B. The Steelhead stops the interception of new connections for optimization for as long as it is in

admission control

C. This is just a report and the Steelhead will continue to optimize traffic

D. The Steelhead will start optimizing faster any new connections

E. The Steelhead will shut down in less than a minute

Answer: B

Cheat-Test.com Q: 3

Why should you use promiscuous mode on each in-path virtual NIC for Virtual Steelhead appliance? (Select 2)

A. For LAN/WAN Virtual NICs to intercept traffic not destined for the virtual machine

B. This configuration is mandatory for traffic optimization

C. Promiscuous mode is not required

D. Only verbose mode should be configured

E. Only regular mode should be configured

Answer: A,B

Cheat-Test.com Q: 4

What deployment type supports fail-to-wire?

A. Physical in-path

B. Virtual in-path

C. Out-of-path

D. Virtual Steelhead appliance

E. Proxy file server

Answer: A

Cheat-Test.com Q: 5

Can you optimize FTP using Steelhead Mobile?

A. Yes, this is possible on all FTP modes

B. When using active FTP

C. When using passive FTP

D. It is not possible to optimize FTP traffic

E. Only when there is no firewall enabled

Answer: C

Cheat-Test.com Q: 6

Where are SDR references maintained on a Steelhead appliance?

A. Persistent storage

B. USB keys

C. Flash storage

D. RSP partition

E. Configuration file

Answer: A

Cheat-Test.com Q: 7

Which of the following features are available with the Virtual Steelhead appliance? (Select 2)

A. RSP

B. HSTCP

C. Fail-to-wire

D. PFS

E. Datastore synchronization

Answer: B,E

Cheat-Test.com Q: 8

What of the following are true when deploying the Virtual Steelhead appliance? (Select 2)

A. Only use 10 Gbps link

B. Never reserve virtual CPU

C. Do not over provision physical RAM

D. Always use SSD drives

E. Do not share physical NICs

Answer: C,E

Cheat-Test.com Q: 9

What information does the OVA package include about the Virtual Steelhead appliance? (Select 4)

A. Virtual disks

B. CPU

C. Memory

D. License

E. Storage

Answer: A,B,C,E

Cheat-Test.com Q: 10

When deploying a Virtual Steelhead appliance, how much extra memory should be allocated for the extra VMware overhead?

A. 3%

B. 4%

C. 5%

D. 10%

E. 2%

Answer: C

Cheat-Test.com Q: 11

What are the possible ways to downgrade a Virtual Steelhead appliance after it has been upgraded?

A. Remove the upgrade license and restart the virtual Steelhead appliance

B. Reinstall the original model license

C. Reduce the amount of CPU and RAM allocated to the Virtual Steelhead appliance and it will

automatically downgrade at the next startup

D. It is not possible to downgrade after an upgrade

Answer: D

Cheat-Test.com Q: 12

When upgrading a Virtual Steelhead appliance, what steps can be taken to preserve the existing datastore?

A. When upgrading a Virtual Steelhead appliance, it is not possible to preserve the existing

datastore

B. Detach the existing datastore and re-attach to the new Virtual Steelhead appliance

C. Run vMotion and move the datastore to a different ESX host before performing the upgrade

and then bring it back afterwards

D. Move the existing datastore to an NFS share and move it back after the upgrade

Answer: A

Cheat-Test.com Q: 13

The amount of memory required for Steelhead Mobile installation varies between 81 MB to 228 MB. What is the reasons for the variation?

A. Number of TCP connections

B. Types of application

C. Datastore size

D. Bandwidth

E. All of the above

Answer: C

Cheat-Test.com Q: 14

What platform is supported by SMC-VE?

A. ESX 3.5

B. ESX 4.0

C. ESX 4.1

D. RSP

E. HyperV

Answer: D

Cheat-Test.com Q: 15

Which of the following are Steelhead Mobile Controller alarms? (Select 2)

A. Memory paging

B. Datastore errors

C. Peer version mismatch

D. SSL errors

E. File system full

Answer: A,E

Cheat-Test.com Q: 16

Which of the following is Endpoint alarm?

A. Locked secure vault

B. Firewalled status

C. Network interface error

D. Temperature

E. Memory paging

Answer: B

Cheat-Test.com Q: 17

After upgrading the Steelhead Mobile Controller to the latest software release, it requires a reboot. During the reboot, what would happen to the users connected to the Steelhead Mobile Controller via the Steelhead Mobile client?

A. All optimization ceases to function

B. Existing connections are reset, but subsequent connections will be optimized

C. The Steelhead Mobile client informs the user to reboot their computer

D. No disruption to the end user

E. Only Layer 7 optimization is affected; all other optimization remain unaffected

Answer: D

Cheat-Test.com Q: 18

When configuring SSL optimization for Steelhead Mobile clients, what step must be taken?

A. Mutual exchange of public keys between the Steelhead Mobile Controller and the server-side

Steelhead appliance

B. Mutual exchange of private keys between the Steelhead Mobile Controller and the server-side

Steelhead appliance

C. Generate a self-signed certificate for the Steelhead Mobile Controller and import that on the

client PCs

D. Import the server's public and private keys to the Steelhead Mobile Controller

E. Generate individual certificates for each PC and manually import the public key on the

Steelhead Mobile Controller

Answer: A

Cheat-Test.com Q: 19

Which of the following deployments is incompatible with the Branch Warming feature?

A. In-path

B. Virtual in-path

C. Out-of-path

D. WCCP

E. PBR

Answer: C

Cheat-Test.com Q: 20

In a WCCP cluster using mask assignments, if there are six Steelhead appliances in the cluster, what is the minimum number of bits that should be used?

A. 1

B. 3

C. 5

D. 6

E. 7

Answer: B

Cheat-Test.com Q: 21

When is it necessary to configure the SRDF Module rules? (Select 2)

A. Traffic originated between two EMC DMX arrays

B. Traffic originated from the Symmetrix FC ports (RF ports)

C. Traffic originated from the Symmetrix GigE ports (RE ports)

D. Traffic originated between two EMC V-Max arrays

Answer: C,D

Cheat-Test.com Q: 22

It is not recommended to use the same Steelhead appliance to optimize both replication traffic and general user traffic because:

A. Replication traffic uses 16 KB blocks and causes fragmentation in the datastore

B. User traffic may contain sensitive traffic and should not be mixed with other traffic

C. Replication traffic may cause admission control therefore affecting user traffic

D. The traffic pattern between the two types of traffic is generally very different and therefore the

datastore may wrap more quickly affecting performance

Answer: D

Cheat-Test.com Q: 23

The client-side Steelhead appliance has been configured for OOB Destination Transparency, what should the source IP/port be for the OOB connection?

A. Client IP/random port

B. Client-side Steelhead appliance in-path IP/random port

C. Client IP/port 708

D. Client-side Steelhead appliance in-path IP/port 708

E. None of the above

Answer: B

Cheat-Test.com Q: 24

You have outgrown your current Steelhead appliance and want to copy the datastore from your exiting Steelhead 550 appliance to a new 2050 Steelhead appliance. What feature would you use to synchronize the different model Steelhead appliance datastores?

A. Export/Import operation function

B. Copy the datastore file system

C. “datastore send” command

D. Copying the configuration files

E. This cannot be done on Steelhead appliances

Answer: E

Cheat-Test.com Q: 25

When upgrading from a Steelhead 5050 appliance to a Steelhead 6050 appliance what can be migrated to the new appliance? (Select 2)

A. Datastore

B. Licenses

C. Network configuration

D. Optimization configurations

E. Serial numbers

Answer: C,D

Cheat-Test.com Q: 26

When configuring failover, in what manner must you configure your Steelhead appliances?

1) Master/Backup

2) Primary/Secondary/Tertiary

3) Master/Master

4) Backup/Backup

5) Primary/Principle

A. 1

B. 2

C. 3, 4

D. 1, 3, 4

E. 1, 2, 3, 4, 5

Answer: A

Cheat-Test.com Q: 27

Two Steelhead appliances deployed in-path at different offices cannot auto-discover each other. What technique can be used to “force” the two Steelhead appliances to optimize traffic between each other?

A. Change the TCP port the Steelhead appliances use for their in-path connections to 7810

B. Disable the auto-discovery feature on the Steelhead appliances

C. Create auto-discovery rules that map to each Steelhead appliance's in-path IP address

D. Create fixed-target rules on each Steelhead appliance using the in-path IP address of the other

Steelhead appliance, and use port 7800

E. Use the “enable probe” command from the CLI

Answer: D

Cheat-Test.com Q: 28

Three Steelhead appliances SH1, SH2, and SH3 are deployed as shown in the exhibit. They are all using the default auto-discovery rule for optimization. However, CLIENT99 experiences a fail- ure when attempting to access either the HTTP or FTP service on SERVER88. CLIENT99 was able to access these services prior to the deployment of the three Steelhead appliances.

Which of the following choices would most likely correct the problem? A. Remove SH2. Use

Which of the following choices would most likely correct the problem?

A. Remove SH2. Use only SH1 and SH3.

B. Remove SH1. Use only SH2 and SH3.

C. Turn on Connection Forwarding between SH1 and SH2

D. Turn on Connection Forwarding between SH1 and SH3

E. Turn on Connection Forwarding between SH2 and SH3

Answer: C

Cheat-Test.com Q: 29

In creating a customized Steelhead Mobile client MSI package, what is the Group ID (GID) used for?

A. Organization of groups

B. Configuring individual Steelhead Mobile client users with different license groups

C. Configuration of fixed-target rule groups

D. Configuration of pass-through rule groups

E. All of the above

Answer: A

Cheat-Test.com Q: 30

What is configured in an Acceleration policy? (Choose the best answer)

A. Redundant Steelhead Mobile Controllers

B. In-path rules

C. Group IDs

D. Port labels

Answer: B

Cheat-Test.com Q: 31

What is configured in an Endpoint policy? (Choose the best answer)

A. Redundant Steelhead Mobile Controllers

B. In-path rules

C. Group IDs

D. Port labels

Answer: A

Cheat-Test.com Q: 32

What ports are required for proper operation of the Steelhead Mobile client?

A. 7800 outbound, 7801 inbound, 7870 outbound

B. 7800 inbound, 7870 inbound, 7870 outbound

C. 7800 inbound, 7801 outbound, 7870 outbound

D. None of the above

Answer: A

Cheat-Test.com Q: 33

A Steelhead Mobile client can be configured to operate in visible or invisible mode (show client in system tray parameter). What part of the configuration is this setting included?

A. Acceleration policy

B. Authentication policy

C. Endpoint policy

D. Port labels

Answer: C

Cheat-Test.com Q: 34

What are the SSL trusts that must be configured for a Steelhead Mobile client to successfully optimize SSL traffic? (Select 2)

A. Steelhead Mobile clients trust Steelhead Mobile Controller

B. Server-side Steelhead trusts Steelhead Mobile clients

C. Steelhead Mobile clients trusts client-side Steelhead

D. Client-side Steelhead, server-side Steelhead, Steelhead Mobile clients, and CMC appliance all

must trust each other

Answer: A,B

Cheat-Test.com Q: 35

If the VPN concentrator that a Steelhead Mobile client connects to is not in path with a Steelhead appliance, what changes could be made to the Riverbed infrastructure to allow optimization from the Steelhead Mobile clients?

A. Enable out-of-path support on server-side Steelhead

B. Add a fixed-target rule in the Steelhead Mobile Acceleration policy

C. Enable peering rule in Steelhead Mobile client

D. B and C

E. A and B

Answer: E

Cheat-Test.com Q: 36

For a Steelhead Mobile solution to work properly, what port needs to be allowed by the device that Steelhead Mobile is installed on?

A. 7800

B. 7810

C. 7801

D. 7830

E. 7840

Answer: C

Cheat-Test.com Q: 37

What service needs to be allowed if you are enforcing outbound security in the Steelhead Mobile solution?

A. rbtdebug.exe

B. rbtmon.exe

C. shmobile.exe

D. rbtsport.exe

E. All of the above

Answer: E

Cheat-Test.com Q: 38

On the Steelhead Mobile Controller, what VPNs require the use of Reorder Intermediate Drivers? (Select 2)

A. Nortel VPN

B. Cisco VPN client

C. Check Point

D. OpenVPN

E. Riverbed VPN client

Answer: A,C

Cheat-Test.com Q: 39

On the Steelhead Mobile Controller, what is the default setting of Reorder Intermediate Drivers?

A. Enabled

B. Disabled

C. Offline

D. Online

E. Checked

Answer: B

Cheat-Test.com Q: 40

How can you provide updates to multiple Steelhead Mobile clients at the same time? (Select 2)

A. Using profiles

B. Using multiple Steelhead Mobile Controllers

C. Using Group IDs

D. Using policies

Answer: C,D

Cheat-Test.com Q: 41

On the Steelhead Mobile Controller, when should you use the CIFS option 'Disable Write Optimization'?

A. When the Steelhead Mobile client does frequent writes to large files

B. An application that expects write-through without asking for it explicitly

C. To increase performance during large updates to files

D. To reduce datastore usage on busy Steelhead Mobile clients

E. To increase performance during directory listings

Answer: B

Cheat-Test.com Q: 42

Which authentication methods are available to the Steelhead Mobile Controller?

A. Local and LDAP

B. Local, NIS, and LDAP

C. Local, RADIUS, and TACACS+

D. Local, RADIUS, and Active Directory

E. NTLM and Kerberos

Answer: C

Cheat-Test.com Q: 43

What information is available in the System Snapshot files on the Steelhead Mobile Controller?

A. A copy of all memory

B. A copy of hardware registers

C. Status indicators

D. System configs and tcpdumps

E. A, B, and C

Answer: E

Cheat-Test.com Q: 44

When using SSL, what is the purpose of peer authentication?

A. Register peers

B. Confirm the identity of the peer

C. Establish sessions

D. Verify the user permissions

E. Authenticate the client to the server

Answer: B

Cheat-Test.com Q: 45

How does the Steelhead Mobile Controller provide Steelhead Mobile clients with the assigned policies and policy updates?

A. Using the GID

B. Using the SID

C. Policies are pushed to all clients using IPSec

D. The Steelhead Mobile client needs to be re-installed to update the policies

E. Upon connection to the Steelhead appliance

Answer: A

Cheat-Test.com Q: 46

The Steelhead Mobile client on your laptop is showing a status of “Firewalled”. What is the problem?

A. Port 7800 is being blocked between the Steelhead Mobile Controller and the Steelhead

appliance

B. Port 7810 is being blocked between the Steelhead Mobile client and the Steelhead appliance

C. Port 7801 is being blocked between the Steelhead Mobile client and the Windows TCP Stack

D. Port 7850 is being blocked between the Steelhead Mobile Controller and the Steelhead

appliance

E. Port 7801 is being blocked between the Steelhead Mobile Controller and the Steelhead

appliance

Answer: C

Cheat-Test.com Q: 47

The Group ID (GID) links which two policies? (Select 2)

A. Optimization

B. Acceleration

C. Installation

D. Endpoint

E. Assignment

Answer: B,D

Cheat-Test.com Q: 48

You would like your Steelhead Mobile clients to automatically detect when they are in a branch office with a local Steelhead. You have decided that the Steelhead Mobile Client should only optimize connections if the Steelhead appliance is more than 10 ms away. What is the name of the feature you need to enable?

A. Adapter location awareness

B. Latency licensing awareness

C. Optimization awareness

D. Branch office self-awareness

E. Latency-based location awareness

Answer: E

Cheat-Test.com Q: 49

To verify that the Steelhead Mobile client software is running, what process should you look for in the Windows Task Manager?

A. rbtsport.exe

B. taskmgr.exe

C. svchost.exe

D. services.exe

E. rivmobile.exe

Answer: A

Cheat-Test.com Q: 50

A customer with no Steelhead appliances currently deployed wants to test Steelhead Mobile on a client that connects to corporate through a VPN over the Internet. The customer has the requirement that there be no network disruptions during the initial testing phase. Which of the following would work?

A. Place a Steelhead appliance in-path behind the WAN router and have the Steelhead Mobile

client use auto-discovery rules

B. Use server-side out-of-path with a Steelhead and use fixed-target rules on the Steelhead

Mobile clients

C. Place a Steelhead in-path directly behind the VPN gateway and use auto-discovery on the

Steelhead Mobile client

D. Use server-side out-of-path with the Steelhead Mobile Controller and use a fixed-target on the

Steelhead Mobile client

E. Place the Steelhead Mobile Controller in-path directly behind the VPN gateway and use auto-

discovery on the Steelhead Mobile client

Answer: B

Cheat-Test.com Q: 51

Refer to the exhibit.

client Answer: B Cheat-Test.com Q: 51 Refer to the exhibit. What configuration option is most relevant

What configuration option is most relevant on Steelhead A to enable Steelhead Mobile Client R to set up the most efficient optimized connection to Server B?

A. Enhanced auto-discovery

B. Simplified Routing

C. no in-path peering manual enable

D. in-path rule pass rulenum start

E. in-path peering rule pass rulenum 1

Answer: A

Cheat-Test.com Q: 52

Refer to the exhibit.

Answer: A Cheat-Test.com Q: 52 Refer to the exhibit. What option in the Acceleration policy used

What option in the Acceleration policy used on Steelhead Mobile Client A will most likely enhance the users experience connecting to Server B, if Server B is an Exchange 2003 Server?

A. Enable MAPI NSPI

B. Increase the datastore size

C. Enable latency-based location awareness

D. Enable SSL optimization and import the Exchange certificate for Server B into Steelhead B

E. Peering rule rejecting optimization with Steelhead A

Answer: C

Cheat-Test.com Q: 53

Refer to the exhibit.

If Server A is an FTP server, which setting will enable active FTP optimization on

If Server A is an FTP server, which setting will enable active FTP optimization on Steelhead Mobile Client R?

A. in-path auto srcport 20

B. SteelheadA.in-path auto dstport 20

C. Client R: in-path auto dstport 20

D. Default auto-discovery rules will work

E. None of the above

Answer: E

Cheat-Test.com Q: 54

Refer to the exhibit.

If Steelhead Mobile Client B offers up a share on the network, what is needed

If Steelhead Mobile Client B offers up a share on the network, what is needed on Steelhead Mobile Client R to open an optimized connection to this share if enhanced auto-discovery is enabled on all Steelhead appliances?

A. Default auto-discovery will work fine without modification

B. The connection to Client B cannot be optimized because the Steelhead Mobile Controller

cannot optimize incoming connections

C. A fixed-target rule to Client B's IP address is needed in order for optimization to occur on

Mobile Client B

D. The addition of a peering rule

Answer: A

Cheat-Test.com Q: 55

Company X has many offshore oil rigs they want to bring optimization to. The only available connection is through a satellite that has frequent bursts of packet loss. There are very few users per rig and HTTPS-based SharePoint performance is so poor they often time out pulling down even a small file. CIFS often does not work at all. They are considering the Steelhead Mobile solution to solve this problem. You suggest they deploy a Steelhead in-path at the data center and:

A. Steelhead Mobile with FEC turned on to help with lossy links

B. Steelhead Mobile with HS-TCP configuration

C. Steelhead Mobile running MX-TCP to deal with the loss

D. Deploy Steelhead appliances with MX-TCP to deal with the loss

E. Deploy Steelhead appliances with HS-TCP, Window Scaling, fixed-target rules, and TCP New

Reno to overcome the loss

Answer: D

Cheat-Test.com Q: 56

Is any user data sent across the out-of-band (OOB) connection of a Steelhead appliance?

A. No data is sent across this connection

B. Yes, only after 60 seconds

C. Yes, when the peer Steelhead appliance requests information

D. Yes, when the connection is setup

E. Yes, every 30 seconds

F. Yes, every 30 minutes

Answer: A

Cheat-Test.com Q: 57

A customer's network consists of a data center with an Interceptor appliance and a Steelhead

appliance cluster and several remote sites each with Steelhead appliances.

You would like to pass-through an application unoptimized due to a suspected problem and are provided the following information:

The application uses a static TCP port, 15000.

The application is initiated from the remote site machines.

The same servers which host the application host several other applications as well.

Based on the information provided which option will allow the application to pass-through:

A. Configure in-path rules on the Interceptor appliance to pass-through destination TCP port

15000

B. Configure in-path rules on the data center Steelhead appliances to pass-through the server IP

addresses

C. Configure a peering rule on the Interceptor appliance to pass-through destination TCP port

15000

D. Configure a load-balancing rule on the Interceptor appliance to pass-through destination TCP

port 15000

E. Stop the Interceptor appliance service

Answer: D

Cheat-Test.com Q: 58

A firewall at a remote site on the WAN side of Steelhead appliance (A) is stripping out the 76 and

78 values in the TCP options field. Steelhead appliance (B) is in the local cluster of appliances communicating with an Interceptor appliance. The desired result is for optimization to continue between Steelhead appliance (A) and Steelhead appliance (B) for all traffic originating from the remote site. A suggestion is made to use fixed target rule(s) to meet this objective. Based on the information provided select the best answer from the choices below:

A. On Steelhead appliance (A) configure a fixed-target rule to the Interceptor in-path address

B. On Steelhead appliance (A) configure a fixed target rule to the Interceptor in-path address with

Steelhead appliance (B) as the backup target.

C. On Steelhead appliance (A) configure a fixed target rule to the Steelhead appliance (B) in-path

address

D. Fixed target rules will not work with Steelhead appliances virtually out of path and

communicating with Interceptors

E. TCP option 76 or 78 are not relevant when an Interceptor appliance is used, Peer Affinity will

automatically achieve this objective

Answer: C

Cheat-Test.com Q: 59

A customer would like to deploy the Interceptor appliance on four aggregated 100 Mbps links

which use LACP to bundle the physical links into a single logical link. Which of the following is

true? (Select 2)

A. LACP is not supported with the Interceptor appliance

B. The command “in-path multi-interface enable” must be configured

C. The same IP address must be configured on each of the four in-path interfaces

D. Each In-path interface should have its own unique IP address.

E. The command “no arp filter response” should be enabled.

Answer: D,E

Cheat-Test.com Q: 60

In a quad Interceptor appliance deployment the directly connected pairs are configured in failover modE.

IC-A & IC-B are failover buddies

IC-C & IC-D are failover buddies

To prevent asymmetric routing IC-A should be configured to have a neighbor relationship with which of the following peer Interceptors? (Select 2)

A. IC-B

B. IC-C

C. IC-D

D. Interceptor appliance uses auto discovery to learn about each other

E. Neighbor relationships are unnecessary in a quad Interceptor appliance deployment

Answer: B,C

Cheat-Test.com Q: 61

The primary data center Interceptor is configured to fail-to-block. What best describes the result of stopping the Interceptor appliance service?

A. All traffic passes through the Interceptor appliance

B. The Interceptor allows UDP traffic to pass-through, but blocks all TCP traffic

C. Previously optimized connections continue to be redirected, but new TCP connections are

passed through

D. All traffic through the Interceptor will be blocked

E. The Interceptor appliance communicates to the Steelhead appliances to disable their

optimization service

Answer: D

Cheat-Test.com Q: 62

Which statements are true regarding the default methods by which load-balancing takes place in the Interceptor appliance. (Select 2)

A. The Interceptor appliance uses round robin, for each TCP connection, regardless of source or

destination IP address, and is equally load-balanced between a group of Steelhead appliances

B. The Interceptor appliance uses round robin, for each TCP connection, depending on source IP

address, and is equally load-balanced between a group of Steelhead appliances

C. The Interceptor appliance uses hash assignment, for each TCP connection depending the hash

value calculated from source and destination IP address, and is directed to a particular Steelhead appliance in the local cluster

D. The Interceptor appliance can dynamically determine and direct traffic for optimization to the

least-loaded Steelhead appliances based on Steelhead appliance resource usage

E. The Interceptor appliance uses peer affinity, a Steelhead appliance in the local cluster that has

been previously paired with a destination IP address is preferred

F. The Interceptor appliance uses peer affinity, a Steelhead appliance in the local cluster that has

been previously paired with a remote Steelhead appliance is preferred

Answer: D,F

Cheat-Test.com Q: 63

Which statement is true regarding “fair-peering”?

A. It is a default parameter

B. It enables load distributed using round-robin

C. It enables load distribution using peer affinity

D. It can be configured as part of a load-balancing rule

E. It automatically redistributes connections equally among all appliances in a cluster when a new

appliance is added to the local cluster

Answer: D

Cheat-Test.com Q: 64

Using an Interceptor appliance is an alternative to what network designs? (Select 2)

A. WCCP

B. PBR

C. Connection Forwarding

D. Fixed-target rules

E. Peering rules

Answer: A,B

Cheat-Test.com Q: 65

What are an Interceptor appliance's main functions? (Select 2)

A. Provides a way to intercept and redirect interesting traffic for optimization

B. Monitors multiple links and redirect interesting traffic over a cluster of Steelhead appliances in a

logical in-path deployment

C. Replaces any existing Layer 4 switch in a given environment

D. Used to configure and work with WCCP and PBR

E. Required component Steelhead appliances in all Steelhead appliance deployments

Answer: A,B

Cheat-Test.com Q: 66

On the Interceptor appliance, what are the possible filter settings on a load balancing rule? (Select

4)

A.

Source Port

B.

Source IP Subnet

C.

Destination IP Subnet

D.

Destination Port

E.

VLAN ID

Answer: B,C,D,E

Cheat-Test.com Q: 67

What are the capabilities of an Interceptor appliance? (Select 3)

A. Peer affinity

B. Sequential rule processing

C. Intelligent forwarding

D. Basic in-path rules for pushing to the Steelhead appliance cluster

E. Centralize reporting of all Steelhead appliances in the enterprise

Answer: A,B,C

Cheat-Test.com Q: 68

Which of the following are configurable attributes of an Interceptor appliance? (Select 3)

A. Synchronizing datastore

B. Sharing connection state with a parallel Interceptor appliance

C. Redirect to a Steelhead appliance cluster

D. Failover to another Interceptor appliance

Answer: B,C,D

Cheat-Test.com Q: 69

What type of reporting information will an Interceptor appliance store? (Select 2)

A. Connection counts

B. Total packets in and out

C. Bytes and packets redirected to each neighbor Steelhead appliance

D. Scalable Data Referencing (SDR) Status

Answer: A,B

Cheat-Test.com Q: 70

What is required to be configured on a Steelhead appliance in order to work with an Interceptor appliance?

A. Connection Forwarding

B. Peering rules

C. Fixed-target rules

D. Pass-through rules

E. Nothing needs to be configured since this is all automated

Answer: A

Cheat-Test.com Q: 71

In a serial cluster deployment of Interceptor appliances, which interfaces are connected from one Interceptor appliance to another Interceptor appliance assuming they are connected back to back?

A. LAN0_0 to LAN0_1

B. WAN0_0 to WAN0_0

C. WAN0_0 to LAN0_0

D. LAN0_0 to LAN0_0

Answer: C

Cheat-Test.com Q: 72

Which TCP port will two Interceptor appliances communicate across in a parallel deployment?

A. 7800

B. 7810

C. 7840

D. 7850

E. 7860

Answer: E

Cheat-Test.com Q: 73

What type of configuration must be used on a Steelhead appliance in order to communicate with an Interceptor appliance?

A. In-path

B. Out-of-path

C. Logical in-path

D. Physical in-path Hybrid Mode

Answer: C

Cheat-Test.com Q: 74

To configure a Steelhead appliance for logical in-path mode, the following must be enabled in the General Service Settings page:

A. Reset Existing Client Connections on Start Up

B. Enable L4/PBR/WCCP Support on Interface wan0_0

C. Enable Optimizations on Interface inpath0_0

D. B and C

E. A, B, and C

Answer: D

Cheat-Test.com Q: 75

If a Steelhead appliance is configured for logical in-path mode:

A. The Primary interface cannot be on the same subnet

B. The LAN In-path interface will be disabled

C. The WAN In-path interface will be disabled

D. The Steelhead appliance listens for the Interceptor on TCP port 7860

Answer: B

Cheat-Test.com Q: 76

The Interceptor appliance can be configured to redirect traffic to the Steelhead appliances via what methods?

A. GRE

B. L2

C. ISIS

D. Multicast

E. Redirection is automatic and not configurable

Answer: E

Cheat-Test.com Q: 77

What is the command to verify a configuration of the Interceptor peers and peer neighbors?

A. verify interceptor deployment

B. service verify

C. debug validate deployment

D. config checker

Answer: C

Cheat-Test.com Q: 78

A customer wants to deploy parallel Interceptor appliances. How should an Interceptor appliance be configured in relation to another parallel Interceptor appliance?

A. Peer Interceptor

B. As a failover buddy

C. As a peer neighbor

D. A and B

E. A, B, and C

Answer: A

Cheat-Test.com Q: 79

A data center location has three Steelhead appliances and one Interceptor appliance clustered

together. If Steelheads A and B are unable to handle the new web traffic on port 80, the administrator does not want the connection to be serviced by Steelhead C. Given the current rules, we want to prevent traffic from redirecting to Steelhead C.

Current Rules:

Rule 1: Redirect rule for ports 445, 139, 80, target SH A

Rule 2: Redirect rule for ports 8080, 80, target SH B

Auto (default rule)

Which rule should be added on the Interceptor to achieve desired functionality?

A. A new rule 1 for ports 80 for Steelhead A and B

B. New rule 3: Pass-through rule for port 80

C. Rule 3: Redirect for port 80 to Steelhead C

D. No new rule needed for the administrator's policy

E. New rule 1: Pass-through rule for port 80

Answer: B

Cheat-Test.com Q: 80

A deployment has two parallel Interceptor appliances (A and B) each across a different link

directed at different data center locations. Each data center has one Steelhead appliance (Steelhead-1 or Steelhead-2). The administrator wants probes coming into Interceptor A to be first serviced by Steelhead-1, then Steelhead-2 only if Steelhead-1 is full or unavailable. What is the most appropriate rule to be configured?

A. A Redirect Load Balancing rule containing Steelhead-1 and Steelhead-2

B. No Load Balancing rules are needed for the administrator's policy

C. Two Redirect Load Balancing rules; first rule for Steelhead-1 and second rule for Steelhead-2

D. Two Redirect Load Balancing rules; first for both Steelhead-1 and Steelhead-2, second one for

Steelhead-2

Answer: C

Cheat-Test.com Q: 81

What is the default behavior of an Interceptor appliance using 2.0 code when its peer Interceptor appliance is unavailable?

A. Redirect to peer

B. Pass-through new connections

C. Block all connections

D. Deny all connections

E. Optimize all connections

Answer: B

Cheat-Test.com Q: 82

On an Interceptor appliance, what does the Neighbor Peers reporting page display?

A. connected, disconnected

B. connecting, disconnecting

C. connected, connecting, disconnecting, disconnected

D. connected, connecting, resyncing, disconnected

Answer: D

Cheat-Test.com Q: 83

How is peer affinity reset in the CLI for an Interceptor appliance cluster?

A. “peer affinity reset” on all Interceptors

B. “neighbor reset” on all Steelheads

C. “service restart” on all Interceptors

D. “neighbor reset” on all Interceptors

Answer: C

Cheat-Test.com Q: 84

What is the primary purpose of enabling Multiple Interface Support on the Interceptor?

A. It allows for the ability to support multiple NICs on the Interceptor

B. It allows the Interceptor appliance to communicate with Steelhead appliances and other

Interceptor appliances via more than one In-path interface

C. It allows the Interceptor appliance to communicate via Multicast to In-path interfaces on the

Steelhead appliances

D. It allows the Interceptor appliance to be managed by In-path interfaces as well as the Primary

interface

Answer: B

Cheat-Test.com Q: 85

The primary purpose of setting proxies (found on Networking – Proxies) on the Interceptor is to:

A. Allow for a Web or FTP proxy when specifying a URL on the Management Console or CLI

B. Allow for another Interceptor to redirect on behalf of the current Interceptor

C. Allow for Steelhead appliances to dynamically handle the load of another Steelhead appliance

D. Allow for two Interceptor appliances to act redundantly in a serial configuration

Answer: A

Cheat-Test.com Q: 86

Refer to the exhibit.

What does the term resyncing mean? A. All Interceptor appliances have been connected and the

What does the term resyncing mean?

A. All Interceptor appliances have been connected and the appliances are transferring connection

information

B. All Interceptor appliances and all Steelhead appliances have been connected and the

appliances are transferring connection information

C. The connection has been established and the Interceptor appliance is transferring its state

information

D. The connection has been established and the devices are transferring their state information

Answer: D

Cheat-Test.com Q: 87

Peer affinity is most closely related to:

A. Parallel Interceptor redirection based on Sport ID and client IP

B. Serial Interceptor redirection based on Sport ID to server

C. Segstore ID Steelhead mapping based on Sport ID of Steelhead appliances

D. The shipyard from which Riverbed is most likely to ship Interceptors

Answer: C

Cheat-Test.com Q: 88

For a new connection, an Interceptor appliance has no peer affinity, which Steelhead appliance will the Interceptor appliance choose for the connection?

A. The Interceptor appliance selects the Steelhead appliance with the least connections

B. The Interceptor appliance selects the Steelhead that has the most connections

C. The Interceptor appliance selects the most loaded Steelhead appliance

D. The Interceptor appliance selects the Steelhead appliance with the most peer affinity

Answer: A

Cheat-Test.com Q: 89

For a new connection, a Load Balancing rule matches but none of the target Steelhead appliances in the rule are available. What will happen to the new connection?

A. The connection is passed through

B. The next rule in the list is examined

C. The Interceptor appliance triggers an alarm

D. The Interceptor appliance discontinues redirecting any new connections and places this rule in

admissions control

Answer: B

Cheat-Test.com Q: 90

By default, which Steelhead appliances are placed in an Interceptor appliance's auto pool?

A. All Steelhead appliances in the network

B. Peer-neighbor Steelhead appliances as targets in one Load Balancing rule

C. Peer-neighbor Steelhead appliances not assigned as targets in any Load Balancing rule

D. Peer-neighbor Steelhead appliances assigned to all current Load Balancing rules

Answer: C

Cheat-Test.com Q: 91

The purpose of Intelligent Forwarding is to:

A. Automatically detect Steelhead appliances in the network

B. Help prevent network loops

C. Assist in the creation of static routes on the Interceptor appliance

D. Preclude the need for proper routing

Answer: B

Cheat-Test.com Q: 92

The Interceptor appliance will attempt to redirect a connection to a Steelhead appliance in the auto pool:

A. When no user defined Load Balancing rules matches AND peer neighbors are defined

B. When no user defined Load Balancing rules matches AND no peer neighbors are defined

C. When no peer Interceptor appliances are defined

D. When a user-defined Load Balancing rule matches AND a target Steelhead appliance is

available

Answer: A

Cheat-Test.com Q: 93

The Interceptor appliance cluster can support how many optimized connections?

A. 50,000

B. 100,000

C. 200,000

D. More than 200,000

Answer: D

Cheat-Test.com Q: 94

Under what circumstances would there be GRE traffic between the Interceptor and Steelhead appliances?

A. Throughout the entire lifespan of a connection

B. During connection teardown

C. During connection setup

D. GRE is not used but L2 is used during the entire connection

E. GRE is never used between the Interceptor and Steelhead appliances

Answer: C

Cheat-Test.com Q: 95

One of the Steelhead appliances in your Steelhead appliance cluster is running an older version of RiOS. You decide to schedule a change window to upgrade that Steelhead appliance's image to the current release. What should you do to ensure that the Steelhead appliance optimization still occurs and the upgraded Steelhead appliance no longer accepts new connections?

A. Enable the “no in-path accept new” CLI command

B. Create an in-path rule on the Steelhead appliance to bypass the connections

C. On the Interceptor appliance, click on “Pause” for that particular Steelhead appliance

D. Schedule a job on the Steelhead appliance to remove itself from the cluster

E. All of the above

Answer: C

Cheat-Test.com Q: 96

What are the four types of Interceptor appliance In-path rules?

A. Auto, Pass-through, Drop, Feint

B. Auto, Pass-through, Discard, Deny

C. Redirect, Pass-through, Discard, Deny

D. Auto1, Auto2, Allow, Pass-through

Answer: C

Cheat-Test.com Q: 97

What is the default In-path rule on an Interceptor appliance?

A. Optimize All

B. Pass-through All

C. Auto All

D. Redirect All

Answer: D

Cheat-Test.com Q: 98

For In-path rules on an Interceptor appliance, Source and Destination subnets are specified in what format? (where “x” is any single digit number):

A. xxx.xxx.xxx.xxx netmask xxx.xxx.xxx.xxx

B. xxx.xxx.xxx.xxx / xx

C. “all subnets”

D. xxx.xxx.xxx.xxx.xx

Answer: B

Cheat-Test.com Q: 99

The primary purpose of the Redirect In-path rule is to:

A. Select which traffic to redirect to Steelhead appliances

B. Utilize the Interceptor appliance as a backup firewall device

C. Select which traffic to split to two different interfaces

D. Select to which Steelhead appliance(s) traffic will be redirected

Answer: A

Cheat-Test.com Q: 100

What are two types of Load Balancing rules on an Interceptor appliance?

A. Auto, Drop

B. Redirect, Pass-through

C. Allow, Deny

D. Auto-Balance, Auto-Terminate

Answer: B

Topic 2, Volume B

Cheat-Test.com Q: 101

What is the default Load Balancing rule on an Interceptor appliance?

A. Redirect

B. Allow

C. Auto

D. Pass-through

Answer: C

Cheat-Test.com Q: 102

How many failover buddies can be configured for a single Interceptor?

A. 1

B. 2

C. 3

D. 4

E. No limit

Answer: A

Cheat-Test.com Q: 103

What are the default port labels on an Interceptor appliance?

A. Optimized, Pass-through, Blocked

B. Interactive, RBT-Proto, Secure

C. RBT-Proto, Enabled, Disabled

D. Named differently from those on the Steelhead appliance

E. Port labels do not exist on an Interceptor appliance

Answer: B

Cheat-Test.com Q: 104

Which physical Steelhead interface communicates with the Interceptor appliance?

A. AUX

B. Primary

C. wan0_0

D. B and C

E. A, B, and C

Answer: D

Cheat-Test.com Q: 105

The default setting for “allow failure” in the Interceptor appliance version 2.0 is: (Select 2)

A. Is configurable

B. Is not configurable

C. Enabled by default

D. Disabled by default

Answer: A,D

Cheat-Test.com Q: 106

On the Interceptor appliance, the Neighbor Peers page shows which of the following?

A. Optimized connections, Admission Control connection count

B. Optimized connections, Pass-through connections count

C. Current Connections per Second (CPS), Admission Control count

D. Packets per second, Connections per Second, Optimized connections count

Answer: A

Cheat-Test.com Q: 107

How many in-path rules will a LAN-initiated (i.e. SYN packet arrives at a LAN port of an In-path interface) single connection match on an Interceptor appliance?

A. 0

B. 1

C. 2

D. 3

Answer: B

Cheat-Test.com Q: 108

How many in-path rules will a WAN-initiated (i.e. SYN packet arrives at a WAN port of an In-path interface) single connection match? Assume no packet ricochet occurs (i.e. the SYN travels through the Interceptor appliance once).

A. 0

B. 1

C. 2

D. 3

Answer: A

Cheat-Test.com Q: 109

What is “Peer Affinity” on an Interceptor appliance?

A. Which parallel Interceptor appliance an Interceptor appliance is most likely to forward traffic to

B. Deciding which of the two serial Interceptors handles more traffic

C. Matching remote Steelhead appliances to a local Steelhead appliance

D. The shipyard from which Riverbed is most likely to ship Interceptor appliances

Answer: C

Cheat-Test.com Q: 110

Which logging severity levels are supported by the CMC appliance? (Select 4)

A. Emergency

B. Educational

C. Info

D. Notice

E. Critical

Answer: A,C,D,E

Cheat-Test.com Q: 111

Which user roles and permissions are supported by the CMC appliance? (Select 3)

A. Read-Only

B. Read/Write

C. Write-Only

D. Deny

E. Accept

Answer: A,B,D

Cheat-Test.com Q: 112

How many versions of CMC appliance software images can reside on the CMC simultaneously?

A. 5

B. 4

C. 3

D. 2

E. 1

Answer: D

Cheat-Test.com Q: 113

When registering a Steelhead appliance to the CMC appliance, which of the following options are available? (Select 4)

A. IP address

B. Serial Number

C. Username

D. License

E. Group

Answer: A,B,C,E

Cheat-Test.com Q: 114

What is the baud-rate of the console port on the CMC appliance?

A. 1200

B. 2400

C. 4800

D. 9600

E. 19200

Answer: D

Cheat-Test.com Q: 115

Which of the following configuration policies are supported on the CMC appliance? (Select 4)

A. Security Policy

B. Optimization Policy

C. System Setting Policy

D. License Policy

E. Networking Policy

Answer: A,B,C,E

Cheat-Test.com Q: 116

Which of the following are configurable in the CMC appliance Jump-Start Wizard? (Select 4)

A. IP address

B. Netmask

C. Steelhead appliance model number

D. Default gateway

E. Administrator password

Answer: A,B,D,E

Cheat-Test.com Q: 117

What is visible on the CMC appliance home page dashboard? (Select 4)

A. CMC appliance model

B. CMC appliance version

C. Logout

D. Reset

E. User Logged in

Answer: A,B,C,E

Cheat-Test.com Q: 118

What is the default CMC appliance name resolved by the Steelhead appliance for initial configuration?

A. cmc-riverbed

B. riverbed-cmc

C. cmc.riverbed.nbttech

D. riverbed.cmc

E. riverbedcmc

Answer: E

Cheat-Test.com Q: 119

Which of the following reports are available on the CMC appliance? (Select 4)

A. Optimized Throughput

B. Traffic Summary

C. Current Connections

D. Connection History

E. Data Store Hit Rate

Answer: A,B,D,E

Cheat-Test.com Q: 120

What parameters are required to add a new Steelhead appliance on the CMC appliance? (Select

2)

A. Hostname

B. IP address

C. Serial number

D. Sport ID

E. User name and password

Answer: C,E

Cheat-Test.com Q: 121

When upgrading a Steelhead appliance from the CMC appliance what methodologies can be

used? (Select 2)

A. Upgrade from uploaded image

B. Upgrade from the CMC appliance flash

C. Automatic download from support.riverbed.com

D. Upgrade from URL

E. Upgrade from TFTP server

Answer: A,D

Cheat-Test.com Q: 122

What interface on the CMC appliance is required for the initial configuration?

A. In-path interface

B. AUX interface

C. WAN interface

D. Primary interface

E. LAN interface

Answer: D

Cheat-Test.com Q: 123

Which of the following is true regarding the CMC appliance?

A. Can be configured using its default IP address of 192.168.1.1

B. Can be initially set up via the CLI

C. Can be initially setup via the AUX interface

D. Can be initially set up via telnet

E. Both C and D

Answer: B

Cheat-Test.com Q: 124

Regarding the registering of Steelhead appliances,

A. Local appliances (on the same IP subnet) are automatically registered every time because their

10-byte probe is intercepted by the CMC appliance

B. Remote appliances are registered when a fixed-target rule is applied to the appliance directing

it to the CMC appliance

C. Remote appliances are registered by proxy via the server-side Steelhead appliance

D. Remote appliances are registered manually when they have not auto-registered with the CMC

appliance

E. Local appliances can only be registered manually, since fixed-target rules may only be applied

to remote Steelhead appliances

Answer: D

Cheat-Test.com Q: 125

When manually registering a Steelhead appliance on the Central Management Console (CMC) appliance:

A. The serial number and IP address must match what is on the Steelhead appliance

B. The MAC address and IP address must match what is on the Steelhead appliance

C. The serial number and hostname must match what is on the Steelhead appliance

D. The serial number is independent of the hostname, as the hostname of the Steelhead

appliance on the CMC appliance will get overwritten if there is a different hostname on the Steelhead appliance

E. Both A and D

Answer: E

Cheat-Test.com Q: 126

The secure vault on the CMC appliancE. (Select 3)

A. Is always enabled and uses AES 256-bit encryption

B. Can be enabled and supports 128, 192 and 256-bit AES encryption

C. Is always enabled and opens by default at startup if the secure vault password has not been

changed

D. Has a default password which, if changed, means that it will need to be opened manually after

each startup

E. Contains all configuration and SSL information

Answer: A,C,D

Cheat-Test.com Q: 127

Which two of the following attributes are required to be added to a TACACS+ server to enable monitor and admin logon access to the CMC appliance via TACACS: (Select 2)

A. service = rbt-exec {local-user-name = "monitor"}

B. service = wan-accel {local-user-name = "monitor"}

C. service = rbt-exec {local-user-name = "admin"}

D. service = wan-accel {local-user-name = "admin"}

E. service = rbt-exec {local-user-name = "su"}

Answer: A,C

Cheat-Test.com Q: 128

What types of operations can be observed under the Manage > Operation History page in the CMC Management Console? (Select 2)

A. push

B. link

C. abort

D. fetch

Answer: A,D

Cheat-Test.com Q: 129

What are the four types of policies on a CMC appliance?

A. Networking, Optimization, Software, System

B. Networking, Optimization, Rules, System

C. Networking, Optimization, Security, System

D. Networking, Acceleration, Security, System

Answer: C

Cheat-Test.com Q: 130

Which of the following best describes the way a CMC appliance policy can be created?

A. By creating new policies through the CLI

B. Policies can be created either manually, via a configuration fetch from a Steelhead appliance,

or by copying another policy

C. By copying from a text file

D. Policies can only be created manually

Answer: B

Cheat-Test.com Q: 131

Which of the following are examples of Networking policies on the CMC appliance? (Select 3)

A. WCCP

B. HighSpeed TCP

C. Routing

D. Port Labels

E. HTTP Protocol

Answer: A,C,D

Cheat-Test.com Q: 132

Which of the following are examples of Security policies on the CMC appliance? (Select 3)

A. SSL Peering

B. SSL Ciphers

C. User Permissions

D. Web Settings

E. RADIUS

Answer: C,D,E

Cheat-Test.com Q: 133

Which of the following is true about fetching Steelhead appliance's configurations from a CMC appliance?

A. Fetched configurations are automatically saved as groups, which can be managed and applied

to appliances and appliance policies

B. Configurations cannot be fetched from the CMC appliance, they must be pushed

C. Fetched configurations are automatically saved as policies, which can be managed and applied

to appliances and appliance groups

D. Fetched configurations are saved as system settings, which can be managed and applied to

appliances and appliance groups

Answer: C

Cheat-Test.com Q: 134

What methods can the CMC appliance use to provide notification of CMC system events? (Select

3)

A.

Email

B.

RADIUS

C.

SNMP traps

D.

Syslog

Answer: A,C,D

Cheat-Test.com Q: 135

The CMC appliance version 6.1 supports which SNMP versions? (Select 3)

A. Version 1

B. Version 2

C. Version 2c

D. Version 3

Answer: A,C,D

Cheat-Test.com Q: 136

Which are true about the Steelhead appliance backups taken and stored by the CMC appliance? (Select 3)

A. They are text file snapshots of the current running configuration taken at 3 a.m. (by default)

B. The CMC appliance creates hyperlinks of the backups for easy viewing with a Web browser

C. The configurations can be copied from the CMC appliance back to the Steelhead appliance via

SCP

D. There is a limit of five configurations per Steelhead appliance that can be stored at any one

time in a rolling queue

E. The Steelhead configuration files can be edited on the CMC appliance

Answer: A,B,C

Cheat-Test.com Q: 137

What can be monitored via the CMC appliance? (Select 2)

A. Currently logged in users to Steelhead appliances or the CMC appliance

B. Command history per CMC appliance user

C. Rogue Steelhead appliances on the network

D. Current connections for an individual Steelhead appliance

Answer: B,D

Cheat-Test.com Q: 138

The Home page in the Management Console for the CMC appliance can be configured to display what information?

A. Default login used by the CMC appliance for each appliance

B. Last hour of throughput across all managed appliances

C. Status of each individual alarm for each managed Steelhead appliance

D. Last 20 lines of a Steelhead appliance's system log file

Answer: B

Cheat-Test.com Q: 139

When using TACACS+ or RADIUS to authenticate management access to the CMC appliance, which of the following is true?

A. You are required to supply login credentials to every Steelhead appliance

B. You will automatically be logged into to every Steelhead appliance

C. All users will use the same user name and password

D. It is not possible to use TACACS+ or RADIUS

Answer: A

Cheat-Test.com Q: 140

What Steelhead appliance models support the installation of Microsoft Windows Server 2008 R2 package on the RSP? (Select 2)

A. 1050

B. 250

C. 550

D. 3020

Answer: A,D

Cheat-Test.com Q: 141

What are the methods to upload an RSP package? (Select 3)

A. tftp

B. scp

C. ftp

D. ssh

E. http

Answer: B,C,E

Cheat-Test.com Q: 142

What command should you use to see the direct URL of a package?

A. show rsp slots

B. show rsp modules

C. show rsp platform

D. show rsp packages

E. show rsp vms

Answer: A

Cheat-Test.com Q: 143

You have an existing Steelhead appliance deployment which is achieving excellent optimization at five sites. You have deployed a Steelhead appliance physically in-path at a new small branch office and all of your applications have become slower for this new branch office only. What is the likely cause?

A. Incorrect in-path rules at the data-center

B. Incorrect in-path rules at the new branch office

C. Duplex mismatch between the new branch Steelhead and a connected device

D. Duplex mismatch between the data-center Steelhead and a connected device

E. Incorrect peering rules at the data-center

F. Incorrect peering rules at the new branch office

Answer: C

Cheat-Test.com Q: 144

You have an existing Steelhead appliance deployment which is achieving excellent optimization at five sites. You have deployed a Steelhead appliance physically in-path at a new small branch office and many of the new branch office users' applications are unoptimized; however some of the new branch office users' access to the same applications are optimized. None of the Steelhead appliances are in admission control. What is the likely cause?

A. Duplex mismatch between the new branch office Steelhead and a connected device

B. Duplex mismatch between the data center Steelhead and a connected device

C. Network Asymmetry

D. WAN link disconnection

E. Overloaded servers

Answer: C

Cheat-Test.com Q: 145

An unwanted Steelhead appliance appears on the current connections list of one of your Steelhead appliances. How can you stop inbound connections from this unknown appliance from optimizing with your Steelhead appliances?

A. Create new peering rule(s) on your Steelhead appliances

B. Create new in-path rule(s) on your Steelhead appliance

C. Create IPSec tunnels between all of your Steelhead appliances

D. Reload all of your Steelhead appliances

E. Reload only the data center Steelhead appliance

Answer: A

Cheat-Test.com Q: 146

Log messages in the Steelhead appliance Management Console such as “error=SMB_SHUTDOWN_ERR_SEC_SIG_ENABLED” are an indication of what condition?

A. The Steelhead appliance has entered admission control

B. The Steelhead appliance has detected an asymmetric network

C. The Steelhead appliance is configured with the incorrect speed or duplex on the Primary

interface

D. The Steelhead appliance is configured with the incorrect speed or duplex on of the in-path

interfaces

E. The Steelhead appliance is configured in “Tunnel Mode”

F. The Steelhead appliance has detected Windows Server Message Block (SMB) signing

Answer: F

Cheat-Test.com Q: 147

If a file is not optimized for more than one user at a time, this indicates:

A. Steelhead appliance has entered admission control

B. Steelhead appliance is configured with the incorrect speed or duplex on the Primary interface

C. Steelhead appliance is configured with the incorrect speed or duplex on of the in-path

interfaces

D. Steelhead appliance is not able to acquire a “File Hold Key (FHK)”

E. Steelhead appliance is not able to acquire an “Opportunistic Lock (oplock)”

F. Steelhead appliance is not able to acquire a “Double Link (doulink)”

Answer: E

Cheat-Test.com Q: 148

With these default registry parameters, SMB signing is negotiated in the following manner. (Select 2)

A. SMB/CIFS exchanges between the Client/Workstation and the Member Server are not signed

B. SMB/CIFS exchanges between the Client/Workstation and the Member Server are always

signed

C. SMB/CIFS exchanges between the Client/Workstation and the Domain Controller are not

signed

D. SMB/CIFS exchanges between the Client/Workstation and the Domain Controller are always

signed

Answer: A,D

Cheat-Test.com Q: 149

A fat pipe is a network that can carry large amounts of data without significantly degrading transmission speed. If you have a fat pipe that is not being fully utilized and you are experiencing WAN congestion, latency, and packet loss as a result of the limitations of regular TCP, which of the following RiOS features will help? (Select 2)

A. Enable Forced Burst TCP (FB-TCP)

B. Enable HighSpeed TCP (HSTCP)

C. Disable admission control

D. Lower the Advanced Security Checkflow Parameter (ASCP)

E. Enable Maximum TCP (MX-TCP)

F. Enable disk encryption

Answer: B,E

Cheat-Test.com Q: 150

You are using Steelhead appliances in an Oracle Forms environment and are not seeing adequate acceleration. What could be the cause of this?

A. You need to install a separate Oracle Forms license

B. Oracle Forms optimization is enabled by default. However, you must set an in-path rule to

enable this feature.

C. Oracle Forms optimization can only be configured from the command line (CLI)

D. Oracle Forms optimization only works with Oracle Applications 9i

E. Oracle Forms optimization only works with Oracle Applications 8i

Answer: B

Cheat-Test.com Q: 151

Your Steelhead appliance deployment includes users accessing the Internet from branch offices with the traffic being back-hauled to the data center before going out to the Internet. However,

HTTP latency optimization does not appear to be very effective, and in certain cases, is slower than without optimization. What settings might help with this Internet-bound traffic?

A. Riverbed recommends you turn off URL Learning and Parse-and-Prefetch and only enable

OPT

B. Riverbed recommends you enable URL Learning and Parse-and-Prefetch and turn off OPT

C. Riverbed recommends you turn off URL Learning and only enable Parse-and-Prefetch and

OPT

D. Riverbed recommends you turn off URL Learning, Parse-and-Prefetch, and OPT

E. Riverbed recommends you enable URL Learning, Parse-and-Prefetch, and OPT

Answer: A

Cheat-Test.com Q: 152

WCCP protocol has a methodology of load balancing with two or more Steelhead appliances. What are the maximum number of buckets able to be used for the MASK assignment?

A. 8

B. 32

C. 64

D. 128

E. 256

Answer: D

Cheat-Test.com Q: 153

While looking at the Current Connections page on a client-side Steelhead, you noticed that there is more CIFS traffic on the WAN than on the LAN for some connections. What may be the problem?

1) The source data is compressed or encrypted

2) File server not located on the same subnet as the server-side Steelhead

3) The Steelhead is counting both CIFS optimized and unoptimized traffic

4) CIFS read-ahead

5) CIFS write-behind

A. 1, 4

B. 4, 5

C. 1, 2, 3

D. 1, 2, 5

E. 3, 5

Answer: A

Cheat-Test.com Q: 154

In an in-path deployment, if a naked SYN packet arrives on the WAN interface of Steelhead, what probe option is added to this SYN packet for auto-discovery?

A. Option-76

B. Option-78

C. SACK

D. WSCALE

E. None of the above

Answer: E

Cheat-Test.com Q: 155

If using Fixed-target rules, what Steelhead specific probe options are associated with the SYN packet?

A. Option-76 (0x4c)

B. Option-78 (0x4e)

C. Client-side Steelhead's in-path IP address

D. Client-side Steelhead's port number

E. No probes are sent with fixed-target rules

Answer: E

Cheat-Test.com Q: 156

Given four Steelheads are deployed in a WCCP cluster and all Steelheads are optimizing traffic to and from the data center. Steelhead-A fails and only Steelhead-B and Steelhead-C are intercepting new connections while Steelhead-D is NOT optimizing any traffic. What is the likely problem?

A. The load balancing algorithm on the router is broken

B. Simplified routing is not enabled

C. Steelhead-B and Steelhead-C are missing the “in-path neighbor continue-intercept” command

D. Steelhead-D is missing the “in-path neighbor allow-failure” command

E. Need to issue the command “in-path accept connections” on Steelhead-D

Answer: D

Cheat-Test.com Q: 157

A customer noticed that after deploying the Steelhead between their switch and router, OSPF takes much longer to re-converge after the router fails. Which RiOS feature can you enable to reduce the convergence time?

A. Adjusting the OSPF “keep-alive” timers on the Steelhead appliance

B. Configure Fail-To-Block on the Steelhead appliance

C. Enable Link State Propagation

D. Enable Link State Notification

E. Configure Rapid Spanning Tree on the Steelhead appliance

Answer: C

Cheat-Test.com Q: 158

To increase the high availability of a site at a remote office, you decided to install a second Steelhead appliance as an active/active serial cluster. However, after installing the second Steelhead appliance at the remote site, users started complaining about slow access to the data center. You have verified that this is not a duplex issue. At the data center location all users access the Internet which pass-through the Steelhead appliances. What is the most likely problem?

A. SMB Signing

B. Oplock issue

C. The serial cluster Steelhead appliances are peering to each other

D. Simplified routing was enabled on the secondary Steelhead appliance

E. The datastore on the Steelhead appliances are wrapping

Answer: C

Cheat-Test.com Q: 159

Refer to the exhibit.

Answer: C Cheat-Test.com Q: 159 Refer to the exhibit. Corp-A and Corp-B have overlapping address space

Corp-A and Corp-B have overlapping address space and therefore the network administrator implemented NAT to overcome this. Users from Corp-A NAT to 172.16.1.0/24 and users from Corp-B NAT to 172.16.2.0/24. Users in Corp-A use the destination address of 172.16.2.0/24 to access the resources in Corp-B. The servers in Corp-B use the client IP for authentication. What do you need to do in order to make this deployment work? (Select 2)

A. Configure Full Transparency

B. Configure out-of-path

C. Configure Port Transparency

D. Configure OOB Transparency

E. Steelhead appliances cannot be deployed in this network

Answer: A,D

Cheat-Test.com Q: 160

Refer to the exhibit.

Refer to the exhibit. Corp-A and Corp-B have overlapping address space and therefore the network administrator

Corp-A and Corp-B have overlapping address space and therefore the network administrator implemented NAT to overcome this. Users from Corp-A NAT to 172.16.1.0/24 and users from Corp-B NAT to 172.16.2.0/24. Users in Corp-A use the destination address of 172.16.2.0/24 to access the resources in Corp-B. The servers in Corp-B use the client IP for authentication. You deploy the Steelhead appliance using the default WAN visibility mode but noticed all the connections are passed-through. What is the likely problem?

A. When the Steelhead appliance in Corp-B opens the outer connection, it is using the source IP

of 172.16.2.x instead of 192.168.1.x

B. On the Steelhead appliance in Corp-B, there is a missing static route for the 192.168.1.0/25

network

C. On the Steelhead appliance in Corp-A, there is a missing static route for the 172.16.2.0/24

network

D. When the Steelhead appliance in Corp-B opens the outer connection, it is using the source IP

of 192.168.1.x instead of 172.16.1.x

E. None of the above

Answer: D

Cheat-Test.com Q: 161

You enabled port transparency but noticed that active FTP connections are failing. What may be the problem?

A. The routers need to understand port transparency

B. Port transparency only maintains destination ports

C. Port transparency requires NAT

D. You need to a fixed-target rule on the server-side for port transparency

E. None of the above

Answer: B

Cheat-Test.com Q: 162

After deploying the Steelhead appliances in-path, you are not seeing any optimization between 10.11.0.128 and 10.11.23.18.

seeing any optimization between 10.11.0.128 and 10.11.23.18. Look at the following trace in the exhibit and

Look at the following trace in the exhibit and explain why: (HINT: Look at the SYN packet)

A. There is a spanning-tree loop

B. The cables are reversed

C. The three way hand-shake is not being completed

D. The client and servers are on the same /16 subnet

E. There is no SYN/ACK from 10.11.23.18

Answer: B

Cheat-Test.com Q: 163

Refer to the HTTP trace exhibit.

You noticed in the HTTP reports that you are not seeing any hits. What is

You noticed in the HTTP reports that you are not seeing any hits. What is required in order for HTTP optimization to work?

A. Client request is missing the “Cache” header

B. Keep-alive timeout on the server it too short

C. Server does not support HTTP 1.1 extensions

D. The “Content-Length” is too long. The HTTP blade can only handle 16K of data.

E. Server is not setting a cookie

Answer: E

Cheat-Test.com Q: 164

Refer to the exhibit.

Answer: E Cheat-Test.com Q: 164 Refer to the exhibit. You noticed the following entry in the

You noticed the following entry in the logs. What is the cause of the problem?

A. Complete asymmetry

B. Server-side asymmetry

C. Client-side asymmetry

D. Multi-syn retransmit

E. SYN retransmit

Answer: C

Cheat-Test.com Q: 165

A Windows Vista client tries to download a file from a Windows 2008 server over a 45Mbps link with 200ms. Assuming the connection is optimized, given the default configuration on the Steelhead, what optimization techniques would be applied?

1) Data Streamlining

2) Transport Streamlining

3) MS-SQL Transaction Prediction

4) HighSpeed TCP

5) MX-TCP

A. 1, 2, 3

B. 1, 2

C. 1, 2, 3, 4

D. 1, 2, 3, 5

E. 1, 3, 4

Answer: B

Cheat-Test.com Q: 166

Refer to the exhibit.

3, 4 Answer: B Cheat-Test.com Q: 166 Refer to the exhibit. You configured CIFS prepopulation at

You configured CIFS prepopulation at Corp-A but it is not working. What is likely the cause of the issue?

A. CIFS prepopulation requires WCCP

B. Primary interface needs to be on a different subnet

C. CIFS prepopulation requires a fixed-target rule

D. The Primary interface needs to be on the LAN side of the Steelhead appliance

E. CIFS prepopulation requires SMBv2

Answer: D

Cheat-Test.com Q: 167 You have an in-house HTTP application running on port 8443 but you are not seeing HTTP

optimization. You checked and made sure that the HTTP blade is enabled. What is the likely problem?

A. Primary port needs to be on the LAN side of the Steelhead

B. There is a separate license key for the HTTP blade

C. The HTTP blade will only work on port 80 and 8080 and can not be changed

D. The HTTP blade only supports HTTP 1.1 and the application is using HTTP 1.0

E. HTTP blade is enabled by default on port 80 and 8080. An in-path rule is necessary for all other

ports.

Answer: E

Cheat-Test.com Q: 168

Refer to the exhibit.

ports. Answer: E Cheat-Test.com Q: 168 Refer to the exhibit. Traffic going from Corp-A-DC-2 towards Corp-B

Traffic going from Corp-A-DC-2 towards Corp-B will always use Link-1. Traffic from Corp-B back to Corp-A-DC-1 may traverse Corp-A-DC-1, over the GigaMAN before it reaches Corp-A-DC-2. No TCP connections are initiated from Corp-B to either Corp-A-DC-1 or Corp-A-DC-2. Unfortunately, the customer does not have any money to purchase any additional Steelheads. What are some possible fixes to ensure optimization occurs while Link-1 is operational? (If Link-1 ceases to function, optimization is not possible.) (Select 2)

A. Configure a fixed-target rule on the Corp-A-DC-2 Steelhead pointing to the Corp-B Steelhead

on port 7800

B. On the Corp-B Steelhead, enable “in-path probe direct”

C. On the Corp-A-DC-2 Steelhead, enable “in-path probe direct”

D. Configure the Corp-A-DC-2 Steelhead to inject a route into the network

E. Enable Full Transparency

Answer: A,C

Cheat-Test.com Q: 169

Which of the following is NOT supported in Alarm Settings?

A. Raise alarm when network interface duplex errors are detected

B. Raise alarm when network interface link errors are detected

C. Raise alarm when the number of optimized connections exceeds user specified limit

D. Raise alarm if a software version mismatch is detected in the network

E. Raise alarm when asymmetric routes are detected

Answer: C

Cheat-Test.com Q: 170

The alerting threshold for CPU utilization is 70% and the reset threshold is 50%. Which of the following situations will result in an alarm being triggered? (Select 2)

A. Initial utilization of 30% becomes 75%

B. Drop from 90% of utilization to 70%

C. Initial utilization of 73% becomes 90%

D. Drop from 75% of utilization to 48% and shot up to 68%

E. Drop from 75% of utilization to 48% and shot up to 78%

Answer: A,E

Cheat-Test.com Q: 171

Refer to the exhibit.

Refer to the exhibit. A user from one of your branch offices reports connections to servers

A user from one of your branch offices reports connections to servers are failing after a new deployment. The exhibit shows how the Steelhead appliances have been deployed. Which of the following will most likely fix the issue? (Select 2)

A. Fixed-target rule is needed on the client-side Steelhead appliance

B. Change the WCCP to use Redirect Out instead of Redirect In

C. Remove Redirect-IN from the LAN at the Branch Office

D. Add Redirect-IN on the WAN at the HQ

E. Remove fixed-target rule from the server-side Steelhead appliance

Answer: A,D

Cheat-Test.com Q: 172

The exhibit shows a data center side serial clustering deployment. In this organization, not every remote site has a Steelhead appliance deployed, and all remote locations will be connecting to the data center.

For connections initiated from the data center, there is a possibility that the Steelhead appliances

For connections initiated from the data center, there is a possibility that the Steelhead appliances shown in the exhibit will end up peering with each other, rather than the intended remote Steelhead appliances. Where are peering rules needed to prevent this problem?

A. A only

B. B only

C. B and C

D. A and B

Answer: D

Cheat-Test.com Q: 173

Refer to the exhibit.

prevent this problem? A. A only B. B only C. B and C D. A and

A customer has a server-side out-of-path deployment, and reports that connections from some of

their remote branch offices are not being optimized. What is the most likely problem?

A. A missing fixed-target rule on the server-side Steelhead appliance

B. A missing fixed-target rule on the client-side Steelhead appliance

C. The WAN interface is connected to the server-side Steelhead appliance

D. The LAN interface is connected to the server-side Steelhead appliance

E. Using port 7810 in the fixed-target rule instead of 7800

Answer: B

Cheat-Test.com Q: 174

After a new physical in-path installation, all applications appear to be slower. Adding a pass- through rule does not seem to fix the problem. Which of the following is the most likely cause of the problem?

A. Duplex mismatch

B. Firewall blocking auto-discovery probes

C. No fixed-target rules installed

D. A and C

E. A, B, and C

Answer: A

Cheat-Test.com Q: 175

In a recent in-path deployment, users are complaining that some of their CIFS drive-mapping

connections do not appear to be optimized. Upon further analysis, you discover the file shares reside on a domain controller. The Steelhead appliances are deployed in a default configuration. Which of the following is the most likely cause of the problem?

A. The Steelhead appliance lost an Opportunistic Lock on the file

B. SMB Signing is set to required

C. No fixed-target rules installed

D. Misconfigured Steelhead appliance

E. Packet ricochet

Answer: B

Cheat-Test.com Q: 176

A customer is reporting higher than normal CPU utilization on certain routers in their network. Looking at their Steelhead appliance logs, they see “intercept/localkernel/icore.c:1463] nat_check:

SYN packet for already NAT'd connection 100.100.100.33:1611 -> 100.200.200.32:80 ==> 100.201.201.25:7801”. All connections are showing up optimized but the logs persist. Given the exhibit,

up optimized but the logs persist. Given the exhibit, what is the likely problem? A. Lost

what is the likely problem?

A. Lost Opportunistic Lock

B. SMB Signing

C. Fixed-target rule is needed

D. Asymmetric Route

E. Packet Ricochet

Answer: E

Cheat-Test.com Q: 177

Refer to the exhibit.

Fixed-target rule is needed D. Asymmetric Route E. Packet Ricochet Answer: E Cheat-Test.com Q: 177 Refer

A customer is reporting that the first connection from a user to the server is failing. However,

subsequent connections work properly and are optimized. How can this problem best be

resolved?

A. Fixed-target rule

B. Enable RIP/OSPF on the routers

C. Enable Simplified Routing

D. Enable QoS

E. Enable RIP/OSPF on the Steelhead appliances

Answer: C

Cheat-Test.com Q: 178

In an existing deployment, all connections appear to be unoptimized. The Current Connections

page lists the connections as pass-through.

Connections page lists the connections as pass-through. The logs indicate admission control “Jan 19 18:44:56

The logs indicate admission control “Jan 19 18:44:56 client sport[343]: [admission_control.WARN] Pausing intercept.” What are some possible ways to alleviate the problem? (Select 2)

A. Verify that there is no SMB Signing on the server

B. Ensure that there are no Opportunistic Lock issues

C. Disable or reduce the connection timeout of MAPI prepopulation

D. Investigate if there is a virus on a client trying to propagate itself

E. Validate that NFS v2 broadcasts are enabled

Answer: C,D

Cheat-Test.com Q: 179

You need to take a full packet trace from the WAN interface of a Steelhead appliance to send into technical support. Which of the following commands will achieve this assuming typical Ethernet MTU? (Select 2)

A. tcpdump –i wan0_0 –s 0 –w filename

B. tcpdump –i wan0_0 –s 1500 –w filename

C. tcpdump –I wan0_0 –w filename

D. tcpdump –i wan0_0 –w filename

E. tcpdump –I wan0_0 –s 1500 –w filename

Answer: A,B

Cheat-Test.com Q: 180

Which of the following commands would allow you to generate a system dump from the CLI?

A. sysdump

B. dump generate

C. debug generate dump

D. sysdump generate dump

E. dump generate –w filename

Answer: C

Cheat-Test.com Q: 181

The Optimization service has been disabled on a Steelhead appliance. Which of the following events occur as a result?

A. LAN and WAN interfaces stop intercepting

B. Primary interface becomes disabled

C. AUX interface becomes disabled

D. The Steelhead appliance reboots

Answer: A

Cheat-Test.com Q: 182

Which section of the Steelhead appliance Management Console can help identify speed/duplex errors? (Select 2)

A. View Logs

B. Current Connections

C. Alarm Status

D. Interface Statistics

E. Monitored Ports

Answer: A,D

Cheat-Test.com Q: 183

A customer with a new physical in-path installation decides to turn on the optimization service during lunch time on a working day. This is done so that he can see if the users perceive any performance improvement. When starting the optimization service, he does not enable the in-path kickoff option. Assuming there were several already active connections when he starts the optimization service, how will the Steelhead appliances handle these existing connections?

A. The Steelhead appliance will optimize all connections, including pre-existing

B. The Steelhead appliance will pass-through all pre-existing connections, leaving them un-

optimized

C. The Steelhead appliance will reset all pre-existing connections, thus automatically changing

their optimization status from un-optimized to optimized

D. The Steelhead appliance will list the connections as “pre-existing” on the Current Connections

page

E. Both B and D

F. Both C and D

Answer: E

Cheat-Test.com Q: 184

You need to perform a tcpdump of traffic entering the Steelhead appliance's lan0_0 interface. Which of the following demonstrate the proper command format to perform the tcpdump and capture to a file?

A. tcpdump –p lan0_0 –S 300 –w lancap.cap

B. tcpdump –i lan0_0 –s 300 –w lancap.cap

C. tcpdump –i lan0_0

D. tcpdump –I lan0_0 –s 300

E. tcpdump –i lan0_0 -3 300 –r lancap.cap

Answer: B

Cheat-Test.com Q: 185

In a new physical in-path deployment, you realize that a Steelhead appliance at one of your branch offices is optimizing connections from other sites, however, no connections initiated from that branch office are being optimized. Which of the following is the most likely cause of this problem?

A. Duplex mismatch

B. Bilateral Opportunistic Lock failure

C. Policy-based routing incorrectly configured

D. Reversed WAN and LAN cabling

Answer: D

Cheat-Test.com Q: 186

When troubleshooting a datastore wrapping alarm with 1 day wrapping notification configured, which of the following should be examined? (Select 2)

A. If the unit was mis-sized

B. If stream based encrypted traffic is being sent across the link as optimized

C. If your fixed-target rules are pointing to the correct Steelhead appliance

D. If Connection Forwarding was properly configured

Answer: A,B

Cheat-Test.com Q: 187

What should you do when you receive the following message?

was properly configured Answer: A,B Cheat-Test.com Q: 187 What should you do when you receive the

A. Nothing. This is a warning message which means that the Steelhead appliance is resetting an

internal state regarding this connection and it should not affect user performance.

B. Switch off the Steelhead appliance

C. Create a specific pass-through rule to bypass the above source and destination hosts

D. Reload the Steelhead appliance

Answer: A

Cheat-Test.com Q: 188

What should you do when you receive the following message?

[intercept.NOTICE] sending kickoff RST: 10.35.178.41:1169 -> 10.110.141.30:1031.

A. Nothing. This is just a notice message.

B. Verify whether the "Reset Existing Client Connections on Start Up" option is checked and

uncheck it

C. Switch off the Steelhead appliance

D. Create a specific pass-through rule to bypass the above source and destination hosts

E. Restart the Steelhead appliance

Answer: B

Cheat-Test.com Q: 189

Refer to the exhibit.

In the accompanying exhibit, SH3 and SH4 are able to optimize FTP and HTTP sessions

In the accompanying exhibit, SH3 and SH4 are able to optimize FTP and HTTP sessions between Client41 and the respective application hosts Server31 and Server32. However, optimization does not happen for Client42 and these application hosts. A quick check on SH3 and SH4 registers neither optimized nor pass-through traffic from Client42. Client42 is able to ping Client41 and the in-path address of SH4. Note that SH3 and SH4 are in auto-discovery mode. What is the likely cause?

A. The default gateway of Client41 is configured wrong

B. The default gateway of Client42 is configured wrong

C. The default gateway of SH3 is configured wrong

D. The default gateway of SH4 is configured wrong

E. The routing protocol between R3 and R4 is configured wrong

Answer: B

Cheat-Test.com Q: 190

Refer to the exhibit.

SH3 and SH4 are able to optimize FTP and HTTP sessions between Client41 and the

SH3 and SH4 are able to optimize FTP and HTTP sessions between Client41 and the respective application hosts Server31 and Server32. However, optimization seems to be a problem for Client42 and these application hosts. A quick check on SH3 and SH4 registers neither optimized nor pass-through traffic from Client42. Client42 is able to ping to both Server31 and Server32. Note that SH3 and SH4 are in auto-discovery mode. What is the likely cause?

A. The default gateway of Client41 is configured wrong

B. The default gateway of Client42 is configured wrong

C. An outbound access-list specified at R3f0 denies TCP traffic from Client42

D. The routing protocol between R3 and R4 is configured wrong

Answer: C

Cheat-Test.com Q: 191

Refer to the exhibit.

SH3 and SH4 are able to optimize HTTP sessions from Client41 to application host Server31.

SH3 and SH4 are able to optimize HTTP sessions from Client41 to application host Server31. However, Client41 receives a failure messagE. “ftp connect: Unknown error number” while trying to connect Server32. The same applies to Client42. Note that SH3 and SH4 are in auto-discovery mode. Client41 and Client42 are able to ping Server32. What is the most likely cause of this failure?

A. The network interface card (NIC) at Server32 is down

B. The FTP service running in Server32 is down

C. An outbound access-list specified at R3f0 denies IP traffic from Client41 and Client42

D. An outbound access-list specified at R3f0 denies FTP control traffic from Client41 and Client42

E. The routing protocol between R3 and R4 is configured wrong

Answer: B

Cheat-Test.com Q: 192

Refer to the exhibit.

A connection times out when Client41 and Client42 attempt to either establish an HTTP session

A connection times out when Client41 and Client42 attempt to either establish an HTTP session to

Server31 or an FTP connection to Server32 after not connecting to them for some time. The very next attempt to connect to these services done immediately after the failure seems to work correctly. The clients are able to ping both servers and no access-lists are configured on the routers. SH3 uses the IP address of R3f0 as its default gateway. Upon powering off SH3 and SH4, the problem goes away even for first connection and everything works normally (even after not connecting for extended periods of time). Which of the following are likely to correct this problem?

A. Both servers have faulty network interface cards and should be replaced

B. Both the HTTP service running in Server31 and the FTP service running in Server32 are down

and should be restarted

C. A more specific static route pointing to Subnet 31 is not configured at SH3

D. A more specific static route pointing to Subnet 31 is not configured at R3

E. A more specific static route pointing to Subnet 31 is not configured at L3 Switch

Answer: C

Cheat-Test.com Q: 193

In the exhibit,

Client41 and Client42 have full access to the HTTP and FTP services provided by Server31

Client41 and Client42 have full access to the HTTP and FTP services provided by Server31 and Server32 respectively. They continue to have access to these servers after SH3 and SH4 are deployed. A quick check on SH3 and SH4 registers the connections from Client41 and Client 42 as pass-through traffic. Note that SH3 and SH4 are in auto-discovery mode. What are the likely causes? (Select 2)

A. Pass-through rules are specified in the Steelhead appliances to bypass TCP traffic from

Client41 and Client42

B. Deny rules are specified in the Steelhead appliances to bypass IP traffic from Client41 and

Client42

C. There is a firewall inside the WAN cloud which strips the TCP options field

D. There is a firewall inside the WAN cloud which strips the IP options field

Answer: A,C

Cheat-Test.com Q: 194

Where in the Steelhead appliance can you verify IP address settings? (Select 2)

A. Interface Statistics

B. View the configuration

C. Neighbor Statistics

D. QoS Statistics

E. Log messages

Answer: A,B

Cheat-Test.com Q: 195

In a new in-path deployment, connections are listed as pass-through on the branch office Steelhead appliance. Which of the following is the likely cause of the problem?

1) Pass-through rule preventing optimization

2) Server-side Steelhead appliance is down

3) Satellite proxy not copying auto-discovery probes

4) Asymmetric routing is detected for the client/server flow

5) Duplex mismatch on WAN or LAN interface

A. 3, 2

B. 2, 4

C. 1, 2, 5

D. 1, 2, 3, 4

E. 1, 2, 3, 4, 5

Answer: D

Cheat-Test.com Q: 196

You are troubleshooting a new Steelhead Mobile installation where none of the VPN users with Steelhead Mobile client installed are being optimized. You determine that the Steelhead appliance in the data center is not in-path for VPN users. What are your options to fix this? (Select 2)

A. Use the Steelhead in an out-of-path deployment using fixed-target rules in the Steelhead

appliance

B. Use the Steelhead in a hybrid in-path/out-of-path deployment using fixed-target rules in the

Steelhead Mobile client

C. Put the Steelhead appliance in-path on the VPN concentrator segment using a multi-port NIC

D. Install the Steelhead Mobile Controller on the VPN segment

Answer: B,C

Cheat-Test.com Q: 197

The port used by the Steelhead appliance for datastore synchronizations is:

A. 7801

B. 7810

C. 7744

D. 7850

Answer: C

Cheat-Test.com Q: 198

In a server-side out-of-path deployment, the server-side Steelhead appliance connects to the network via which physical interface:

A. LAN0_0

B. Primary

C. Auxiliary

D. WAN0_0

Answer: B

Cheat-Test.com Q: 199

Which of the following are valid WCCPv2 control messages? (Select 3)

A. I_SEE_YOU

B. HERE_I_AM

C. REMOVAL_QUERY

D. REMOVAL_ACK

Answer: A,B,C

Cheat-Test.com Q: 200

When utilizing MAPI prepopulation, the default timer is set to:

A. 96 hours

B. 1 hour

C. 30 minutes

D. There is no default timer

Answer: A

Topic 3, Volume C

Cheat-Test.com Q: 201

Which of the following are valid QoS priority queues for Steelhead appliances? (Select 3)

A. Normal

B. Medium

C. Real-time

D. Low

E. Critical

Answer: A,C,D

Cheat-Test.com Q: 202

The port used by the Steelhead appliance for connection forwarding is:

A. 7810

B. 7850

C. 7801

D. 7820

Answer: B