A financial services firm has deployed SteelHead appliances between its New York headquarters and a London branch office. They are optimizing CIFS traffic for accessing large financial models. After deployment, users report that while initial access to a file is slow, subsequent access to the same file by other users is significantly faster. However, if a small change is made to a large file, the entire file seems to be re-transmitted over the WAN. Which RiOS feature is most likely misconfigured or not being fully utilized?
Answer and explanation
Correct answer: C
Scalable Data Referencing (SDR) works by breaking data streams into chunks and storing references. If a small change is made, only the new or modified chunks should be sent over the WAN. The described behavior suggests that the system is not effectively identifying and sending only the deltas, which points to an issue with how SDR is processing the CIFS traffic. While other features contribute to performance, the core issue of re-transmitting entire files after small changes is a classic symptom of sub-optimal SDR operation.
Question 2
A network architect is designing a SteelHead deployment for a large enterprise with a complex, multi-vendor router environment. To ensure resilience and avoid creating a single point of failure, they want to redirect traffic to a cluster of SteelHead appliances without modifying client configurations or using Policy-Based Routing (PBR). Which deployment method is best suited for this requirement?
Answer and explanation
Correct answer: D
WCCP is a Cisco-developed protocol that allows routers to transparently redirect traffic to other devices, such as a cluster of SteelHead appliances. It is ideal for this scenario because it provides load balancing and failover capabilities across multiple appliances and does not require changes to client configurations or complex PBR rules. It is widely supported and suitable for multi-vendor environments.
Question 3
A system administrator is deploying a Virtual SteelHead (VSH) appliance on a VMware ESXi host that also runs several other critical business applications. To guarantee a minimum level of performance for WAN optimization, the administrator needs to ensure the VSH virtual machine receives a consistent amount of CPU resources, even when the host is under heavy load. Which VMware feature should be configured for the VSH virtual machine?
Answer and explanation
Correct answer: C
A CPU Reservation in VMware guarantees a minimum amount of CPU resources for a virtual machine, regardless of the load from other VMs. This is the correct feature to use to ensure the Virtual SteelHead has the necessary processing power to perform WAN optimization effectively at all times. CPU Limit sets a maximum, and CPU Shares only defines relative priority during contention.
Question 4
True or False: When using SteelHead Mobile with the 'Branch Warming' feature enabled, the SteelHead Mobile client's datastore is synchronized only with the server-side SteelHead appliance, not the local branch SteelHead appliance.
Answer and explanation
Correct answer: B
The statement is false. The purpose of Branch Warming is to pre-populate the datastore of the local branch SteelHead appliance with data segments that the mobile client has already received. This allows other users in the branch to benefit from the data reduction, warming the branch appliance's cache. Therefore, data is populated in the client, the server-side SteelHead, AND the local branch SteelHead appliance.
Question 5
A company has deployed SteelHead CX appliances to accelerate access to their SaaS applications, including Microsoft 365. An administrator needs to ensure that only authenticated Microsoft 365 traffic from their company's tenant is optimized, while blocking optimization for personal Microsoft 365 accounts. Which feature within the SteelHead CX configuration should be used to achieve this?
Answer and explanation
Correct answer: C
The SaaS application Identity feature in SteelHead CX allows administrators to define specific tenant IDs or domains for supported SaaS applications like Microsoft 365. By configuring the company's tenant ID, the SteelHead CX can differentiate between corporate and personal traffic, applying optimization policies only to the authorized corporate tenant.
Question 6
Multiple answers
During a network audit, it was discovered that a SteelHead appliance, configured for SSL optimization, is using a server certificate with a weak signing algorithm (SHA-1). To comply with new security policies, the certificate must be replaced with one using SHA-256. What are the critical steps an administrator must perform on the SteelHead to update the SSL certificate for a specific internal server? (Select TWO)
Answer and explanation
Correct answers: B, C
The SteelHead appliance needs the actual server certificate and its corresponding private key to impersonate the server to the client during the SSL handshake for optimization. This is a fundamental step.
After importing the certificate, the SSL in-path rule that defines optimization for that server's traffic must be updated to use the newly imported SHA-256 certificate instead of the old SHA-1 certificate.
Question 7
A consultant is reviewing a SteelHead deployment where two appliances are connected over a satellite link characterized by very high latency (>600ms) and moderate packet loss. Standard TCP applications are performing poorly despite data reduction ratios being high. The consultant suspects the TCP congestion control algorithm is too conservative for this link type. Which Riverbed-specific transport streamlining feature is designed specifically to address this kind of challenging network environment?
Answer and explanation
Correct answer: C
MX-TCP (Maximum Speed TCP) is a proprietary Riverbed transport protocol designed for high-latency, high-packet-loss environments like satellite links. It uses different congestion control mechanisms and packet loss recovery techniques than standard TCP or even HS-TCP, allowing it to utilize the available bandwidth much more effectively on such challenging links.
Question 8
A network administrator needs to create a QoS policy on a SteelHead appliance to prioritize interactive SSH traffic over bulk FTP data transfers. The goal is to ensure SSH sessions remain responsive even when large files are being transferred. To which predefined QoS class should the SSH traffic (TCP port 22) be assigned to give it higher priority?
Answer and explanation
Correct answer: A
The 'Interactive' QoS class is specifically designed for low-bandwidth, latency-sensitive applications like SSH and Telnet. Assigning SSH traffic to this class ensures it receives priority over traffic in lower-priority classes, such as the 'Bulk' class where FTP would typically be placed, thus maintaining responsiveness.
Question 9
An administrator is managing a large-scale SteelHead deployment using a SteelCentral Controller (SCC). A new security policy requires that all administrative access to the SteelHead appliances must use a centralized authentication system. The administrator configures the SCC to push a policy that sets the authentication mode to RADIUS. However, several appliances in a remote region fail to apply the new policy. What is the most likely reason for this failure?
Answer and explanation
Correct answer: C
In RiOS, certain critical local configurations can be protected from being overwritten by SCC policies using the '!read-only' flag. If the authentication settings on the remote appliances were configured locally and marked as read-only, the SCC policy push will fail for that specific setting, preventing the change to RADIUS.
Question 10
Case Study:
A global architectural firm, "ArchiDesign," has its primary data center in Chicago, with branch offices in London, Singapore, and Sydney. The firm relies heavily on transferring large Autodesk Revit (CAD) files and uses a centralized document management system over CIFS/SMB. All inter-office traffic is sent over a managed MPLS network, but users in the APAC region (Singapore and Sydney) complain about extremely slow file transfers and application response times due to high latency (250-300ms).
Current Situation: The network team has deployed SteelHead appliances at all four locations. Data reduction ratios are excellent (averaging 85%), but the application-level performance improvement for the APAC offices is still below expectations. The network team has validated that the issue is not bandwidth saturation but rather the number of TCP round trips required by the applications across the high-latency links.
Requirements:
Significantly improve the 'time-to-first-byte' for users opening large CAD files.
Reduce the chattiness of the CIFS/SMB protocol over the WAN.
The solution must not require any changes to the end-user workstations or the servers in Chicago.
Which combination of RiOS features should the ArchiDesign network team focus on configuring and optimizing to best meet these requirements?
Answer and explanation
Correct answer: C
The core problem described is application latency caused by protocol chattiness over high-latency links, even with good data reduction. Application Streamlining features are designed to solve this. CIFS prepopulation can pre-load data to the branch office appliance, drastically improving open times. CIFS read-ahead and write-behind are specific latency optimization techniques that reduce the number of round trips required by the protocol, directly addressing the user complaints. This combination targets the application layer, which is the source of the remaining performance bottleneck.