A network administrator is configuring SNMPv3 monitoring for a new set of Cisco Catalyst switches. To ensure the highest level of security as required by company policy, which security level should be selected in the node's credential set?
Answer and explanation
Correct answer: C
This is the highest security level for SNMPv3. It provides both authentication (auth) to verify the message source and privacy (priv) through encryption of the data payload. This ensures message integrity, authenticity, and confidentiality, meeting the highest security requirements.
Question 2
While attempting to create a Universal Device Poller (UnDP) for a proprietary storage array, the administrator receives a 'MIB compilation error' when uploading the vendor's MIB file to the Orion server. Which of the following is the most probable cause of this issue?
Answer and explanation
Correct answer: B
MIBs often use definitions and object types from other, more standard MIBs (e.g., RFC1213-MIB). If a vendor MIB references an object from a parent MIB that is not already present in the Orion MIB database, the compiler will fail because it cannot resolve the dependency. The solution is to load the required parent MIBs first.
Question 3
Multiple answers
A security audit requires that all network device monitoring must use SNMPv3 with the strongest possible security. An engineer is tasked with implementing this. Which of the following actions are essential to meet this requirement? (Select THREE)
Answer and explanation
Correct answers: A, B, D
The authPriv security level provides both authentication and encryption (privacy), which is the strongest security available in SNMPv3 and is essential to meet the audit requirement.
The security of SNMPv3 relies on the strength of the passphrases. Using weak or default passwords would undermine the security provided by the protocol, even with authPriv enabled.
When using authPriv, you must select both an authentication protocol (e.g., SHA) and a privacy protocol. Choosing a strong encryption algorithm like AES is crucial for ensuring data confidentiality.
Question 4
A Network Operations Center (NOC) analyst is trying to understand the difference in SNMP messages being received. What is the key functional difference between an SNMP Trap and an SNMP Inform message?
Answer and explanation
Correct answer: B
This is the primary difference. An SNMP Trap is a 'fire-and-forget' message; the sending device does not know if it was received. An SNMP Inform is a confirmed message; the management station must send an acknowledgment (response PDU). If no acknowledgment is received, the agent may resend the Inform. This makes Informs more reliable for critical notifications.
Question 5
A hospital's IT department needs to monitor the temperature of a specific server room using a networked environmental sensor that is not natively supported by SolarWinds NPM. The sensor provides its temperature reading via a specific SNMP OID. What is the most direct and efficient method within NPM to collect and display this temperature data?
Answer and explanation
Correct answer: C
The Universal Device Poller (UnDP) is the designated tool in NPM for this exact purpose. It allows administrators to define custom pollers for any metric available via an SNMP OID. Once created, the poller can be assigned to the node, and its data can be charted, displayed, and used in alerts just like a native metric.
Question 6
True or False: The Universal Device Poller (UnDP) can be configured to poll metrics from Windows servers using WMI credentials.
Answer and explanation
Correct answer: B
This is correct. The Universal Device Poller (UnDP) is limited to the SNMP protocol for custom polling. WMI polling is a separate mechanism primarily associated with the SolarWinds Server & Application Monitor (SAM) module.
Question 7
A Network Sonar Discovery job covering a large subnet (a /22 network) is taking several hours to complete, significantly impacting the polling engine's performance. Which action would most effectively reduce the discovery duration without sacrificing the goal of finding all relevant network devices?
Answer and explanation
Correct answer: D
A major time sink in discovery is testing multiple SNMP credentials against every IP in the range. By refining the list to only the known, valid community strings for that subnet, the discovery can proceed much faster. It avoids waiting for timeouts on incorrect credentials for each potential device.
Question 8
To reduce alert noise from downstream devices during a core switch outage, an administrator decides to configure dependencies. A distribution switch (DSW-1) is connected to a core switch (CSW-1). Several access switches (ASW-1, ASW-2) are connected to DSW-1. How should the dependency be configured?
This correctly models the network topology. Making DSW-1 a child of CSW-1 ensures that if CSW-1 goes down, DSW-1 enters an 'Unreachable' state, suppressing its own 'Down' alert. Subsequently, making the access switches (ASW-1, ASW-2) children of DSW-1 ensures that when DSW-1 is down or unreachable, alerts for the access switches are also suppressed. Using a group for the access switches is an efficient way to manage this second dependency.
Question 9
An administrator is creating a custom property to classify nodes by their environment (e.g., 'Production', 'Staging', 'Development'). What is the primary purpose of defining a custom property in this manner?
Answer and explanation
Correct answer: B
Custom properties act as metadata tags. Their main purpose is to allow for flexible organization of monitored entities. Once defined, you can use these properties to create dynamic groups, build targeted alert conditions (e.g., 'only alert on 'Production' nodes'), create specific views, and generate filtered reports.
Question 10
A newly added Cisco router is showing a status of 'Unknown' in NPM. The administrator has verified the following:
The node is reachable via ping from the polling engine.
The SNMPv3 credentials (username, auth/priv protocols, and passphrases) are identical on the device and in the Orion credential set.
What is a common, often-overlooked configuration mismatch on the Cisco device that would cause this issue?
Answer and explanation
Correct answer: B
SNMPv3 uses a unique engineID for each device. Orion discovers and uses this ID for communication. If the device's configuration is changed, or if it's a clone of another device, it might have a duplicate or incorrect engineID. This mismatch prevents the cryptographic keys from working correctly, leading to authentication failures that manifest as an 'Unknown' status even when credentials appear correct. Forcing a rediscovery of the node in Orion often resolves this.