201-01 Sample Questions & Answers
Emphasizes configuring NetProfiler, NetExpress and the Flow Gateway above all, then splits evenly between Packet Analyzer and NetShark analysis, with AppResponse configuration, Riverbed's solutions overview, Transaction Analyzer basics, and the Portal.
Launch the full 201-01 simulator →Showing 10 of 20 free samples.
- Question 1IntermediateSelect 2
SteelCentral NetProfiler, NetExpress, and Flow Gateway · Host Groups
A network administrator is configuring Host Groups in SteelCentral NetProfiler to better organize and report on traffic from different company departments. What are two key benefits of using Host Groups? (Select TWO)
Show answer & explanation
Correct answers: B, D
Host Groups aggregate IP addresses into logical containers, which is essential for reporting on the traffic patterns of entire departments, server farms, or branch offices as a single entity.
Using logical names for Host Groups in service definitions, report filters, and policies makes the configuration more readable, manageable, and less prone to error than maintaining long, static lists of IP addresses.
- Question 2Advanced
SteelCentral NetShark · Performance Analysis
An engineer is analyzing a performance issue in a three-tier application using data from a NetShark appliance. The analysis shows significant delays. The engineer suspects the issue is between the Application Server and the Database Server. The following diagram represents the TCP round-trip time (RTT) measurements from the NetShark's perspective. Given the data presented, where is the most likely source of the application delay?
sequenceDiagram participant Client participant AppServer as Application Server participant DBServer as Database Server Client->>AppServer: HTTP Request Note right of Client: Network RTT (Client-App): 20ms AppServer->>DBServer: SQL Query Note right of AppServer: Server Processing: 50ms Note right of AppServer: Network RTT (App-DB): 150ms DBServer-->>AppServer: SQL Result Note left of DBServer: DB Processing: 30ms AppServer-->>Client: HTTP ResponseShow answer & explanation
Correct answer: C
The diagram clearly shows the breakdown of time spent in each segment. The Network RTT between the Application Server and the Database server is 150ms, which is the largest single component of delay. This indicates that the most significant bottleneck is the network segment connecting these two tiers.
- Question 3Intermediate
SteelCentral Portal · Dashboard Configuration
A network operations team uses SteelCentral Portal to display a consolidated view of network and application performance. The team lead wants to create a custom dashboard that shows the top 10 applications by bandwidth from NetProfiler alongside the top 5 web applications by user experience time from AppResponse. Which Portal feature should be used to accomplish this?
Show answer & explanation
Correct answer: C
SteelCentral Portal uses widgets as the building blocks for dashboards. Each widget is designed to pull specific data from a configured data source (like NetProfiler or AppResponse). To create the desired view, the administrator would create a new dashboard and then add the appropriate 'Top N Applications' widget from the NetProfiler data source and the 'Top N Web Applications' widget from the AppResponse data source.
- Question 4Intermediate
SteelCentral Transaction Analyzer · Transaction Modeling
When using SteelCentral Transaction Analyzer to troubleshoot a multi-tier application, what is the primary purpose of creating a 'Transaction' model?
Show answer & explanation
Correct answer: B
A 'Transaction' model in Transaction Analyzer is used to stitch together individual packet traces from different tiers (e.g., web, application, database) into a single, cohesive end-to-end view. This allows an analyst to visualize the message flow, identify which tier introduces the most latency, and understand the complete response time breakdown for a user's action.
- Question 5Intermediate
SteelCentral NetProfiler, NetExpress, and Flow Gateway · NetProfiler Enterprise Architecture
A company is deploying SteelCentral NetProfiler Enterprise, which consists of a separate database, application, and web server. What is the primary reason for this distributed architecture compared to the all-in-one NetProfiler appliance?
Show answer & explanation
Correct answer: C
The distributed architecture of NetProfiler Enterprise is designed for scalability. By separating the database, application processing, and web interface onto dedicated servers, each component can be scaled independently to handle very high flow volumes (millions of flows per minute) and store massive amounts of historical data, which is common in large enterprise or service provider networks.
- Question 6Intermediate
SteelCentral Packet Analyzer · Expert Analysis
An engineer using SteelCentral Packet Analyzer opens a large trace file and wants to quickly identify all conversations that experienced TCP retransmissions. Which feature would be the most efficient way to achieve this?
Show answer & explanation
Correct answer: C
The Expert System in Packet Analyzer automatically analyzes trace files for common problems. The 'Expert Events' view provides a categorized summary of all detected issues, including a specific category for TCP retransmissions. This allows the engineer to instantly see all affected conversations without needing to manually create filters or inspect each stream individually, making it the most efficient method.
- Question 7AdvancedSelect 3
SteelCentral NetProfiler, NetExpress, and Flow Gateway · Policy and Alert Configuration
A hospital is using NetProfiler to monitor its network. The security team is concerned about potential data exfiltration and has asked the network team to create an alert that triggers if any single host inside the network transfers more than 1 GB of data to an external public IP address over a 1-hour period. Which combination of NetProfiler components is required to build this alert? (Select THREE)
Show answer & explanation
Correct answers: A, B, D
A Host Group is needed to define the scope of 'any single host inside the network' that the policy will monitor.
A Service is required to define the traffic of interest, specifically from the internal Host Group to any external address. This allows the policy to focus only on data leaving the network.
The Policy is the core component that ties everything together. It will use the Host Group and Service to specify what to monitor and then apply a threshold (1 GB) to the 'Total Bytes' metric over the specified time window (1 hour) to trigger an alert.
- Question 8Beginner
General Knowledge · Packet Analysis Fundamentals
When performing packet analysis, what is the key difference between a capture filter and a display filter?
Show answer & explanation
Correct answer: B
This is the fundamental difference. A capture filter (e.g., BPF syntax) is applied before data is written, preventing unwanted packets from ever being stored. This is a destructive action in that the filtered-out packets are lost forever. A display filter (e.g., Wireshark syntax) is non-destructive and is applied to an existing trace file to temporarily hide or show packets in the user interface for easier analysis.
- Question 9Intermediate
SteelCentral AppResponse · Performance Metrics
A user reports that a web application is slow. An analyst uses AppResponse and observes a high 'Retransmission Delay' for the user's session. What does this metric specifically indicate?
Show answer & explanation
Correct answer: C
'Retransmission Delay' is a network-related metric that quantifies the impact of packet loss. It measures the time elapsed from when a TCP segment was first sent to when its retransmission was sent, indicating that the original packet was lost or corrupted in transit. A high value in this metric points directly to a network quality issue (congestion, faulty hardware, etc.) as the source of the slowness.
- Question 10Intermediate
SteelCentral NetShark · Product Integration
True or False: A single SteelCentral NetShark appliance can simultaneously send packet data to SteelCentral Packet Analyzer for deep analysis and flow data to SteelCentral NetProfiler for traffic monitoring.
Show answer & explanation
Correct answer: A
This statement is true. A key capability of NetShark is its ability to serve multiple purposes. It can perform continuous packet capture, allowing analysts to pull specific trace files into Packet Analyzer for investigation. At the same time, it can generate flow records (often called 'Enhanced Flows' or 'Packet-derived Flows') from the captured traffic and export them to NetProfiler, enriching NetProfiler's visibility without requiring separate flow sources.
Ready for the real thing?
The full 201-01 simulator has every exam-style question, timed mode, and instant scoring.