SCP-500 Research & Evidence-Based Practice 4 β Questions and Answers
Question 1: Which principle of evidence-based IT practice does SolarWinds Orion's alert escalation hierarchy support?
- Ignore low-severity alerts entirely
- Prioritize responses based on objective severity tiers derived from measured threshold breaches (Correct answer)
- Alert all staff simultaneously regardless of severity
- Disable alerts for nodes below a certain age
Correct answer: Prioritize responses based on objective severity tiers derived from measured threshold breaches
Tiered alert escalation ensures that resources are prioritized proportionally to objectively measured severity, reducing noise and focusing attention where evidence indicates the most impact.
Question 2: When using SolarWinds NTA (NetFlow Traffic Analyzer) to research a suspected data exfiltration event, which data point provides the most relevant forensic evidence?
- Average CPU on the firewall
- Top talkers by volume, destination IP, and time-of-day flow data (Correct answer)
- DHCP lease duration for the suspect host
- VLAN membership of the switch port
Correct answer: Top talkers by volume, destination IP, and time-of-day flow data
Top-talker analysis with destination IP and temporal flow data directly evidences unusual outbound data transfer patterns associated with exfiltration.
Question 3: An organization runs a monthly research review of their SolarWinds alert data. What is the primary benefit of analyzing alert frequency trends over time?
- It automatically resolves open alerts
- It identifies chronic problem areas that may require permanent remediation rather than repeated reactive fixes (Correct answer)
- It reduces the number of monitored nodes
- It upgrades SolarWinds to the latest version
Correct answer: It identifies chronic problem areas that may require permanent remediation rather than repeated reactive fixes
Trending alert frequency over time reveals systemic issues that recur frequently, directing investment toward permanent fixes rather than repeated manual intervention.
Question 4: In SolarWinds, what is the recommended evidence-based approach when an alert fires for a node that is in a planned maintenance window?
- Respond as if it were a real incident
- Suppress alerts using a scheduled maintenance window so maintenance-period events are excluded from SLA and incident data (Correct answer)
- Permanently disable monitoring for that node
- Escalate immediately to senior engineers
Correct answer: Suppress alerts using a scheduled maintenance window so maintenance-period events are excluded from SLA and incident data
Maintenance windows suppress alerts and exclude the period from availability calculations, keeping evidence clean and SLA data accurate.
Question 5: Which SolarWinds Orion feature allows a researcher to visualize network topology and overlay real-time performance data to identify geographic patterns in degradation?
- Network Atlas / Network Map (Correct answer)
- Flow Navigator
- Config Viewer
- License Manager
Correct answer: Network Atlas / Network Map
Network Atlas (Network Map) lets administrators draw or auto-generate topology maps and overlay live metrics, revealing spatial patterns in performance problems.
Question 6: When applying evidence-based practice to SolarWinds threshold tuning, what is the correct sequence of steps?
- Set thresholds arbitrarily, then adjust if complaints arise
- Collect baseline data β analyze normal operating range β set thresholds above normal variance β review and refine after 30 days (Correct answer)
- Copy thresholds from vendor defaults permanently
- Set the lowest possible threshold to maximize alert volume
Correct answer: Collect baseline data β analyze normal operating range β set thresholds above normal variance β review and refine after 30 days
Evidence-based threshold tuning starts with baseline data, derives statistically appropriate values, then refines them after observing real-world alert behavior.
Question 7: A researcher using SolarWinds wants to determine if a memory leak exists in a monitored application server. Which evidence pattern most strongly supports this conclusion?
- CPU utilization is stable over 7 days
- Memory utilization shows a steady monotonic increase over days that only resets after a server restart (Correct answer)
- Network throughput spikes at midnight
- Disk I/O is higher than average
Correct answer: Memory utilization shows a steady monotonic increase over days that only resets after a server restart
A monotonically increasing memory trend that resets only on restart is the classic evidence pattern for a memory leak in the monitored process.
Which principle of evidence-based IT practice does SolarWinds Orion's alert escalation hierarchy support?