SCP-500 Research & Evidence-Based Practice 5 — Questions and Answers
Question 1: Which SolarWinds capability supports evidence-based change management by automatically detecting and logging unauthorized configuration changes on network devices?
- NPM Interface Monitor
- NCM Real-Time Change Detection via syslog or SNMP trap correlation (Correct answer)
- IPAM Conflict Detection
- SAM Process Monitor
Correct answer: NCM Real-Time Change Detection via syslog or SNMP trap correlation
NCM's real-time change detection captures unauthorized or unexpected config changes as they happen, providing timestamped evidence critical for change audits.
Question 2: In evidence-based capacity planning, what does a 'time-to-threshold' projection in SolarWinds indicate?
- The time since the last alert was acknowledged
- The estimated date when a resource will reach its critical threshold if current growth continues (Correct answer)
- The polling interval for SNMP data collection
- The duration of the last maintenance window
Correct answer: The estimated date when a resource will reach its critical threshold if current growth continues
Time-to-threshold projections give administrators a data-driven deadline for procuring or provisioning additional capacity before a resource is exhausted.
Question 3: When researching the effectiveness of a QoS policy using SolarWinds NTA, which metric provides the most direct evidence of policy enforcement?
- Total bandwidth consumed by all interfaces
- DSCP marking distribution and per-class traffic volumes on the WAN link (Correct answer)
- Number of devices in the topology
- CPU utilization of the QoS-enforcing router
Correct answer: DSCP marking distribution and per-class traffic volumes on the WAN link
DSCP marking distribution confirms that traffic is being classified correctly, and per-class volumes verify that rate limits and prioritization are being enforced as designed.
Question 4: A SolarWinds administrator is asked to research whether adding a new monitoring poller improved data collection reliability. Which evidence-based metric should they examine?
- The number of new nodes added
- Poller queue depth and the percentage of missed polls before and after the poller addition (Correct answer)
- Alert acknowledgment time
- The poller's operating system version
Correct answer: Poller queue depth and the percentage of missed polls before and after the poller addition
Comparing poller queue depth and missed-poll rates before and after the change directly measures whether the additional poller reduced collection failures.
Question 5: Which SolarWinds best practice ensures that research findings from one environment (e.g., dev) are validated before being applied to production monitoring configurations?
- Apply all changes directly to production first to save time
- Test new alert thresholds, templates, and views in a non-production Orion instance before promoting them (Correct answer)
- Use manual email alerts instead of Orion alerts in production
- Disable all alerts during the research phase in production
Correct answer: Test new alert thresholds, templates, and views in a non-production Orion instance before promoting them
Testing configuration changes in a non-production instance prevents untested monitoring rules from generating false positives or gaps in production coverage.
Question 6: When presenting research on network reliability to management using SolarWinds data, which metric most directly quantifies the business impact of downtime?
- Average SNMP response time in milliseconds
- Mean Time Between Failures (MTBF) and Mean Time To Repair (MTTR) derived from availability history (Correct answer)
- Number of interface errors per day
- Total volume of syslog messages generated
Correct answer: Mean Time Between Failures (MTBF) and Mean Time To Repair (MTTR) derived from availability history
MTBF and MTTR translate raw availability data into failure frequency and recovery speed, metrics management can directly correlate to cost and risk.
Question 7: In SolarWinds, which approach to alert threshold research helps reduce alert fatigue while maintaining detection accuracy?
- Set all thresholds to their lowest possible values
- Use dynamic baselines that automatically adjust thresholds based on historical normal behavior for each node (Correct answer)
- Apply the same fixed thresholds to every node regardless of role
- Disable warning thresholds and only keep critical thresholds
Correct answer: Use dynamic baselines that automatically adjust thresholds based on historical normal behavior for each node
Dynamic baselines adapt thresholds to each node's normal behavior pattern, reducing false positives caused by applying uniform thresholds across diverse workloads.
Which SolarWinds capability supports evidence-based change management by automatically detecting and logging unauthorized configuration changes on network devices?