1. What version(s) of SSH does NetCache support?
A. Versions 1 and 2
B. Version 2 only
C. Versions 2 and 3
D. Version 3 only
E. None
070-410 exam Answer:A
2. Which set of acceleration rules will best allow for acceleration of a Windows Media Server that uses MMS and HTTP
for transport protocols?
NetCache IP: netcache.server.com
Streaming Server IP: m.server.com
A. streaming.acceleration.rules=\\ 1755 * * 1755 m.server.com * 80 * * 80 m.server
B. config.streaming.acceleration.rules=\\ 1755 * * 1755 m.server.com *
config.http.acceleration.rules=\\ 80 * * 80 m.server.com *
C. config.acceleration.rules=\\
mms netcache.server.com m.server.com
http netcache.server.com m.server.com
D. config.streaming.acceleration.rules=\\ 554 * * 554 m.server.com * 80 * * 80 m.server.com *
3. What happens if you assign a service group ID of 4 on one NetCache appliance, and you assign a
service group ID of 2 on another NetCache appliance?
A. The two groups will load balance between each other.
B. The WCCP router will automatically group the two together.
C. Each NetCache appliance will join a different service group.
D. The NetCache appliances use only the ID assignment for internal information, so there is no effect.
070-410 dumps Answer: C
4. Which three are true about WCCP? (Choose 3)
A. WCCP service groups must support a single protocol.
B. WCCP service groups can consist of one or more routers or proxy-cache servers.
C. WCCP service groups must be defined with the same settings.
D. Traffic redirection and distribution are based on logical WCCP service groups.
Answer: BCD
5. What is the purpose of the “Here I Am” message?
A. It identifies the NetCache appliance as the router.
B. It identifies the service group membership.
C. It announces that the NetCache appliance is available after a shutdown.
D. It identifies that the NetCache appliance has received a request.
070-410 pdf Answer: B
6. When traffic is tunneled, the NetCache appliance can take which two actions? (Choose 2)
A. It can be used with manually configured browsers.
B. It passes specified types of nonstandard traffic through without caching it.
C. It examines the source and destination information, and caches the resulting objects.

D. It receives requests and allows or denies based on ACLs.
Answer: BD
7. When is information recorded into the Streaming Access log?
A. When the client streaming connection is opened.
B. Within 500 ms of connect.
C. Throughout the streaming session.
D. When the client streaming connection is closed.
070-410 vce Answer: D
8. When you have a Digital Rights Management (DRM) streaming, authentication is performed between which two devices?
A. HTTP server and client player
B. streaming media server and client player
C. authentication server and router
D. domain controller and streaming media server
Answer: B
9. A list of HTTP headers returned to a client for a cache hit on a stream may be viewed using the
A. smstats command
B. sysstat command
C. Streaming Details log
D. object command
070-410 exam Answer: D
10. Bandwidth allocation rules can be used to optimize streaming performance in which three ways? (Choose 3)
A. They can allocate bandwidth by user and group.
B. They can manage NetCache bandwidth utilization to ensure bandwidth for other uses.
C. They can allocate bandwidth based on CPU and memory usage.

D. They can restrict or deny connections.
Answer: ABD

11. Applications that use ephemeral ports on both sides of a connection are difficult to mine, because:
A. The ephemeral ports cannot be predicted
B. They all use the same port, TCP/1024
C. The well-known ports cannot be predicted
D. The ephemeral ports can be predicted but the port pairings are always different
070-410 dumps Answer:A
12. Mining FTP frames for both the Control and Data connections is difficult, because:
A. The server listens on TCP/20 and on ephemeral addresses that are difficult to predict.
B. The server listens on TCP/21 and multiple addresses that cannot be predicted.
C. The server listens on TCP/21 and ephemeral ports that are difficult to predict.
D. Many implementations of FTP exist that use varying well-known ports.
Answer: C
13. Which of the following is NOT typically associated with network security auditing?
A. Inspection of passwords
B. Examining a network for signs of misuse
C. Troubleshooting network application efficiency
D. Looking for conformance to policy
070-410 pdf Answer: C
14. Consider this illustration of a data mining filter. What is wrong with it?

A. The filter only allows packets that are sent to HTTP servers on their well-known port. It would only show commands without replies. This filter is incomplete.
B. The filter only allows packets that are both to and from the well-known port TCP/80 (HTTP). Both source and destination port cannot be 80. Nothing would pass the filter.
C. It would also allow UDP packets to and from port 80 (HTTP), which does not make sense, since HTTP is a TCP-based protocol.
D. Nothing. It will capture normal data to and from TCP/80 (HTTP) servers.
Answer: B
15. The easiest way to identify data for further analysis is to .
A. create an alias
B. group multiple protocols together
C. sort on port number
D. select all ephemeral ports
070-410 vce Answer: C
16. A one to many relationship is indicative of:
A. Backdoors
B. Clients sending email to a relay server
C. Password guessing
D. Peer-to-Peer
Answer: D
17. Consider this mining filter. Which description most accurately describes what it does?
A. It includes all packets to and from network
B. It includes all packets that have sources and destinations within network
C. It includes all packets that are not to or from network

D. Nothing. No packets would pass this filter.
070-410 exam Answer: C
18. Time duration and speed are .
A. primary limitations of mining and analysis
B. not relevant to InfiniStream C. only related to Expert analysis
D. relevant, but secondary issues
19. For testing, it is useful to convert your into .
A. data / units of measurement
B. hypothesis / an if-then statement
C. hypothesis / a conclusion
D. conclusion / if-then statement
070-410 dumps Answer: B
20. Maintaining a baseline can aid in detecting bandwidth denial of service attacks by:
A. Listing status codes associated with denial of service.
B. Revealing significant changes in protocol activity and bandwidth through comparison.
C. Showing ports known to be associated with bandwidth denial of service.
D. Listing source IP addresses know to send denial of service attacks.
Answer: B

21. To see user names sent to an FTP server, you should view .
A. the Expert Service layer objects
B. the Expert Application layer objects
C. the Advanced tab in the mining interface (Quick Select)
D. the Names tab in the mining interface (Quick Select)
070-410 pdf Answer: B

22. Your network contains an Active Directory domain named contoso.com. All servers run Windows Server 2012 R2.
Client computers run either Windows 7 or Windows 8. All of the computer accounts of the client computers reside in an organizational unit (OU) named Clients. A Group Policy object (GPO) named GP01 is linked to the Clients OU. All of the client computers use a DNS server named Server1. You configure a server named Server2 as an ISATAP router. You add a host (A) record for ISATAP to the contoso.com DNS zone. You need to ensure that the client computers locate the ISATAP router. What should you do?
A. Run the Add-DnsServerResourceRecord cmdlet on Server1.

B. Configure the DNS Client Group Policy setting of GPO1.
C. Configure the Network Options Group Policy preference of GPO1.
D. Run the Set-DnsServerGlobalQueryBlockList cmdlet on Server1.
Correct Answer: D
23. Your network contains an Active Directory domain named contoso.com. The domain contains a server named Server1 that runs Windows Server 2012 R2 and has the Remote Access server role installed. A user named User1 must connect to the network remotely. The client computer of User1 requires Challenge Handshake Authentication Protocol (CHAP) for remote connections. CHAP is enabled on Server1. You need to ensure that User1 can connect to Server1 and authenticate to the domain. What should you do from Active Directory Users and Computers?
A. From the properties of Server1, select Trust this computer for delegation to any service (Kerberos only).
B. From the properties of Server1, assign the Allowed to Authenticate permission to User1.
C. From the properties of User1, select Use Kerberos DES encryption types for this account.
D. From the properties of User1, select Store password using reversible encryption.
070-410 vce Correct Answer: D
24. Your network contains a Hyper-V host named Hyperv1 that runs Windows Server 2012 R2. Hyperv1 has a virtual switch named Switch1. You replace all of the network adapters on Hyperv1 with new network adapters that support single- root I/O virtualization (SR-IOV). You need to enable SR-IOV for all of the virtual machines on Hyperv1. Which two actions should you perform? (Each correct answer presents part of the solution. Choose two.)
A. On each virtual machine, modify the Advanced Features settings of the network adapter.
B. Modify the settings of the Switch1 virtual switch.
C. Delete, and then recreate the Switch1 virtual switch.
D. On each virtual machine, modify the BIOS settings.
E. On each virtual machine, modify the Hardware Acceleration settings of the network adapter.
Correct Answer: CE
25. Your network contains a server named Server1 that runs Windows Server 2012 R2. Server1 is a member of a workgroup. You need to configure a local Group Policy on Server1 that will apply only to non- administrators.Which tool should you use?
A. Server Manager
B. Group Policy Management Editor
C. Group Policy Management
D. Group Policy Object Editor
070-410 exam Correct Answer: D
26. Your network contains an Active Directory domain named contoso.com. The domain contains a server named Server! that runs Windows Server 2012 R2. Server1 contains a virtual machine named VM1 that runs Windows Server 2012 R2.
You need to ensure that a user named User1 can install Windows features on VM1. The solution must minimize the number of permissions assigned to User1. To which group should you add User1?
A. Administrators on VM1
B. Power Users on VM1
C. Hyper-V Administrators on Server1
D. Server Operators on Server1
Correct Answer: A
27. Your network contains an Active Directory domain named adatum.com. The domain contains a member server named LON-DC1. LON-DC1 runs Windows Server 2012 R2 and has the DHCP Server server role installed. The network contains 100 client computers and 50 IP phones. The computers and the phones are from the same vendor. You create an IPv4 scope that contains addresses from to You need to ensure that the IP phones receive IP addresses in the range of to The solution must minimize administrative effort. What should you create?
A. Server level policies
B. Filters
C. Reservations
D. Scope level policies
070-410 dumps Correct Answer: D


