SolarWinds Observability Self-Hosted Fundamentals Observability-Self-Hosted-Fundamentals Exam Questions

Page: 1 / 14
Total 75 questions
Question 1

Which two of the following settings are automatically enabled for a user with the default set of user permissions in SolarWinds' Hybrid Cloud Observability (HCO)? (Choose two.)



Answer : C, D

When a new user account is created in the SolarWinds Platform, it is assigned a set of 'Default' permissions designed to provide a 'Read-Only' baseline of visibility. According to the SolarWinds Platform User Account Management guide, the platform is configured to ensure that new users can immediately benefit from the monitoring data without having the power to accidentally modify the environment.

Specifically, view all active alerts (C) and view all existing reports (D) are enabled by default. This ensures that any team member with a login can see the current health of the infrastructure and access historical performance data. These are considered 'Passive' rights that allow for operational awareness. Conversely, disable session time out (A) is a security-sensitive setting that is typically disabled by default to prevent abandoned sessions from remaining active on public or shared workstations. Self-manage dashboards (B), while a common feature, often requires explicit 'Dashboards' or 'View' management permissions to be toggled on by an administrator to prevent a proliferation of unmanaged or redundant dashboard pages within the database. By defaulting to alert and report visibility, SolarWinds follows the principle of providing immediate information for troubleshooting while reserving management and security-override functions for designated administrators.


Question 2

A user account has been granted administrator rights in the web console. By default, which area is disabled for the user (i.e., unable to add, edit, schedule, or delete)?



Answer : C

In the SolarWinds Platform, 'Administrator' rights in the Web Console grant extensive control over monitoring configurations, but they are distinct from 'System Administrator' or 'Security Administrator' roles. According to the SolarWinds Platform User Account Management guide, a Web Console Administrator can manage nodes, create alerts , build reports , and customize dashboards.

However, for security reasons, the ability to manage passwords---specifically the credentials used for polling (SNMP strings, WMI service accounts, or external integration secrets)---is often restricted. While an admin can assign an existing credential to a node, the ability to add, edit, or view the clear-text/obfuscated passwords within the centralized Credential Library is a separate, higher-level security permission. This prevents a standard Web Administrator from potentially harvesting sensitive service account passwords from the database. This 'separation of duties' ensures that while a user can manage the monitoring environment, they cannot necessarily compromise the security of the underlying infrastructure accounts.


Question 3

CPU utilization is being monitored on a critical Windows server and is set to notify when utilization exceeds 90%. Notification parameters are set to disregard those brief spikes over 90% and focus on sustained periods above 90%. What should be configured to accomplish the notification goal?



Answer : C

To prevent 'alert noise' caused by temporary performance spikes, the SolarWinds Platform allows for threshold persistence. According to the SolarWinds Platform Administrator Guide, simply setting a threshold at 90% would trigger an alert the moment a single poll returns a high value.

The correct configuration to ensure only sustained high utilization triggers an action is to set the node to change CPU status if the threshold is met for multiple polling cycles. This is found in the 'Edit Node' properties under the Thresholds section. For example, if the polling interval is 2 minutes and you set the condition to '10 minutes' (or 5 consecutive polls), the CPU status will only transition to Warning or Critical after the utilization has stayed above 90% for that entire duration. This filtering happens at the node/status level, ensuring that the alert engine only fires when there is a legitimate, sustained performance bottleneck rather than a transient spike caused by a routine background process.


Question 4

When viewing an AppStack environmental view, it is noted that a specific ESX host and related virtual machines are not present in the stack views. What is the cause of this issue?



Answer : A

AppStack relies on the relationship data collected by the Virtualization Manager (VMAN) and Server & Application Monitor (SAM) modules. For an ESX host and its virtual machines (VMs) to appear and be correctly mapped in the stack, the platform must be able to 'walk' the relationship from the hypervisor down to the guest OS.

The most common cause for missing virtualization data in AppStack is an incorrect polling method. To show the relationship between a physical host and its VMs, the node must be added to SolarWinds using the 'Poll for VMware' or 'Poll for Hyper-V' options. If the ESX host was added as a standard ICMP (Ping) or SNMP node without specifically enabling the virtualization polling credentials (linking it to the vCenter or the host's direct management API), the platform will see the host as a standalone server. Consequently, it will fail to discover the 'parent-child' relationship between the host and its virtual machines. Without this verified architectural link in the database, AppStack cannot 'build' the visual stack, leaving those entities out of the environment view.


Question 5

Agents have been deployed to a Windows server on a network. The agent is to initiate communication with the application server for all agents. Which firewall port needs to be opened?



Answer : C

SolarWinds agents support two communication modes: 'Server-Initiated' (Passive) and 'Agent-Initiated' (Active). According to the SolarWinds Platform Agent requirements and port information, the direction of communication determines which firewall ports must be open.

When an agent is configured for Agent-Initiated communication (where the agent on the managed node reaches out to the SolarWinds server), it uses TCP port 17778. This port must be open for inbound traffic on the SolarWinds Main Polling Engine or Additional Polling Engine. This mode is highly beneficial for monitoring servers in DMZs or remote sites where the SolarWinds server cannot initiate a connection through the firewall, but the remote node is allowed to communicate back to the primary management network. Port 17777 (Option B) is used for the legacy Orion Information Service, and 17790 (Option D) is used for specific client-to-server messaging in different contexts, but 17778 is the dedicated, encrypted port for agent-initiated data transmission.


Question 6

From which two of the following locations can CPU load be excluded from contributing to overall node status? (Choose two.)



Answer : B, D

By default, the 'overall status' of a node (Up, Warning, Critical) is calculated based on its availability and the health of its child components, such as CPU and Memory. According to the SolarWinds Platform Node Management documentation, administrators can fine-tune this rollup behavior to prevent non-critical metrics from turning a node 'red' on the dashboard.

Edit Node Properties (B): Inside the 'Edit Node' page, there is a section for 'Thresholds.' Here, an administrator can uncheck the box that allows CPU load to contribute to the node's overall status. This is useful for servers that consistently run high CPU but are otherwise healthy.

Node Child Status (D): Within the global SolarWinds settings, administrators can manage 'Node Child Status Participation.' This centralized menu allows you to define which sub-elements (CPU, Memory, Interfaces, etc.) are allowed to influence the parent node's status.

Muting a node (Option C) only pauses alerts and does not change how status is calculated. The All Nodes widget (Option A) is a visualization tool and does not provide the configuration settings to change the underlying status logic.


Question 7

How can access to all reports be removed from user accounts?



Answer : D

In the SolarWinds Platform, report access is governed by both functional permissions and account limitations. While 'Disable Manage Reports' (Option B) prevents a user from editing or creating reports, it does not necessarily hide the 'Reports' menu or prevent the user from viewing existing reports they have access to. To completely remove the visibility and accessibility of all reports for a specific user account, an Account Limitation must be applied.

According to the SolarWinds Platform User Account Management documentation, account limitations act as a security filter that restricts what the user can see throughout the entire Web Console. By navigating to Settings > All Settings > Manage Accounts, selecting the user, and editing their Report Limitation, an administrator can choose 'No Reports'. This configuration ensures that when the user logs in, the Reports section will either be empty or completely hidden from their navigation bar, regardless of their other permissions. This is the most effective method for high-security environments or multi-tenant deployments where certain users should have zero visibility into the historical performance data or inventory summaries contained within the reporting engine.


Page:    1 / 14   
Total 75 questions