D-PDD-DY-01 practice questions
Dell · D-PDD-DY-01 · 300 questions
Original practice questions for the Dell PowerProtect Data Domain Deploy v2 (D-PDD-DY-01) exam, covering the pre-deployment check, deployment, and post-deployment of PowerProtect Data Domain systems — framed as a physical deployment engagement: rack-and-stack at a customer site, then bring-up and integration with DD Boost, CIFS/NFS, replication, and Secure Multi-Tenancy.
This course contains the use of artificial intelligence.
About the D-PDD-DY-01 exam
- Time allowed
- 1 hour 30 minutes
- Questions
- 50
- Passing score
- Not published by Dell
- Format
- Multiple-choice
Schedule this exam The certification this earns
Exam details published by the vendor, checked 23 September 2026. Vendors change fees and formats without notice — confirm on the vendor's own page before you book.
Practice Quizzes
Test your knowledge with standard 20-question practice sets.
Quiz 1
Quiz 2
Quiz 3
Quiz 4
Quiz 5
Quiz 6
Quiz 7
Quiz 8
Quiz 9
Quiz 10
Quiz 11
Quiz 12
Quiz 13
Quiz 14
Quiz 15
Browse by Domain
Study specific topics at your own pace.
Pre-Deployment Check · 42 questions
- A customer hands over raw front-end numbers at kickoff: 2 PB of VMs and file systems to protect, growing 30 percent a year, and expects one Data Domain system to hold it all. An engineer is about to choose a platform tier. Why must those raw front-end estimates be translated before a platform can be selected?
- The customer's backup administrator states that nightly backups of 40 TB of front-end data must complete inside a six-hour window. The new Data Domain appliance looks comfortable on capacity alone. What does that backup window tell the engineer during the pre-deployment review?
- A requirements interview finds that backups will come from NetBackup, from Veeam, and from a legacy NetApp filer that runs no backup agent. The engineer must record which Data Domain connection methods each source needs. Which mapping belongs in the design?
- Two departments will share one new Data Domain system, but the security review requires that neither can see or address the other's data, namespaces, or administration. When should the engineer capture this requirement, and what design decision does it drive?
- A compliance officer in a regulated industry insists that no backup copy may be deleted or altered by anyone, including the backup administrator, until seven-year retention has fully expired. Where does this requirement belong in the deployment plan, and what feature answers it?
- During the security requirement review, the customer's security team demands that the encryption keys protecting backup data at rest be held in their own external key manager rather than on the appliance. What is the correct pre-deployment action for the engineer?
- The DR plan requires a replicated copy of a new Data Domain system at a site 800 km away, and the survey measured 200 ms round-trip latency on a constrained WAN link. What determines whether this replication design is feasible?
- After last year's ransomware incident, the customer demands a backup copy that an attacker holding production administrative credentials can never reach from the production network. Which pre-deployment response is correct?
- The design calls for one Data Domain head unit plus two expansion shelves, and facilities asks how much rack elevation to reserve before the order ships. How should the engineer determine the correct amount?
- During the site survey, facilities shows the engineer the target rack, which has two PDUs fed from a single circuit. What power verification belongs in the pre-deployment checklist before the system ships?
- A fully loaded expansion shelf is far too heavy for one person to carry, and the path from the loading dock crosses a freight elevator and a narrow corridor door. When and how should this be handled?
- The proposed rack position sits near a roof line where the data center runs warm, and summer readings have crept above the mid-20s Celsius. What should the engineer do about this during the site survey?
- Before arrival, the network team asks what the Data Domain deployment will need in writing. The system must support administrative access, backup traffic, and replication to the DR site. What should the pre-deployment network plan contain?
- The customer's policy issues every device an address through DHCP with no DNS records, but the deployment plan wants to administer the new Data Domain system and issue its certificates by hostname. Which pre-deployment requirement resolves this conflict?
- The security team runs a default-deny firewall and asks the engineer to produce, as one deliverable, everything that must be opened for the new Data Domain system. What belongs in that deliverable, and why is it a first-week item?
- A small remote office wants Data Domain deduplicating backup behavior for a few terabytes, but the site has a single VMware host, a small closet, no rack space, and no spare power. Which form-factor decision do the captured pre-deployment requirements support?
- The customer wants five years of monthly backup copies retained on cheaper storage and asks what the appliance design must include right now to make that work. What is the correct pre-deployment answer?
- Before shipping, an engineer notes the DD OS version the new platform will run and the customer's backup application and media server versions. What is the correct compatibility action, and where does the answer come from?
- The data center permits no outbound traffic without a security exception, and at the design review Dell support asks how proactive call-home support will work on the new Data Domain system. What is the correct pre-deployment action?
- The customer's change board approves exactly one maintenance window, Sunday from 02:00 to 06:00, for introducing the new backup target to production. What should the engineer do with that information during pre-deployment planning?
- At kickoff, the design review settles hostnames, the IP scheme, administrator contacts, and who signs each project phase. From the requirements task's point of view, what closes that task?
- Crates arrive on a Friday afternoon. Working through the installation checklist, the engineer opens the packing list. What is the engineer reconciling it against, and why is that the checklist's first hardware step?
- The hardware is racked, and the engineer reaches the service-tag portion of the installation checklist. What is the correct first step with service tags?
- Every service tag is now recorded on the installation worksheet. Before touching a screwdriver, the engineer proceeds with the pre-installation checklist. What is each service tag used for at this stage?
- At the dock, a carton holding new Data Domain gear shows a crushed corner, and the tipped-package indicator on its side has tripped. The carrier driver waits for a signature. What does the installation checklist's receiving step tell the engineer to do?
- Pre-staging a PowerProtect Data Domain head unit, the engineer opens the rail kit and notices the shipped rails don't match the customer's rack type. The customer's team wants to 'just mount it, it will fit.' What does the installation checklist tell the engineer to do?
- During receiving, the project manager asks why the engineer is photographing every service tag and serial number into the deployment binder instead of just typing in the head unit's serial. What is the best answer?
- Receiving verification shows the Data Domain head shipped with a DD OS version older than the minimum required by the customer's backup application support matrix. The install is scheduled for today. What does the installation checklist's software-version step call for?
- Before the first customer backup is allowed to write to a freshly built Data Domain system, the engineer reads the DD OS release notes for the exact planned build. Which pre-installation practice does this support?
- At unboxing, the power cords included with the appliance end in a connector type the customer's PDUs don't have, and someone reaches for a third-party adapter. What should the installation checklist's power section have caught, and what is the right response?
- A site-survey photo shows the target rack, and the engineer is about to rack the head unit on the morning of the install. How should the installation checklist's rack and mechanical section—mounting hole pattern, rack depth, rear service space—be handled?
- On install morning the head unit is staged and the schedule says start today, yet the paperwork shows the expansion shelf's pallet is still sitting in customs. What does the installation checklist's shipment-verification step call for?
- The accessory kit holds two lengths of storage interconnect cable, and the planned layout puts the expansion shelf several rack units below the head unit. What does the checklist's cabling section call for before the install day?
- The customer's rack uses square mounting holes, and the rail kit's hardware list shows screws that mate with cage nuts—yet the box contains screws and no cage nuts. What does the checklist's mounting-hardware step call for?
- At the staging area before racking, the checklist calls for unpack-and-inspection steps and handling-equipment guidance. The team's lift is rated below the loaded chassis weight and someone suggests 'being careful instead.' What does correct staging practice require?
- The installation checklist has blanks for hostname, the management addressing choice between static and DHCP, and the DNS and gateway entries. The on-site engineer plans to 'pick sensible values at bring-up.' What does the checklist intend by having these filled from the design document beforehand?
- The checklist's loading plan puts the expansion shelves at the lowest rack positions, but the customer's technician wants the head unit at the bottom 'because the lights look better down there.' What wins?
- The design requires encryption at rest and cloud tiering, and the installation checklist includes a step confirming the order actually includes those features. When should that entitlement check happen, and why?
- Cutover day arrives, the only person the installer knows at the customer site is on vacation, and nobody else holds badge access to the server room. The installation checklist's contact block had been left blank. What is that checklist item actually for?
- The physical installation is complete and the system is reachable. The project manager asks what closes out the installation-checklist paperwork for this engagement. What completes the task?
- Leaving the server room, the engineer runs the checklist's final sweep: service tags recorded, photographs taken, serials listed. A colleague suggests doing that later from the shipping paperwork at the hotel. Why does the checklist make it an on-site sweep?
- Packing-list reconciliation against the checklist at 4 p.m. the day before install finds one expansion shelf unaccounted for—ordered but on no delivery record. The team wants to rack what they have and hope the shelf turns up. What does proper checklist discipline require?
Deployment · 156 questions
- A fully populated head unit sits at the dock and a single customer technician offers to carry it to the rack 'like a web server.' The installation checklist lists the loaded chassis weight. What do the handling rules require?
- An elevating plan places the fully loaded expansion shelves at the top of the rack 'to save the good lower holes for future gear.' Which physical rule does that plan violate?
- The customer insists the head unit be racked above both expansion shelves because its status lights face the aisle. What determines the final stacking order?
- Rails are installed in a four-post rack, but the rear brackets ended up at a depth that will leave the chassis sticking far out past the rack's rear posts. What should have been adjusted before the unit was offered to the rack?
- After the unit is mounted with its bezel attached, the rack's glass front door will not close. Which verification step was missed before mounting?
- Expansion shelves were stacked flush with no gap, and now a failed drive in the lower unit cannot have its carrier opened because the unit above blocks the handle. What constraint did the original stacking ignore?
- Cabling the second power supply of an upper shelf means reaching behind a neighboring chassis at the rear, and there is no room to route the cord. What should have been planned during the racking?
- After the head and shelves are installed, the rack has open U slots, and the customer's facilities tech stuffs them with cut-up cardboard 'to direct airflow.' What is the correct treatment of empty rack space?
- A Data Domain head unit slides smoothly onto its rail kit, the installer hears the latch click, and he walks away for lunch with the chassis resting on the rails and nothing else fastened. What is the correct condition for a racked chassis?
- An engineer wearing a wool sweater kneels on carpet and pulls a component out of a Data Domain shelf to reseat it, with no wrist strap or grounded mat anywhere nearby. What is wrong with this handling?
- Three identical expansion shelves are racked for one Data Domain head, and before powering anything on the tech labels each shelf with its planned position number from the elevation drawing. What does that labeling accomplish?
- An install crew racks and cables three expansion shelves straight from their shipping crates. Before applying power, one engineer walks the front of every shelf pressing each drive carrier to confirm it is in and latched. What is the purpose of that pass?
- A fully loaded Data Domain head plus three shelves is scheduled into an older rack that already carries core switches and two aging arrays, over carpet tile on a concrete slab. What must happen before this equipment is loaded into the rack?
- An elevation drawing shows twelve free rack units spread across two non-adjacent sections. Before moving hardware, the engineer totals the documented U heights of the head and all planned shelves. What is that check deciding?
- Once the head and all three shelves are mounted, a reviewer notices the installed total exceeds the rack manufacturer's published static load rating. What does that rating mean in this situation?
- To reseat a component, a technician pulls a fully cabled Data Domain head partway from the rack; every rear cable is pulled taut, and the connectors are straining against their ports. What was missed when the cables were installed?
- While a chassis is being slid in, the team finds the left rail sits one hole higher than the right, and the chassis binds halfway in. What was wrong with the rail installation?
- Mid-slide, a Data Domain head meets firm resistance, and the team leader tells the crew to 'push through it.' Why is forcing the chassis the wrong call?
- The install-day schedule lists dock, stage, rail, head, shelves, and power as ordered steps instead of letting the crew open whichever crate is handiest. What is the value of a planned install sequence?
- In a shared rack, live production gear sits right beside the work area, and a technician props a loaded chassis's corner against the neighbor's bezel to free both hands. Which working-around-live-equipment rule is being broken?
- Racking is finished, and before cabling starts the project asks for proof of the final layout. What belongs in the installation record at this point?
- A rail bracket arrives with a bent mounting flange, and the tech reaches for a rubber mallet to straighten it out and press on. What should happen instead?
- Before any cable enters the rack, the lead runs a pass checking every fastener, latch, and lock across the whole head-and-shelf stack. Which part of the racking task does this close out?
- Two expansion shelves must chain to the head, and a tech starts plugging into whichever ports sit closest to each shelf. Why must the chain follow the prescribed start port and order instead?
- The customer wants four expansion shelves on a single chain from one head port, but the platform's documentation allows fewer shelves per chain on this model. How should the installer handle that request?
- To save cable, an installer runs a single interconnect from each shelf to the head; the run looks tidy until testing tugs one cable and a shelf disappears. What did the single-cable approach defeat?
- The kit includes both short and long interconnect cables, and the tech grabs a long one for every link between adjacent units. What is the correct thinking on cable-length selection?
- During cable dressing an interconnect gets routed around a sharp rack-post corner and cinched tight with a zip tie pressed against the connector boot. Which cabling principle is at risk here?
- Six weeks after install, support asks which cable runs from the head's port to shelf 2 port A1, and the rack holds a tangle of identical unmarked interconnects. Which install-time practice would have prevented this?
- After cabling, the engineer boots the head and checks that every physically installed shelf appears in the system's enclosure view. What is this check accepting?
- On power-on day the tech energizes the head first while the shelves stay dark for a few extra minutes, and the boot reports missing disks. What went wrong with the power sequence?
- Inside one shelf chain, the tech mixes two different grades of interconnect cable because 'they both clicked in.' Why can this be a problem even though the connectors mate?
- A shelf disappears from the enclosure list right after someone bumps the rack during cable dressing, though it was visible immediately before the nudge. Where does troubleshooting start?
- While dressing the rack you find the shelf interconnects bundled tightly along the PDU run, directly behind the power cords. What is wrong with this practice, and what should change?
- A drive in an expansion shelf needs replacement, but every cable between the shelf and the head was pulled to full length, so the shelf cannot slide out. Which cabling practice was skipped?
- At first boot every expansion shelf appears in the enclosure list, and the engineer is about to sign off the cabling. Why is 'all shelves visible' not yet enough?
- A junior tech hunts for the separate management cable that is supposed to connect a new expansion shelf, and the engineer says there isn't one. Why?
- An installer finishes the SAS cabling, traces every physical cable against the documented interconnect map, and initials the as-built sheet. What does that verification step actually establish?
- Six months after install, a third expansion shelf arrives and the tech lands it on a free port mid-chain without consulting any documentation. Which set of rules did this installation skip?
- A shelf has two interconnect ports on the back, and a rushed tech jumpering to the next shelf lands both of them on the same port there, treating the pair as interchangeable. What is wrong with that cabling?
- The cable dressing looks immaculate, except every hook-and-loop strap is cinched directly over the connector bodies 'so nothing wiggles.' What must be corrected in this dressing?
- Before the head unit is ever powered, both PSUs of every expansion shelf are cabled, with each shelf's two feeds landing on different PDUs. Why is this a precondition of head bring-up rather than later cleanup?
- To correct a rail alignment, an installed expansion shelf is shifted in-rack; afterward nobody touches its cabling, because the chain 'has always been fine.' What must happen before the chain is trusted again?
- The head's rear panel is crowded with similar-looking ports and install day has a customer watching. What determines which sockets the shelf interconnects go into?
- The chain was healthy on temporary bench power, but dies when the rack's PDUs are transferred to house circuits during a breaker test. Which part of the power-cord task was clearly incomplete?
- On install day the head's dedicated service port gets its own cable onto the customer's service network while the data interfaces are still bare. Why does this deserve a cable of its own before cabling closes?
- Before any cable clicks in, the engineer walks the head's rear marking which physical ports will become management and which will carry backup data, per the approved design. What is the purpose of this pre-cabling step?
- Both of the head's redundant PSU cords are plugged into the same PDU because it was closest. What has the technician actually installed?
- The head's PSU inlets and the customer's PDU outlets belong to different IEC connector families, and the cords in the appliance box may not fit either end. What must be resolved before a power feed can be relied on?
- The second PSU's cord falls a few inches short, and the tech is about to plug a consumer power strip into a PDU outlet to bridge the gap. Why is that practice rejected?
- A data link must reach a switch across the hall, beyond what copper twinax comfortably spans, and the tech is weighing twinax against fiber. What should drive the media choice for this run?
- The new data link is cabled and reports up, but the switch port shows half the expected speed. What verification was missed, and why does it matter now?
- The network team offers one access-VLAN switch port today, while the design calls for tagged VLAN separation later for tenants. What should the deployment do about the switch side while cabling?
- Six identical blue cables leave the head's rear and disappear into the same top-of-rack switch. Which labeling practice prevents a mis-patch during future work?
- The customer 'turns on jumbo frames' on the one switch port facing the replication link and declares it done, yet replication throughput never changes. What understanding is missing here?
- At the rack, the team debates whether replication should ride the shared backup LAN or get dedicated ports. Once the decision is made, what does it change about the physical installation?
- The head's failover NIC pair is cabled to two ports on the same access switch; weeks later a firmware reboot takes that switch down and both NICs go dark together. Which cabling principle was missed?
- A link keeps dropping in the night. On tracing the run you find a leftover generic SFP+ from a drawer was used because the supported optic was out of stock — and it 'was lighting up just fine.' What does this installation violate?
- You cable a 10GBASE-T run from the Data Domain head to the core using two patch panels in the path, and the channel sits close to the maximum distance for copper. The link trains up, but weeks later the backup team reports slow transfers and rising interface errors. What best explains this pattern?
- An engineer finishes the last cable, opens the Data Domain management GUI, and starts entering network settings while half the interfaces still have unverified link state. What should have happened first, and why?
- After a beautiful cable-dressing pass, the rack's branch-circuit breakers sit buried behind a bundle of spiral-wrapped power cords. What did the dressing job violate?
- At handover the customer asks for the as-built port map, and the team realizes nobody recorded which head port lands on which switch port while the cables were going in. What practice does this failure point to?
- With spare time at the rack, a technician plugs patch cords into every remaining spare port on the head and the top-of-rack switch, 'in case they're needed later.' What is the strongest reason not to do this?
- Mid-engagement the network team announces it will 'simplify' the design: the head's service path will now live on the same VLAN as production management traffic. What is the most important objection?
- On first boot the engineer opens the GUI's interface list, notes which interfaces report link, then walks behind the rack comparing each name to the cable actually plugged into that port. What does this cross-check accomplish?
- Every cord in the stack is plugged in, and before energizing, the engineer totals the head's and shelves' expected draw against each circuit's rating. Why is this arithmetic part of connecting power cords?
- Before any configuration, an engineer plugs a known-good laptop on the management subnet into the design and verifies a clean path to the head. Which task does this verification close out, and why at this point?
- A brand-new head is racked and powered but has no IP address yet, and an engineer needs a shell on it right now in the server room. What is the intended access route?
- First login over the service path succeeds, and the system immediately requires a new admin password before allowing anything else. Why does this credential step come first in the access workflow?
- A junior asks why the senior keeps switching between the SSH terminal and the browser console during bring-up — 'isn't one of them going away?' What is the correct understanding of the two access planes?
- The first-access setup on a fresh system walks through license, hostname, DNS, NTP, and email before letting real work proceed. Why do these items belong to this phase?
- While configuring basic management networking, a typo places the head's address in a VLAN that no longer exists, and the system goes dark — no GUI, no SSH. What is the designed way forward?
- An intern gets a first CLI session on the head and starts typing configuration commands at the very first prompt, skipping every show command. What working habit is being skipped, and what does it protect against?
- The customer offers the corporate helpdesk password as the head's admin password, 'because everyone already knows it.' Why does the deployment standard reject this outright?
- The automation team plans scripted read-only health checks next month and asks how to authenticate to the CLI without embedding passwords in scripts. What should the deployment access work arrange now?
- The very first GUI visit shows a browser security warning, and the customer's security officer demands an explanation before anyone proceeds. What is the correct explanation?
- The static management address works perfectly now, and someone suggests unplugging the head's service-port cable 'for tidiness.' What is the strongest reason to leave it connected?
- During the engagement, three engineers all authenticate as admin, and at the end nobody can say who changed what. What account practice would have prevented this?
- The customer wants one account that a compliance reviewer can use to read logs and system state but change nothing. What is the right way to serve that request on the appliance?
- During bring-up a scanner starts hammering the management interface with login attempts, and after several failures even the correct password is now refused. What is happening, and what should the team already have ready?
- The customer eventually plans to run fourteen DD systems and asks whether all the per-system GUI work so far was wrong. What is the correct answer?
- Before the team enables SupportAssist, the customer asks exactly what will leave the appliance when it is turned on. What is the correct way to handle that question?
- The data center is fully air-gapped and outbound connections are forbidden, yet vendor support will need diagnostic data someday. What access pattern is the sanctioned one for such a locked-down site?
- The new Data Domain appliance reports healthy clock sync with the corporate NTP servers, yet every support case pulled from it shows log timestamps exactly six hours ahead of what the on-site team expects for their US Central site. What is the most likely cause?
- An engineer configures time synchronization through the management GUI on a fresh appliance, enters the site's time servers, closes the browser tab, and marks the checklist item complete. Days later, log correlation against other systems is unreliable. What step was missing?
- Initial access and setup of a new appliance are complete, and the team wants the deployment record to capture the configuration state so future troubleshooting can see what was true at handover. Which practice achieves that?
- Before leaving the site, an engineer runs read-only show commands covering the platform, interfaces, enclosures, and capacity, and archives the output with the deployment record. Why is that baseline the most valuable thing captured during first access?
- During a multi-day deployment, the management GUI remains logged in with the admin account on a shared jump host while the engineer steps away for the whole lunch break. What is the correct view of session hygiene for privileged management access?
- After the move off the service port, the appliance answers perfectly from a laptop plugged in beside it, but nothing on the customer's admin subnet can reach the management GUI. The address, mask, gateway, and DNS settings all verify correct. What gap in the access process does this expose?
- The customer's network sheet proposes dynamic addressing for every new device, but the backup applications will be configured against the appliance's management identity. What is the correct addressing strategy for the management interface?
- A freshly configured appliance answers HTTPS from a laptop on the same server-room subnet but is unreachable from the operations VLAN one router away. Address, mask, and DNS are verified correct. Which single missing setting best explains this pattern?
- A backup application is configured with the appliance's fully qualified hostname. The name resolves to the correct address, yet the deployment review still flags the name-service configuration for this system. Which resolution problem would the review be concerned about?
- During setup the engineer configures a single DNS server — the site's primary domain controller. Weeks later that DC goes offline for patching and the appliance can no longer resolve names for mail or time services. Which basic name-service hygiene was skipped?
- A secure data center forbids all outbound internet connections. During network configuration the engineer finds a pre-populated NTP entry pointing at a public internet time pool and leaves it in place. The security audit flags it. What is the correct approach to time sources in this environment?
- A browser refuses the management GUI's freshly issued certificate as not yet valid or expired, and the backup application's schedules fire at the wrong wall-clock times on the same appliance. What single root cause links these symptoms?
- The monitoring team wants to poll the new appliance for health metrics and proposes SNMP v2c with the read-only community string 'monitor' across the production LAN. What is the correct SNMP decision during management setup?
- An engineer enters the monitoring platform's address as the SNMP trap destination during setup and considers alerting complete. The first real disk failure weeks later produces no ticket at all. Which step turned a configuration into an assumption?
- Alert email on the appliance is configured with the correct relay address and a valid sender domain, but the relay runs a receive connector set to silently discard mail arriving from the storage VLAN. What proves the mail configuration is actually complete?
- The security operations center requires every management event from the new appliance to appear in their collector. When should that event forwarding be established, and what completes the task?
- The network team is standardizing interface MTU on the new appliance. Replication runs over a WAN link engineered for jumbo frames, while management sits on ordinary corporate VLANs. What is the correct approach to MTU here?
- Cabling left three data interfaces linked with working switches, although the design uses only two. During configuration the engineer administratively disables the unused ones. What is the strongest reason for that action?
- The network team offers to place the appliance's management interface on the backup-data VLAN because 'the port is already there'. What is the correct design response?
- Security sign-off requires eliminating the browser certificate warning that appeared when administrators first accessed the management GUI. What is the accepted way to satisfy that requirement?
- A vulnerability scan flags the appliance's management web service for supporting obsolete TLS protocol versions. What is the correct hardening direction for the management plane?
- Weeks after go-live, the initial service port still carries the temporary addressing used during installation, and no one documented any decision about it. What is the correct treatment of the service port at the end of the network configuration work?
- At acceptance testing, the team pulls the cable on the active management link and the GUI stays unreachable for the entire failover period — redundancy had been assumed but never demonstrated. What belongs in the basic network configuration to prevent this outcome?
- At the rack an engineer names the appliance 'dd1'; at integration it turns out an existing system already uses 'dd1' in the customer's standard domain, and application configurations become ambiguous. Which hostname practice would have prevented this?
- The design places management on a tagged VLAN, and the engineer configures that VLAN tag on the appliance's management interface. The cable, however, lands on a switch port configured as an untagged access port, and the appliance turns out to be completely isolated. Why?
- During commissioning of a branch-office Data Domain you plan replication to the DR appliance at head office. The management interface is configured with the branch LAN's address and netmask and the branch's default gateway, yet the head-office target subnet is only reachable through a different router that the branch gateway does not know about. The target is up and its firewall permits the traffic, but a ping from the appliance console to the target fails while a laptop on the same LAN succeeds. What should the network configuration phase have included?
- During a maintenance window an engineer changes the management IP address, netmask, default gateway, primary DNS server, and NTP server on a Data Domain, all in one sitting, to match the target design in the handover packet. When finished, the management GUI is unreachable, and the engineer decides to roll all five settings back because nobody can tell which change caused the loss of reachability. Which working practice would have prevented this outcome?
- The network team opens a firewall ticket asking which hosts should be allowed to reach the management interface of a newly deployed Data Domain. The junior engineer drafts a rule allowing the appliance's management IP from the entire corporate /8, reasoning that nobody will ever file another access ticket again. What is the correct response to that draft?
- The acceptance packet for a just-commissioned Data Domain needs a definitive management-network page, but three email threads quote conflicting IP addresses, gateway, DNS servers, NTP source, and SNMP or mail targets, and nobody can say which values are actually configured. What should the handover documentation be built from?
- A NetBackup environment backs up clients located across slow WAN links, and backup streams routinely saturate those links, pushing the window well past dawn. The architect is wiring in a Data Domain and wants the connectivity mode that most improves stream efficiency across the network before the appliance ever sees a byte. Which choice fits?
- A small virtualization shop runs a backup server that can only write its backup files to mounted shares; the product offers no plug-in or appliance integration of any kind. The new Data Domain must serve as the target anyway. What has to exist on the appliance side for this backup connectivity?
- A backup product offers two ways to target a new Data Domain: a generic SMB share mount, or the vendor's dedicated dedupe-appliance integration for Data Domain. The administrator prefers the share route because its wizard is simpler and needs no extra software. Why should the integration win this argument?
- A NAS estate of NetApp filers must be protected to the new Data Domain. Security rules forbid installing backup agents on the filers, and monitoring shows filer CPU already peaks high in business hours, so management wants no file-level backup reads consuming filer resources. How should this backup connectivity be set up?
- A legacy backup application, a mainframe-era product still running nightly jobs, can write only to tape drives and a tape library; it has no disk, file, or integration code paths at all. Physical tape is being decommissioned site-wide and a Data Domain replaces the library. Which connectivity approach fits the scenario?
- A content-archive platform needs to place objects on the new Data Domain using S3-style PUT operations against buckets. One engineer proposes carving out a CIFS share instead and having the platform's gateway drop files onto it, calling that close enough to object storage. What does the scenario actually require on the appliance side?
- The DBA team wants Oracle RMAN backups landing on the new Data Domain with the full deduplication benefit. They have mounted an NFS export from the appliance on the database hosts and propose writing RMAN backup sets to that filesystem as plain files. What should the deployment do instead for proper database-level connectivity?
- Four consumers request the same new Data Domain: NetBackup media servers, a backup server that only writes to mounted shares, a NetApp filer estate, and an archive platform that speaks only S3. A junior engineer asks which single protocol the appliance should therefore be deployed with. What is the right answer?
- Acceptance testing of a new Data Domain turns up a finding from the security team: the backup path exported over NFS is mountable by every server on the roomy campus subnet, not just the two media servers named in the design. The engineer is baffled, because the NFS service was enabled exactly as the connectivity runbook says. What did the connectivity configuration miss?
- A Windows backup server needs a CIFS target on the new Data Domain, and the operations standard requires domain-managed service accounts rather than per-box local passwords, because account lifecycle is already handled centrally. The appliance, as shipped, carries its own local user database. What decision does the CIFS connectivity setup force the engineer to make?
- The firewall team files a ticket asking for "the Data Domain ports" for the upcoming deployment, and the engineer starts pasting the complete list of every port the appliance platform could possibly use, from documentation, into the request. What is the correct way to build that firewall request?
- Two backup applications and a departmental archive will write to the same new Data Domain. An administrator proposes that everyone just shares one big folder for simplicity, with different sub-folders per application. What is the correct storage-path design on the appliance?
- A backup application's setup wizard is asking for Data Domain credentials for its optimized Boost path, and the engineer reaches for the sysadmin login used during commissioning because it is already open in another browser tab. What credentials should the application actually be given?
- A large virtualization estate requires roughly 2 GB/s of ingest overnight to fit its protection window. The proof-of-concept mounted a single CIFS share from the new Data Domain and a single job stream, and it managed only a small fraction of the target rate, so the administrator now suspects the appliance itself is simply too slow. What design change does this scenario actually drive?
- A VTL deployment reaches a decision point: the media server has two spare fibre-channel HBA ports on the existing SAN, but that SAN is documented for decommission next year, and the same server also has spare 10-gigabit Ethernet ports. The administrator asks which transport the virtual tape should be presented over. What is the correct reasoning?
- A niche Linux application produces nightly archive bundles and supports exactly one transfer target protocol: FTPS. The administrator concludes the new Data Domain cannot be used for this workload because the product offers no NFS, CIFS, or backup-integration modes at all. Is that conclusion correct, and why?
- A managed service provider and an internal department are to share one Data Domain. The compliance rule is explicit: neither party's operators may see, address, or administer the other party's backups or configuration. The administrator asks whether dedicated MTrees with carefully restricted users already satisfy that requirement. What does the scenario actually call for?
- A backup application's configuration wizard rejects the Data Domain's hostname during target setup, yet the engineer can resolve that name from the appliance itself without trouble. To unblock the ticket before the shift ends, the engineer adds a hosts-file entry on the application server and moves on. What does the scenario's connectivity actually require?
- A backup server writing to a CIFS target on the Data Domain passed every commissioning test. Two weeks later a routine patch reboot leaves the first nightly job failing quietly, because nobody noticed the share had been a manual mapping that did not come back with the server. What did the deployment miss?
- An engineer enables a file protocol in the appliance's settings, runs the first test write from a client within ten seconds, and when the write fails immediately opens a network ticket accusing the intermediate firewall. Before blaming anything in the middle of the path, what should have been confirmed first?
- An application can reach the Data Domain either over plain NFS across a shared campus network that every department traverses, or over TLS-protected object or FTPS paths on the same network. The storage team wants to pick whichever option needs the least configuration. What should drive that protocol decision?
- A backup architect joins a project where a new application goes live next quarter and will need Data Domain targets. The room splits into CIFS fans and NFS fans before anyone has opened a design document. What makes the protocol choice repeatable instead of a habit argument?
- Bring-up on a new Data Domain head finished with the network settings typed in, but nothing has been exercised from the appliance itself. The lead wants basic testing to start in the right place. Where should it start?
- NTP servers were configured on a new Data Domain hours ago, and the acceptance sheet still has a blank next to "NTP". The engineer wants to close that line honestly. What should they do?
- SNMP targets were configured on a new Data Domain during bring-up, and the NMS console has received nothing yet. What closes the loop on SNMP during basic testing?
- A mail relay was configured on a new Data Domain so it can send alerts, but nobody has ever seen an email from the box. What is the honest way to close out the mail path during bring-up testing?
- All cables are dressed, connected, and labeled on a freshly racked Data Domain, and the engineer has the GUI open. What is the right first functional sweep of the cabled interfaces?
- The acceptance test for a Data Domain with a bonded management pair is to pull the active NIC's cable at the switch. What result makes that failover configuration acceptable?
- While an electrician tests circuits, one PDU feeding a Data Domain's redundant power supplies goes dark and the appliance keeps running. From a deployment standpoint, what does the team still owe this test?
- A Data Domain head with several expansion shelves has just finished its first boot after shipping. Before configuration goes any further, what does hardware verification require?
- At first bring-up, the engineer opens the storage views to check the Data Domain's filesystem status against the expected usable capacity. What result means this check passes?
- An NFS export is configured on a Data Domain, and the senior engineer mounts it from the backup host and copies a file in each direction before signing the file-services line. Why is that the right way to close file-service testing?
- On day one a customer studies the raw capacity figures and openly doubts the deduplication marketing. During bring-up testing, what is a legitimate way to answer that doubt?
- VTL is enabled on a new Data Domain with tape emulation configured, but the media server still lists zero tape devices. What must be true for VTL bring-up to count as complete?
- An NDMP target is configured on a Data Domain and a filer's backups will run through it, but no NDMP job has ever been run. What proves NDMP connectivity in this situation?
- DD Boost is enabled and configured on a Data Domain, but the backup application side has not been tested yet. What completes verification of the optimized path?
- The object store is enabled on a Data Domain for the archive team, and the team's lead asks how readiness will be proven before anyone commits production data. What is the correct bring-up test?
- Before handover of a new Data Domain stack, the team debates whether to run the platform's built-in health and diagnostic battery on it. What best justifies running it at bring-up?
- SupportAssist is configured on a new Data Domain and the support contract is on file, but the call-home connection has never been exercised. What is the correct finish for this item during bring-up?
- On acceptance day, an admin opens the Data Domain's GUI from the operations floor using its full hostname for the first time. What is this test actually verifying?
- Monitoring integrations on a new Data Domain were configured by three people over the past week, and each one says their piece 'probably works'. What standard should the team apply before sign-off?
- A DR-site Data Domain sits across the campus, and replication for it will not be configured until next month's DR project begins. What is the sensible scope for today's basic connectivity testing regarding that peer?
- A CIFS share is configured on a Data Domain; the Windows hosts can see it, but a Linux backup host cannot. During functional testing, what lesson should this situation teach the team?
- The customer is closing out a Data Domain bring-up and wants proof the basic tests actually happened, not just assurances from the team. What is the professional way to close basic testing?
Post-Deployment · 102 questions
- In go-live week of a Data Domain deployment, three contractors and two staff engineers are all logging in with the built-in administrator account. What should change about system access?
- After go-live, the customer hands over an org chart - full-time administrators, a security auditor, and a monitoring group that only needs to see status - and asks that each group receive "just what it needs". How should system access be built?
- Day one after handover: the backup operations team wants a login of its own so it can check filesystem usage, replication status and daily health output without being able to reconfigure anything. The built-in roles each give either too much or too little for that job description. How should the engineer provide the access?
- The enterprise standard is blunt: no local passwords on infrastructure devices. The new appliance currently knows only locally created administrator accounts. The directory team already has an operations group full of the people who will manage the box. What change brings the appliance into compliance?
- A hardening review proposes disabling every locally defined account the day directory login is confirmed working, leaving directory credentials as the only way in. The engineer is asked to sign off. What makes that recommendation dangerous?
- During a security interview the auditor asks how administrator passwords on the backup appliance are controlled. The engineer's honest answer is 'we always pick strong ones'. What should the auditor have found in place instead?
- A monitoring server will run read-only health-check commands against the appliance's CLI every night. The draft automation stores a human administrator's password inside the script. What should replace that arrangement?
- A retention setting on the appliance changed at some point last week. The customer wants a name and a timestamp, and the only constant in the environment is that the operations desk shares one administrator login 'for convenience'. What makes future change history actually usable?
- Three departments will share one appliance, each with its own dedicated storage space. Each department wants its own administrators who can fully manage their space but cannot see or touch what the others hold. Which design answers that?
- At 02:00 during a restore, a nightly automation holding a stale password hammers the appliance with failed logins, and the account the on-call engineer now needs gets locked out. The outage was survivable; the surprise was not. What should have happened before go-live?
- For the second time this month, the management GUI on a shared jump host was found logged in to the appliance since morning, unattended. The customer asks what the platform itself can do about the habit. What is the right answer?
- An integration engineer has resigned. Six accounts created during deployment for various applications and integrations are still active, and nobody can say which of them anything still uses. What is the professional way to clean this up?
- The application team wants a security-related setting changed on the appliance. The engineer who performs all day-to-day administration 'already knows the password' and offers to make the change himself inside this week's window. What does that sentence reveal that should be fixed in the configuration, not in his attitude?
- The compliance team wants standing eyes on administrator activity in the appliance - logins, commands, configuration state - with zero ability to change anything. What is the correct provisioning design?
- A new operator joins the team on Monday. The team lead asks why adding one person to the backup appliance needs a change ticket to the storage group, when the equivalent for every other system in the building is handled by the directory. What should have been configured to make that question legitimate?
- During last month's outage the vendor support path was enabled, a case engineer connected, and the system was saved. Security is now asking why that path is still open today. What governing practice was missed?
- Directory integration is reported as 'configured fine': the engineer tested it once with his own elevated directory account and proposes signing off the access work. The acceptance reviewer pushes back. What is missing from the evidence?
- Six months after go-live nobody can answer two questions: which accounts hold administrative rights on the appliance, and who or what owns each service identity. Which deliverable, had it existed, would have turned that audit into a fifteen-minute diff?
- During a 3 a.m. outage it emerges that the only person who knows the local emergency administrator password is on a flight and unreachable. Which arrangement should have been made while everything was calm?
- A post-go-live access audit finds that the built-in administrative account is still logging in weekly, even though every operator has had a named account since cutover. What is the correct reading of that finding?
- At the quarterly access review the security lead asks a fair question: what has changed in appliance access since the last review? Nobody can answer. Which operating habit turns that question into a fifteen-minute exercise every quarter from now on?
- The monitoring server discovered the appliance the day it was added and shows a green status, but every chart stays empty - the manager is polling a generic device template for this host. What is missing from the integration?
- A drive failed at 03:14 and the operations team found out at the next polling cycle, close to an hour later. The customer's standard claims 'monitoring sees everything'. Why the delay, and how should a platform like this be watched?
- Week one of the new monitoring standard leaves the operations team drowning: the appliance was subscribed to 'everything', roughly sixty alert types arrive, and most have no owner or runbook. How should the subscription be fixed?
- The appliance's filesystem crept toward full for weeks. Nobody was watching a chart. The first visible sign was backup jobs failing at the business sites one gray Monday. What control was actually missing?
- The appliance's email alerting went live early, pointed at every category and every administrator's inbox. Within a month the backup team had a rule archiving all of it unread. How should mail alerting actually be configured?
- The security operations center gladly ingested the appliance into its SIEM, then reported a problem: appliance events arrive but cannot be distinguished from firewall noise, and several fail to parse entirely. What configuration thinking was skipped at the forwarding stage?
- A startup with no on-premises monitoring platform wants vendor-hosted dashboards for its brand-new appliance - nothing to install locally. The team enables the cloud monitoring option in the management interface, yet the next morning the hosted portal still shows no telemetry for the system. Which prerequisite step most likely explains the gap?
- An engineer operates fourteen Data Domain systems across four sites. Every capacity or health question requires per-system logins, and answering 'which systems are near full?' recently took most of a week. Single-system monitoring is already in place on each appliance. What should be added post-deployment to fix this?
- A capacity planner forecasts the appliance's purchase dates by tracking how many bytes the backup application writes to the system each month, yet the appliance keeps filling faster or slower than those forecasts predicted. Which monitoring change produces usable forecasts on a deduplicating appliance?
- A support case opened on the appliance stalls because the support agent's first request is a system health collection, nobody on staff knows how one is generated or delivered, and the team ends up improvising a 2 GB upload through a laptop balanced on a rack rail. What post-deployment configuration would have made attaching health data to the case routine?
- A flapping network interface generates two hundred overnight pages and buries one genuine disk-failure alert in the flood, which nobody reads until morning. What configuration thinking would have kept the meaningful event visible through the storm?
- An audit finds that the appliance's SNMPv3 monitoring user password has been pasted into three network management station configs authored by two contractors, with slightly different values in each. What is the correct remediation thinking for this monitoring credential?
- A budget review asks whether the primary backup target is two years or five years from full. The engineer quotes today's percent-used and the raw capacity numbers from this morning's dashboard. What monitoring output actually answers a lifecycle question like this?
- The DR runbook promises recovery from a replica that is never more than an hour behind, yet no metric anywhere tracks how current the replication actually is. What monitoring configuration closes that gap?
- An SNMP trap announces a failed drive in 'shelf 2', but the rack row holds four identical shelves and the technician spends forty minutes opening doors hunting for the right amber LED. Which part of configuring the monitoring workflow was skipped?
- The network management station was misconfigured for a full month and nobody noticed - the appliance kept generating events, but nothing downstream was talking back. What principle of monitoring configuration would have surfaced this problem early?
- A quarterly resilience drill deliberately induces a monitored condition and times how long it takes until a human acknowledges it. Why is repeating this drill the right practice when the alerting was already proven working once at cutover?
- The customer asks for a monthly one-page picture of the backup estate - capacity, health, and reduction - instead of a human screenshotting graphs on demand. What should the monitoring configuration provide?
- A CA-signed certificate replaced the browser warnings on the management interface at go-live, and twelve months later the warnings returned - unnoticed until the day a partial outage made the GUI the only way in. What should have been added to the post-deployment monitoring set?
- Every backup job over NFS fails all morning, and the root cause turns out to be the file service on the appliance, which stopped quietly the night before. Hardware alerting had been firing healthily all month. What does the monitoring configuration lack?
- Three weeks after go-live, the security department mandates encryption at rest on the production appliance - which is now full of live backup data. Why is this a bring-forward decision rather than a checkbox that can be flipped at any time?
- A customer's key-management standard requires that an enterprise KMIP server hold all encryption keys while the appliance keeps only encrypted data. Before the appliance can actually run under that standard, what must exist?
- The KMIP cluster goes fully dark for a scheduled two-hour maintenance window on Friday night, while an appliance under external key management is mid-stream carrying live backup traffic. What is the realistic expectation for those two hours?
- An annual key rotation policy now applies to the encrypted backup stores, and the DBA objects that rotation means weeks of rewriting petabytes of backup data. What is the accurate answer about key rotation on these systems?
- The sole administrator plans to rotate the encryption keys alone at midnight 'to avoid disruption'. An auditor flags the plan. Which platform security capability is being missed, and what does configuring it correctly involve?
- A decommissioned expansion shelf is leaving the building for a vendor warranty return, and legal wants assurance that no recoverable customer data leaves custody. What is the sanctioned fast path for that assurance?
- A regulator requires proof that backup copies cannot be deleted until each copy's retention period expires - explicitly including deletions attempted by internal administrators. Which platform mechanism matches that wording?
- Two departments both request 'immutability' for their backup copies: one answers to an external regulator, the other just wants junior admins unable to delete last month's restore points. How should the platform's retention lock options be applied?
- Six months after go-live, legal revises a retention rule, and ops proposes to 'just flip the setting' on retention-locked stores whose data was locked under the old terms. What governing constraint must the conversation respect?
- A penetration test reports that the appliance's management web service still negotiates an obsolete TLS version with any client that asks for it. What is the correct hardening response for the management services?
- At go-live the appliance still has five protocols enabled from months of compatibility testing, while the approved design calls for only three. What is the right post-deployment action on the unused services?
- During a post-deployment review, an auditor asks what technically prevents a tenant A administrator from reading tenant B data on a shared Data Domain system. What must be configured to enforce that separation?
- During post-deployment, a customer's network team asks whether Data Domain-to-Data Domain replication across a WAN link needs a site-to-site VPN solely to protect replication payload confidentiality. What should you recommend?
- During a ransomware playbook review, an attacker is assumed to have every Data Domain admin credential. Which protection pattern is most defensible?
- During post-deployment hardening, Security requires CLI management for a zero-standing-privilege shop: no administrator should need to know or share a standing Data Domain password. You must choose an access-plane control that supports this and verify it after configuration. Which control should you enable?
- During a Data Domain bring-up, a compliance officer sees hourly snapshots configured and says the immutability requirement is met. Which feature should you enable to satisfy enforced undeletability for protected data?
- During a post-deployment review, the customer adds an expansion shelf to a Data Domain system that already has encryption at rest enabled. They ask whether the new shelf’s disks must be encrypted separately before backup data can use them. What should you tell them?
- A Data Domain system uses a local key manager for encryption. The only escrow copy of the master key is on one administrator's laptop. Before relying on this configuration, what should be addressed?
- An auditor asks for proof that encryption and retention lock are active on a newly deployed Dell PowerProtect Data Domain system. You must provide an audit artifact that shows the system’s own reported state, including lock expiry behavior. Which artifact should you provide?
- A quarterly vulnerability review requires a Data Domain appliance to move to the latest DD OS, but the application team objects because production backup jobs are running. Which approach best balances security maintenance and operational stability?
- A Data Domain appliance is being decommissioned because it reached end of life. A reseller offers to buy it “as is, for parts.” Local data-retention policy requires proof that all customer data is unrecoverable before custody leaves the site. What should you do first?
- During post-deployment, a backup application wizard lists storage options for a new Data Domain system. Which option registers the appliance so DD Boost and the optimized backup path become available?
- During post-deployment, two backup applications share one Data Domain system. The administrator creates one large storage unit pointing to a single Data Domain path, then maps both applications to it. After one application enables retention lock, capacity usage and lifecycle reporting become difficult to separate. Which storage-unit design should be used?
- After deploying a Data Domain system, you configure backup-software optimized-path integration. Registration prompts ask which transfer host will own each stream. What should you do to realize the appliance’s parallel throughput?
- A greenfield protection suite deployment needs a newly deployed Data Domain system as its target store. Which configuration makes the appliance available to the suite as a backup destination?
- A DBA configures Oracle RMAN to back up to a PowerProtect Data Domain system. The first test writes a flat backup file to an NFS mount instead of using the appliance's optimized path. What should the RMAN channel use for supported database integration?
- An existing backup platform writes to Data Domain over NFS and CIFS. During post-deployment, you add a second backup application that supports Data Domain native store integration on the same appliance. What should you expect from the new application’s write path?
- A team schedules filer backups through a backup application, but no NDMP client or target-device relationship is configured on the application side. When the job runs, the Data Domain appliance remains unused. Which configuration is required to make the filer-to-appliance backup work?
- A Data Domain VTL is presented to a media server, and the OS sees the tape drives. Backup jobs fail because the application shows no library. What must be completed on the application side?
- An archive platform integrates with a Data Domain object target, and each consuming team receives its own bucket. When configuring the backup software's object target for these teams, how should buckets and access keys be handled?
- A shared Data Domain receives backup data from Finance, HR, and Sales. Finance asks which department consumed the most appliance capacity this month. Which design decision must already exist for per-department capacity reporting to be meaningful?
- During a post-deployment review, you discover that the Data Domain DD OS was upgraded to a newer maintenance release, while the backup application’s Data Domain plugin is still two years old. What should you do before declaring the backup integration supported?
- After deploying a faster PowerProtect Data Domain system, a customer still misses the nightly backup window for a large SQL client. The appliance shows headroom, but backup jobs run slowly. Which configuration change should you validate first in the backup software?
- During a quarterly security review, you learn that the backup application’s service identity used to connect to a Data Domain system is subject to password expiry. What should you do to prevent an expired credential from interrupting the next backup window?
- After enabling Data Domain at-rest encryption, a backup application team asks what changes they must make to their backup configuration so data remains encrypted. What should you tell them?
- During a post-deployment review, a backup application keeps application-consistent copies for 7 years, a Data Domain snapshot schedule expires snapshots after 14 days, and retention lock is set to 1 year. Which statement best describes the effective protection for a file?
- During handover for a new PowerProtect Data Domain system, several backup applications report successful backup jobs. What must be completed for each application before the backup-software configuration is considered done?
- After deployment, a new engineer must support three backup stacks sharing one Data Domain system. There is no existing documentation showing which application uses which connection path, MTree, schedule, or owner. Which runbook deliverable best supports ongoing operations?
- During a quarterly review, a fourth backup application asks to join a running Data Domain appliance. Which action sequence should the engineer follow before enabling the new client?
- After deployment, a backup application job fails. Data Domain hardware and core services report healthy, and alerts show no storage or network faults. What should you verify next before changing appliance configuration?
- During post-deployment testing, a backup admin notices the DR Data Domain replica has idle network bandwidth and redirects two nightly backup streams to it instead of the primary appliance. After verifying replication status, what should you require before returning the system to production?
- An application team defines three Data Domain client groups with RPOs of one hour, four hours, and twenty-four hours. During post-deployment policy work, you need to align snapshot schedules to those requirements. What should you configure?
- After a Data Domain bring-up, an hourly snapshot schedule is enabled, but a request for a file from four weeks ago cannot be restored. What policy change should be made to prevent this?
- A compliance rule requires seven years of monthly copies, but the oldest copies are almost never restored. After several years, primary capacity is filling up. Which Data Domain policy should be applied so long retention stops consuming primary space?
- A deployment engineer creates a data-tiering policy on a PowerProtect Data Domain system, but the cloud/object-store destination was never configured or licensed. What must happen before the policy can be applied?
- You're configuring two Data Domain replication pairs: one over low-latency metro fiber with a near-zero RPO, and one over a congested branch link with an hours-long RPO. Which policy best matches each link and recovery goal?
- After deploying a Data Domain system, replication policies are scheduled from 01:00 to 05:00 every night. The customer's backup jobs also run from 01:00 to 05:00, and the replication queue keeps growing instead of draining. What should you do?
- Legal requires immutable backup retention only for the financial share on a Data Domain system. Ops suggests locking the whole appliance to simplify enforcement. Which policy placement meets the requirement while preserving normal operations?
- A new tenant is onboarded on a Data Domain system with Secure Multi-Tenancy enabled. The engineer must ensure all of that tenant’s backup data, quotas, and administrative scope remain isolated inside the tenant context. What should the engineer do?
- A customer says retention, tiering and cleanup for each client are configured on separate screens, so no one can state the current policy. For maintainable Data Domain operations, which approach should be applied?
- During a customer's largest restore test, a Data Domain system becomes sluggish because expiration deletions are running. You must prove the retention policy will avoid this during future tests. What should you verify?
- During a PowerProtect Data Domain deployment review, the DR site storage bill has doubled because the replica retains every replicated backup for the same seven years as production. The customer needs a DR copy for recovery testing and short-term recovery, not a long-term archive. Which policy change should you recommend?
- During a post-deployment audit, the customer’s auditor asks for proof that the Data Domain protection policy is actually running, not just configured. Which evidence best demonstrates that the policy is operating?
- During a post-deployment review of a Data Domain system, you find that a policy expiry was shortened months ago and never restored. No one can identify who approved it. Which control should have prevented this?
- During a cyber-recovery drill, the disconnected Data Domain copy is stale. You need to bring it current and restore protection without weakening the air-gap posture. What should the procedure require?
- A customer receives a litigation notice covering only Project Alpha backups on a Data Domain system. You must keep those backups beyond every existing schedule while leaving other projects on normal rules. Which action meets this requirement?
- A hosting admin wants tenant admins to change their own snapshot schedules without opening tickets, while preserving isolation. What should be configured?
- During post-deployment validation, you apply backup retention and replication policies. One week later, the application owner reports that snapshots were silently missed for several days. No storage-team alert was generated. What should the applied policies have included?
- During a post-deployment review, two engineers disagree about what the nightly policy actually does for the finance-db MTree: one cites a snapshot schedule, the other cites replication. Before changing anything, which authoritative source should you consult?
- A regulated customer updates its backup retention rule from 90 days to 7 years. The Data Domain system’s current MTree retention settings were configured months ago and no longer match the business policy. What is the proper way to keep protection settings truthful to the new rule?
- During an emergency space shortage, an administrator manually deletes an MTree outside the approved policy to free capacity immediately. What should have happened instead?
These questions are original practice material and are NOT actual exam questions or brain-dump content. All vendor marks are trademarks of their respective owners. This site is not affiliated with, endorsed by, or sponsored by Dell Technologies Inc..