Post-Deployment
D-PDD-DY-01 · 102 questions
- In go-live week of a Data Domain deployment, three contractors and two staff engineers are all logging in with the built-in administrator account. What should change about system access?
- After go-live, the customer hands over an org chart - full-time administrators, a security auditor, and a monitoring group that only needs to see status - and asks that each group receive "just what it needs". How should system access be built?
- Day one after handover: the backup operations team wants a login of its own so it can check filesystem usage, replication status and daily health output without being able to reconfigure anything. The built-in roles each give either too much or too little for that job description. How should the engineer provide the access?
- The enterprise standard is blunt: no local passwords on infrastructure devices. The new appliance currently knows only locally created administrator accounts. The directory team already has an operations group full of the people who will manage the box. What change brings the appliance into compliance?
- A hardening review proposes disabling every locally defined account the day directory login is confirmed working, leaving directory credentials as the only way in. The engineer is asked to sign off. What makes that recommendation dangerous?
- During a security interview the auditor asks how administrator passwords on the backup appliance are controlled. The engineer's honest answer is 'we always pick strong ones'. What should the auditor have found in place instead?
- A monitoring server will run read-only health-check commands against the appliance's CLI every night. The draft automation stores a human administrator's password inside the script. What should replace that arrangement?
- A retention setting on the appliance changed at some point last week. The customer wants a name and a timestamp, and the only constant in the environment is that the operations desk shares one administrator login 'for convenience'. What makes future change history actually usable?
- Three departments will share one appliance, each with its own dedicated storage space. Each department wants its own administrators who can fully manage their space but cannot see or touch what the others hold. Which design answers that?
- At 02:00 during a restore, a nightly automation holding a stale password hammers the appliance with failed logins, and the account the on-call engineer now needs gets locked out. The outage was survivable; the surprise was not. What should have happened before go-live?
- For the second time this month, the management GUI on a shared jump host was found logged in to the appliance since morning, unattended. The customer asks what the platform itself can do about the habit. What is the right answer?
- An integration engineer has resigned. Six accounts created during deployment for various applications and integrations are still active, and nobody can say which of them anything still uses. What is the professional way to clean this up?
- The application team wants a security-related setting changed on the appliance. The engineer who performs all day-to-day administration 'already knows the password' and offers to make the change himself inside this week's window. What does that sentence reveal that should be fixed in the configuration, not in his attitude?
- The compliance team wants standing eyes on administrator activity in the appliance - logins, commands, configuration state - with zero ability to change anything. What is the correct provisioning design?
- A new operator joins the team on Monday. The team lead asks why adding one person to the backup appliance needs a change ticket to the storage group, when the equivalent for every other system in the building is handled by the directory. What should have been configured to make that question legitimate?
- During last month's outage the vendor support path was enabled, a case engineer connected, and the system was saved. Security is now asking why that path is still open today. What governing practice was missed?
- Directory integration is reported as 'configured fine': the engineer tested it once with his own elevated directory account and proposes signing off the access work. The acceptance reviewer pushes back. What is missing from the evidence?
- Six months after go-live nobody can answer two questions: which accounts hold administrative rights on the appliance, and who or what owns each service identity. Which deliverable, had it existed, would have turned that audit into a fifteen-minute diff?
- During a 3 a.m. outage it emerges that the only person who knows the local emergency administrator password is on a flight and unreachable. Which arrangement should have been made while everything was calm?
- A post-go-live access audit finds that the built-in administrative account is still logging in weekly, even though every operator has had a named account since cutover. What is the correct reading of that finding?
- At the quarterly access review the security lead asks a fair question: what has changed in appliance access since the last review? Nobody can answer. Which operating habit turns that question into a fifteen-minute exercise every quarter from now on?
- The monitoring server discovered the appliance the day it was added and shows a green status, but every chart stays empty - the manager is polling a generic device template for this host. What is missing from the integration?
- A drive failed at 03:14 and the operations team found out at the next polling cycle, close to an hour later. The customer's standard claims 'monitoring sees everything'. Why the delay, and how should a platform like this be watched?
- Week one of the new monitoring standard leaves the operations team drowning: the appliance was subscribed to 'everything', roughly sixty alert types arrive, and most have no owner or runbook. How should the subscription be fixed?
- The appliance's filesystem crept toward full for weeks. Nobody was watching a chart. The first visible sign was backup jobs failing at the business sites one gray Monday. What control was actually missing?
- The appliance's email alerting went live early, pointed at every category and every administrator's inbox. Within a month the backup team had a rule archiving all of it unread. How should mail alerting actually be configured?
- The security operations center gladly ingested the appliance into its SIEM, then reported a problem: appliance events arrive but cannot be distinguished from firewall noise, and several fail to parse entirely. What configuration thinking was skipped at the forwarding stage?
- A startup with no on-premises monitoring platform wants vendor-hosted dashboards for its brand-new appliance - nothing to install locally. The team enables the cloud monitoring option in the management interface, yet the next morning the hosted portal still shows no telemetry for the system. Which prerequisite step most likely explains the gap?
- An engineer operates fourteen Data Domain systems across four sites. Every capacity or health question requires per-system logins, and answering 'which systems are near full?' recently took most of a week. Single-system monitoring is already in place on each appliance. What should be added post-deployment to fix this?
- A capacity planner forecasts the appliance's purchase dates by tracking how many bytes the backup application writes to the system each month, yet the appliance keeps filling faster or slower than those forecasts predicted. Which monitoring change produces usable forecasts on a deduplicating appliance?
- A support case opened on the appliance stalls because the support agent's first request is a system health collection, nobody on staff knows how one is generated or delivered, and the team ends up improvising a 2 GB upload through a laptop balanced on a rack rail. What post-deployment configuration would have made attaching health data to the case routine?
- A flapping network interface generates two hundred overnight pages and buries one genuine disk-failure alert in the flood, which nobody reads until morning. What configuration thinking would have kept the meaningful event visible through the storm?
- An audit finds that the appliance's SNMPv3 monitoring user password has been pasted into three network management station configs authored by two contractors, with slightly different values in each. What is the correct remediation thinking for this monitoring credential?
- A budget review asks whether the primary backup target is two years or five years from full. The engineer quotes today's percent-used and the raw capacity numbers from this morning's dashboard. What monitoring output actually answers a lifecycle question like this?
- The DR runbook promises recovery from a replica that is never more than an hour behind, yet no metric anywhere tracks how current the replication actually is. What monitoring configuration closes that gap?
- An SNMP trap announces a failed drive in 'shelf 2', but the rack row holds four identical shelves and the technician spends forty minutes opening doors hunting for the right amber LED. Which part of configuring the monitoring workflow was skipped?
- The network management station was misconfigured for a full month and nobody noticed - the appliance kept generating events, but nothing downstream was talking back. What principle of monitoring configuration would have surfaced this problem early?
- A quarterly resilience drill deliberately induces a monitored condition and times how long it takes until a human acknowledges it. Why is repeating this drill the right practice when the alerting was already proven working once at cutover?
- The customer asks for a monthly one-page picture of the backup estate - capacity, health, and reduction - instead of a human screenshotting graphs on demand. What should the monitoring configuration provide?
- A CA-signed certificate replaced the browser warnings on the management interface at go-live, and twelve months later the warnings returned - unnoticed until the day a partial outage made the GUI the only way in. What should have been added to the post-deployment monitoring set?
- Every backup job over NFS fails all morning, and the root cause turns out to be the file service on the appliance, which stopped quietly the night before. Hardware alerting had been firing healthily all month. What does the monitoring configuration lack?
- Three weeks after go-live, the security department mandates encryption at rest on the production appliance - which is now full of live backup data. Why is this a bring-forward decision rather than a checkbox that can be flipped at any time?
- A customer's key-management standard requires that an enterprise KMIP server hold all encryption keys while the appliance keeps only encrypted data. Before the appliance can actually run under that standard, what must exist?
- The KMIP cluster goes fully dark for a scheduled two-hour maintenance window on Friday night, while an appliance under external key management is mid-stream carrying live backup traffic. What is the realistic expectation for those two hours?
- An annual key rotation policy now applies to the encrypted backup stores, and the DBA objects that rotation means weeks of rewriting petabytes of backup data. What is the accurate answer about key rotation on these systems?
- The sole administrator plans to rotate the encryption keys alone at midnight 'to avoid disruption'. An auditor flags the plan. Which platform security capability is being missed, and what does configuring it correctly involve?
- A decommissioned expansion shelf is leaving the building for a vendor warranty return, and legal wants assurance that no recoverable customer data leaves custody. What is the sanctioned fast path for that assurance?
- A regulator requires proof that backup copies cannot be deleted until each copy's retention period expires - explicitly including deletions attempted by internal administrators. Which platform mechanism matches that wording?
- Two departments both request 'immutability' for their backup copies: one answers to an external regulator, the other just wants junior admins unable to delete last month's restore points. How should the platform's retention lock options be applied?
- Six months after go-live, legal revises a retention rule, and ops proposes to 'just flip the setting' on retention-locked stores whose data was locked under the old terms. What governing constraint must the conversation respect?
- A penetration test reports that the appliance's management web service still negotiates an obsolete TLS version with any client that asks for it. What is the correct hardening response for the management services?
- At go-live the appliance still has five protocols enabled from months of compatibility testing, while the approved design calls for only three. What is the right post-deployment action on the unused services?
- During a post-deployment review, an auditor asks what technically prevents a tenant A administrator from reading tenant B data on a shared Data Domain system. What must be configured to enforce that separation?
- During post-deployment, a customer's network team asks whether Data Domain-to-Data Domain replication across a WAN link needs a site-to-site VPN solely to protect replication payload confidentiality. What should you recommend?
- During a ransomware playbook review, an attacker is assumed to have every Data Domain admin credential. Which protection pattern is most defensible?
- During post-deployment hardening, Security requires CLI management for a zero-standing-privilege shop: no administrator should need to know or share a standing Data Domain password. You must choose an access-plane control that supports this and verify it after configuration. Which control should you enable?
- During a Data Domain bring-up, a compliance officer sees hourly snapshots configured and says the immutability requirement is met. Which feature should you enable to satisfy enforced undeletability for protected data?
- During a post-deployment review, the customer adds an expansion shelf to a Data Domain system that already has encryption at rest enabled. They ask whether the new shelf’s disks must be encrypted separately before backup data can use them. What should you tell them?
- A Data Domain system uses a local key manager for encryption. The only escrow copy of the master key is on one administrator's laptop. Before relying on this configuration, what should be addressed?
- An auditor asks for proof that encryption and retention lock are active on a newly deployed Dell PowerProtect Data Domain system. You must provide an audit artifact that shows the system’s own reported state, including lock expiry behavior. Which artifact should you provide?
- A quarterly vulnerability review requires a Data Domain appliance to move to the latest DD OS, but the application team objects because production backup jobs are running. Which approach best balances security maintenance and operational stability?
- A Data Domain appliance is being decommissioned because it reached end of life. A reseller offers to buy it “as is, for parts.” Local data-retention policy requires proof that all customer data is unrecoverable before custody leaves the site. What should you do first?
- During post-deployment, a backup application wizard lists storage options for a new Data Domain system. Which option registers the appliance so DD Boost and the optimized backup path become available?
- During post-deployment, two backup applications share one Data Domain system. The administrator creates one large storage unit pointing to a single Data Domain path, then maps both applications to it. After one application enables retention lock, capacity usage and lifecycle reporting become difficult to separate. Which storage-unit design should be used?
- After deploying a Data Domain system, you configure backup-software optimized-path integration. Registration prompts ask which transfer host will own each stream. What should you do to realize the appliance’s parallel throughput?
- A greenfield protection suite deployment needs a newly deployed Data Domain system as its target store. Which configuration makes the appliance available to the suite as a backup destination?
- A DBA configures Oracle RMAN to back up to a PowerProtect Data Domain system. The first test writes a flat backup file to an NFS mount instead of using the appliance's optimized path. What should the RMAN channel use for supported database integration?
- An existing backup platform writes to Data Domain over NFS and CIFS. During post-deployment, you add a second backup application that supports Data Domain native store integration on the same appliance. What should you expect from the new application’s write path?
- A team schedules filer backups through a backup application, but no NDMP client or target-device relationship is configured on the application side. When the job runs, the Data Domain appliance remains unused. Which configuration is required to make the filer-to-appliance backup work?
- A Data Domain VTL is presented to a media server, and the OS sees the tape drives. Backup jobs fail because the application shows no library. What must be completed on the application side?
- An archive platform integrates with a Data Domain object target, and each consuming team receives its own bucket. When configuring the backup software's object target for these teams, how should buckets and access keys be handled?
- A shared Data Domain receives backup data from Finance, HR, and Sales. Finance asks which department consumed the most appliance capacity this month. Which design decision must already exist for per-department capacity reporting to be meaningful?
- During a post-deployment review, you discover that the Data Domain DD OS was upgraded to a newer maintenance release, while the backup application’s Data Domain plugin is still two years old. What should you do before declaring the backup integration supported?
- After deploying a faster PowerProtect Data Domain system, a customer still misses the nightly backup window for a large SQL client. The appliance shows headroom, but backup jobs run slowly. Which configuration change should you validate first in the backup software?
- During a quarterly security review, you learn that the backup application’s service identity used to connect to a Data Domain system is subject to password expiry. What should you do to prevent an expired credential from interrupting the next backup window?
- After enabling Data Domain at-rest encryption, a backup application team asks what changes they must make to their backup configuration so data remains encrypted. What should you tell them?
- During a post-deployment review, a backup application keeps application-consistent copies for 7 years, a Data Domain snapshot schedule expires snapshots after 14 days, and retention lock is set to 1 year. Which statement best describes the effective protection for a file?
- During handover for a new PowerProtect Data Domain system, several backup applications report successful backup jobs. What must be completed for each application before the backup-software configuration is considered done?
- After deployment, a new engineer must support three backup stacks sharing one Data Domain system. There is no existing documentation showing which application uses which connection path, MTree, schedule, or owner. Which runbook deliverable best supports ongoing operations?
- During a quarterly review, a fourth backup application asks to join a running Data Domain appliance. Which action sequence should the engineer follow before enabling the new client?
- After deployment, a backup application job fails. Data Domain hardware and core services report healthy, and alerts show no storage or network faults. What should you verify next before changing appliance configuration?
- During post-deployment testing, a backup admin notices the DR Data Domain replica has idle network bandwidth and redirects two nightly backup streams to it instead of the primary appliance. After verifying replication status, what should you require before returning the system to production?
- An application team defines three Data Domain client groups with RPOs of one hour, four hours, and twenty-four hours. During post-deployment policy work, you need to align snapshot schedules to those requirements. What should you configure?
- After a Data Domain bring-up, an hourly snapshot schedule is enabled, but a request for a file from four weeks ago cannot be restored. What policy change should be made to prevent this?
- A compliance rule requires seven years of monthly copies, but the oldest copies are almost never restored. After several years, primary capacity is filling up. Which Data Domain policy should be applied so long retention stops consuming primary space?
- A deployment engineer creates a data-tiering policy on a PowerProtect Data Domain system, but the cloud/object-store destination was never configured or licensed. What must happen before the policy can be applied?
- You're configuring two Data Domain replication pairs: one over low-latency metro fiber with a near-zero RPO, and one over a congested branch link with an hours-long RPO. Which policy best matches each link and recovery goal?
- After deploying a Data Domain system, replication policies are scheduled from 01:00 to 05:00 every night. The customer's backup jobs also run from 01:00 to 05:00, and the replication queue keeps growing instead of draining. What should you do?
- Legal requires immutable backup retention only for the financial share on a Data Domain system. Ops suggests locking the whole appliance to simplify enforcement. Which policy placement meets the requirement while preserving normal operations?
- A new tenant is onboarded on a Data Domain system with Secure Multi-Tenancy enabled. The engineer must ensure all of that tenant’s backup data, quotas, and administrative scope remain isolated inside the tenant context. What should the engineer do?
- A customer says retention, tiering and cleanup for each client are configured on separate screens, so no one can state the current policy. For maintainable Data Domain operations, which approach should be applied?
- During a customer's largest restore test, a Data Domain system becomes sluggish because expiration deletions are running. You must prove the retention policy will avoid this during future tests. What should you verify?
- During a PowerProtect Data Domain deployment review, the DR site storage bill has doubled because the replica retains every replicated backup for the same seven years as production. The customer needs a DR copy for recovery testing and short-term recovery, not a long-term archive. Which policy change should you recommend?
- During a post-deployment audit, the customer’s auditor asks for proof that the Data Domain protection policy is actually running, not just configured. Which evidence best demonstrates that the policy is operating?
- During a post-deployment review of a Data Domain system, you find that a policy expiry was shortened months ago and never restored. No one can identify who approved it. Which control should have prevented this?
- During a cyber-recovery drill, the disconnected Data Domain copy is stale. You need to bring it current and restore protection without weakening the air-gap posture. What should the procedure require?
- A customer receives a litigation notice covering only Project Alpha backups on a Data Domain system. You must keep those backups beyond every existing schedule while leaving other projects on normal rules. Which action meets this requirement?
- A hosting admin wants tenant admins to change their own snapshot schedules without opening tickets, while preserving isolation. What should be configured?
- During post-deployment validation, you apply backup retention and replication policies. One week later, the application owner reports that snapshots were silently missed for several days. No storage-team alert was generated. What should the applied policies have included?
- During a post-deployment review, two engineers disagree about what the nightly policy actually does for the finance-db MTree: one cites a snapshot schedule, the other cites replication. Before changing anything, which authoritative source should you consult?
- A regulated customer updates its backup retention rule from 90 days to 7 years. The Data Domain system’s current MTree retention settings were configured months ago and no longer match the business policy. What is the proper way to keep protection settings truthful to the new rule?
- During an emergency space shortage, an administrator manually deletes an MTree outside the approved policy to free capacity immediately. What should have happened instead?