NTP servers were configured on a new Data Domain hours ago, and the acceptance sheet still has a blank next to "NTP". The engineer wants to close that line honestly. What should they do?
Select an answer to reveal the explanation.
Short Explanation
Configuring NTP and proving NTP are two different verbs. You wouldn't mark a door locked because you bought a good lock, would you? Check the sync state and drift the appliance itself reports for each server, then sign the line.
Full Explanation
Time services fail quietly, so verification has to read state, not just settings. NTP is asynchronous: the configuration only declares which servers to try, while the running service tracks per-server reachability, offset, and drift, and exposes which server it actually synchronized to. Reading that status answers the acceptance question directly - the appliance is disciplined by a named, reachable source. The higher-stratum reasoning is inverted: stratum counts distance from the reference clock, so a lower number is closer to the authoritative source and a large stratum adds hop delay, making 'request the highest numbers' exactly backwards. Comparing against a laptop's clock tests nothing, because an unsynchronized laptop has no better claim to correct time than the appliance, and two agreeing wrong clocks still read wrong. A service restart proves persistence of the config, not health of the path: NTP uses UDP port 123, and a blocked port or wrong key produces silent failure that survives any number of restarts. Exam caveat: immediately after first configuration, transient offsets and a settling clock are normal; judge reachability and selection now, and drift over the following day. Operational check: the NTP status output shows a synchronized server with small offset, and appliance time is consistent with the directory services it will depend on.