NS0-164 Certified Data Administrator, ONTAP Practice Questions
Prepare for NS0-164 with more than an answer.
Unlock the full exam and previous versions
- v1NetApp Certified Data Administrator, ONTAP (NS0-165) 150 questions Locked
- NS0-161Legacy NetApp Certified Data Administrator, ONTAP 60 questions Locked
- NS0-164Legacy NetApp Certified Data Administrator, ONTAP 276 questions Current
- Exam fee
- $200 USD
- Level
- Professional
- Valid for
- 24 months
Domains covered on the exam 8
- Storage Platforms12%
- Core ONTAP18%
- ONTAP Storage15%
- Networking12%
- Storage Protocols and Connectivity18%
- Data Protection15%
- Security10%
- Performance10%
- 1
A system administrator is using the ONTAP CLI to troubleshoot a network issue. The administrator needs to verify end-to-end IP connectivity from a specific data LIF on a specific SVM to a client's IP address. Which command should be used?
Show answer details
Correct answer: A
The
network pingcommand is used to test reachability from a specific LIF. The syntaxnetwork ping -vserver -lif -destinationallows the administrator to specify the exact source SVM and LIF for the ping test. This is crucial for verifying connectivity for a specific network path used by clients, as opposed to pinging from a node or cluster management interface. - 2
What is the primary function of an intercluster LIF in an ONTAP environment?
Show answer details
Correct answer: C
Intercluster LIFs are specifically designed to handle traffic between different ONTAP clusters that have been peered. Their primary use case is for replication traffic, such as SnapMirror and SnapVault, allowing data to be protected across cluster boundaries. Data LIFs are for client access, and cluster management LIFs are for administration.
- 3
An organization wants to tier inactive data from its performance-sensitive AFF aggregate to a lower-cost object storage tier in the cloud. The requirement is that only data that has not been accessed for 60 days should be tiered. Which FabricPool tiering policy should be configured?
Show answer details
Correct answer: C
The 'auto' tiering policy tiers cold data blocks from the active file system to the cloud tier based on inactivity. The administrator can set the tiering minimum cooling period (e.g., 60 days) to meet the requirement. The 'snapshot-only' policy only tiers data from snapshot copies, 'all' tiers data as soon as it is written, and 'none' disables tiering.
- 4
A storage administrator is provisioning storage for a new high-performance database on an AFF A70 system. The application vendor requires block-based storage with the lowest possible host-side overhead and latency. Which protocol and logical object should be provisioned on the ONTAP system?
Show answer details
Correct answer: A
NVMe over Fabrics (such as NVMe/FC) is a protocol designed for modern flash storage that significantly reduces latency and host CPU overhead compared to traditional SAN protocols like iSCSI and Fibre Channel. The logical storage object used with the NVMe protocol is a namespace, not a LUN. For the highest performance and lowest overhead, provisioning an NVMe namespace via NVMe/FC is the optimal choice.
- 5
A two-node ONTAP cluster experiences a power failure on Node 1. The HA partner, Node 2, successfully takes over Node 1's aggregates. After power is restored to Node 1 and it boots up, what is the default behavior of the cluster regarding the aggregates owned by Node 1?
Show answer details
Correct answer: B
By default ONTAP performs automatic giveback. When the taken-over node boots and reaches the Waiting for giveback state, the takeover partner automatically returns its aggregates (root aggregate first, then the data aggregates one at a time) once the -delay-seconds period (default 600 seconds) has elapsed. Automatic giveback can be disabled with storage failover modify -node -auto-giveback false (and -auto-giveback-after-panic false for panic-triggered takeovers) if you want to investigate before giving back manually.
- 6
A financial services company is deploying a new ONTAP 9.16.1 cluster using AFF A90 systems for a high-frequency trading application. The primary requirement is to provide the lowest possible latency for NVMe/TCP clients while ensuring data is encrypted in-flight for regulatory compliance. A storage architect has been asked to recommend the optimal network encryption method that minimizes performance overhead. Which configuration should be implemented?
Show answer details
Correct answer: D
Beginning with ONTAP 9.16.1, computationally intensive IPsec operations (encryption and integrity checks) can be offloaded to supported NICs, such as the X50131A/X50131B I/O modules on the AFF A90. NetApp documents a network-throughput impact of about 5% or less compared with unencrypted traffic, so this encrypts the NVMe/TCP traffic in flight with minimal latency overhead. Software-only IPsec consumes controller CPU and adds more latency. Cluster peering encryption protects only intercluster (SnapMirror) traffic between clusters, not host traffic. SMB encryption does not apply to NVMe/TCP.
- 7
A large media production house uses a 10 PB FlexGroup volume on an ONTAP 9.16.1 cluster to store raw 8K video footage. Editors have reported inconsistent performance, with some file operations being significantly slower than others. Analysis reveals that a few constituent volumes are disproportionately busy and full, while others are underutilized. Which ONTAP 9.16.1 feature is specifically designed to automatically resolve this issue over time?
Show answer details
Correct answer: D
Beginning with ONTAP 9.16.1, advanced capacity balancing (
volume modify ... -granular-data advanced) extends the granular data functionality introduced in 9.12.1: data of very large files (larger than 10 GB), such as raw 8K video, is written across multiple FlexGroup member volumes, so large growing files no longer overload a single constituent. Adaptive QoS limits throughput, FabricPool tiers cold data, and a volume move does not redistribute data between constituents. - 8
During a security audit, an administrator discovers that the cluster and node management LIFs are accessible from the general user data network, which violates company policy. The requirement is to logically separate the management network traffic from all data and replication traffic without using physical firewalls. Which combination of ONTAP networking objects should be used to achieve this isolation? (Select TWO)
Show answer details
Correct answer: A, E
IPspaces give each network its own routing domain (separate routing tables, even overlapping addresses), and broadcast domains group the ports that belong to each Layer 2 network inside an IPspace. Cluster and node management LIFs remain in the Default IPspace, so data and replication LIFs are placed in their own IPspace(s) with their own broadcast domains, keeping management traffic logically separated without physical firewalls. Export policies, interface groups and static routes do not provide this isolation.
IPspaces give each network its own routing domain (separate routing tables, even overlapping addresses), and broadcast domains group the ports that belong to each Layer 2 network inside an IPspace. Cluster and node management LIFs remain in the Default IPspace, so data and replication LIFs are placed in their own IPspace(s) with their own broadcast domains, keeping management traffic logically separated without physical firewalls. Export policies, interface groups and static routes do not provide this isolation.
- 9
A healthcare provider needs to deploy a new electronic health record (EHR) system on an existing ONTAP cluster whose drives are standard (non-self-encrypting) drives; no new hardware can be purchased. To comply with HIPAA regulations, all patient data stored in the EHR database volumes must be encrypted at rest. The security team has mandated the use of an external, KMIP-compliant key manager that is already in use elsewhere in the organization. Which NetApp encryption technology meets these requirements?
Show answer details
Correct answer: B
NetApp Volume Encryption (NVE) is software-based, per-volume encryption at rest that works on the existing non-self-encrypting drives. It can use an external KMIP key manager, which meets the mandate to use the organization's existing KMIP server. NSE would require buying self-encrypting drives. NAE with the Onboard Key Manager does not use the external KMIP server. IPsec protects data in flight, not at rest.
- 10
An administrator is configuring a new SVM for a multi-tenant environment. The tenant requires administrative access but must be restricted to managing only their own volumes, LUNs, and export policies within their assigned SVM. What is the most appropriate ONTAP feature to delegate this limited administrative control?
Show answer details
Correct answer: D
The
vsadminrole is specifically designed for SVM-level administration. Creating a user account scoped to a particular SVM and assigning it thevsadminrole grants that user administrative privileges only within that SVM's context. They can manage resources like volumes and protocols for their SVM but cannot see or modify cluster-level settings or resources in other SVMs. This is the standard method for delegating control in a multi-tenant environment.
