Key details for this exam, checked against the published exam outline
Each question shows the correct answer and an explanation of why it is right
Which two of the following export formats are supported in Hybrid Cloud Observability (HCO) reports? (Choose two.)
SolarWinds Hybrid Cloud Observability provides robust reporting capabilities designed for both technical analysis and executive presentation. The SolarWinds Platform Reporting Guide specifies that reports generated through the Web Console can be delivered or manually exported in several standardized formats.
Excel (.xls/.xlsx): This format is primarily used for data-heavy reports where administrators need to perform further calculations, sorting, or external data manipulation. It allows the raw table data from the report to be easily ingested into other business intelligence tools.
PDF: This is the standard format for automated delivery and 'executive-ready' documentation. It preserves the visual layout, including charts, logos, and specific formatting defined in the report builder.
While the platform uses JSON (Option B) for internal API communications and some dashboard configurations, and txt (Option D) might be used for certain log exports, they are not standard selectable 'export formats' within the primary Web-Based Report builder for end-user consumption. The primary focus of the reporting engine is providing human-readable (PDF) and spreadsheet-compatible (Excel) outputs.
Which two of the following settings are automatically enabled for a user with the default set of user permissions in SolarWinds' Hybrid Cloud Observability (HCO)? (Choose two.)
When a new user account is created in the SolarWinds Platform, it is assigned a set of 'Default' permissions designed to provide a 'Read-Only' baseline of visibility. According to the SolarWinds Platform User Account Management guide, the platform is configured to ensure that new users can immediately benefit from the monitoring data without having the power to accidentally modify the environment.
Specifically, view all active alerts (C) and view all existing reports (D) are enabled by default. This ensures that any team member with a login can see the current health of the infrastructure and access historical performance data. These are considered 'Passive' rights that allow for operational awareness. Conversely, disable session time out (A) is a security-sensitive setting that is typically disabled by default to prevent abandoned sessions from remaining active on public or shared workstations. Self-manage dashboards (B), while a common feature, often requires explicit 'Dashboards' or 'View' management permissions to be toggled on by an administrator to prevent a proliferation of unmanaged or redundant dashboard pages within the database. By defaulting to alert and report visibility, SolarWinds follows the principle of providing immediate information for troubleshooting while reserving management and security-override functions for designated administrators.
What is an AlertStack cluster?
AlertStack is a specialized AIOps feature within Hybrid Cloud Observability (HCO) designed to simplify incident response. According to the SolarWinds HCO Alerting documentation, an AlertStack cluster is an autogenerated grouping of related active alerts on related entities.
The primary goal of clustering is to reduce 'alert fatigue.' Instead of presenting a technician with twenty individual alerts (e.g., one for high CPU on a server, one for an application failure, and three for slow database response), AlertStack analyzes the relationships and dependencies between those entities. If the platform determines that the alerts are part of a single root-cause event---such as a storage array failure impacting multiple virtual machines and their applications---it automatically clusters them into a single visual timeline. This clustering is autogenerated by the platform's machine learning engine based on the AppStack dependency map; it does not require a user to manually group the alerts. This allows the IT team to identify the 'blast radius' of an incident and focus on the primary failure point rather than triaging dozens of symptoms individually.
Which two of the following statements apply to SolarWinds Hybrid Cloud Observability (HCO) Platform? (Choose two.)
The SolarWinds Hybrid Cloud Observability (HCO) Platform is designed for maximum deployment flexibility to accommodate diverse enterprise security and infrastructure requirements. According to the SolarWinds Platform Installation and Upgrade Guide, the platform's architecture is fundamentally self-contained.
Operation without an internet connection (A): This is a critical requirement for many government, military, and high-security financial environments. The platform is capable of 'air-gapped' operation, where all polling, data processing, and visualization occur within a private network. While features like 'Platform Connect' (for cloud-based AI) may require a connection, the core monitoring, alerting, and reporting functions remain fully operational without any external internet access.
Deployment on-premises or in the cloud (B): HCO is truly hybrid. It can be installed on physical hardware or virtual machines within a local data center, or it can be deployed within a Virtual Private Cloud (VPC) on platforms like AWS or Azure. This allows organizations to maintain their monitoring infrastructure alongside their managed assets, regardless of where those assets reside.
While HCO provides AIOps and machine learning (Option C), this is a feature of specific licensing tiers and configuration states rather than a fundamental 'platform' characteristic that defines its deployment capability in the same way its offline and hybrid nature does.
CPU utilization is being monitored on a critical Windows server and is set to notify when utilization exceeds 90%. Notification parameters are set to disregard those brief spikes over 90% and focus on sustained periods above 90%. What should be configured to accomplish the notification goal?
To prevent 'alert noise' caused by temporary performance spikes, the SolarWinds Platform allows for threshold persistence. According to the SolarWinds Platform Administrator Guide, simply setting a threshold at 90% would trigger an alert the moment a single poll returns a high value.
The correct configuration to ensure only sustained high utilization triggers an action is to set the node to change CPU status if the threshold is met for multiple polling cycles. This is found in the 'Edit Node' properties under the Thresholds section. For example, if the polling interval is 2 minutes and you set the condition to '10 minutes' (or 5 consecutive polls), the CPU status will only transition to Warning or Critical after the utilization has stayed above 90% for that entire duration. This filtering happens at the node/status level, ensuring that the alert engine only fires when there is a legitimate, sustained performance bottleneck rather than a transient spike caused by a routine background process.
75 questions covering all exam domains, starting from $20
Exam domains verified against: Official SolarWinds Observability-Self-Hosted-Fundamentals exam guide, last checked September 2026.
Understand the structural components of the SolarWinds platform and how to deploy it in your environment. Learn the network discovery capabilities that allow you to identify and add devices to your monitoring setup.
Sample question from this domain above: Q1
Manage monitored nodes and their statuses across your infrastructure. Work with agents to collect monitoring data from endpoints and maintain visibility across your environment.
Sample question from this domain above: Q2
Create dashboards and views tailored to your needs and organizational structure. Configure user accounts, permissions, custom properties, and groups to match your operational requirements.
Sample question from this domain above: Q5
Create and manage alerts that notify your team of important events, threshold breaches, and conditions requiring attention. Understand how to configure alert rules to keep your infrastructure stable.
Sample question from this domain above: Q4
Generate reports that track performance, trends, and incidents in your monitored environment. Use reporting tools to communicate infrastructure status and insights to stakeholders.
Sample question from this domain above: Q3
Use AppStack and PerfStack to visualize application dependencies and performance relationships. Employ Intelligent Mapping to understand how your infrastructure components interact and correlate.
Common questions about the exam itself