Limited-Time Offer: Enjoy 50% Savings! Ends in 00h 00m 00s Coupon code: 50OFF
Skip to content

Free Pure Storage Pure Certified FlashArray Storage Professional FlashArray-Storage-Professional Exam Questions

Page: 1 / 8 Total 75 questions

Want more questions? Get Premium Access.

Question 1

An administrator is setting up FA File using the FlashArray GUI. The company is an NFS only shop and needs to configure their remote user authentication.

Which of the following GUI locations should the administrator use to configure access?

Correct Answer: B. Settings > Access > Directory Services
Explanation:

For FlashArray File Services (FA File), user authentication and mapping depend on the storage protocol being used. In an NFS-only environment, remote user authentication (resolving UNIX UIDs and GIDs to actual usernames and managing access) is typically handled via LDAP or NIS.

To configure this integration in the Purity GUI, the storage administrator must navigate to Settings > Access > Directory Services. This specific section allows the FlashArray to connect to a centralized directory server (such as OpenLDAP or even Active Directory providing LDAP services) to pull the necessary UNIX user and group attributes required for NFS file permissions to function properly.

Here is why the other options are incorrect:

Settings > Access > Create Active Directory Account (A): This specific menu path is used strictly for configuring native Active Directory (AD) computer accounts and joining the domain to support the SMB (Server Message Block) protocol. Since the scenario explicitly states the company is an 'NFS only shop,' configuring an SMB AD account is not the correct step.

Settings > Access > File System (C): While you manage file-level exports and policies within the Purity file interface, the global configuration for remote user authentication and directory server integration lives under the dedicated Directory Services pane.


Question 2

An application engineer reports seeing high latency in their application running in a VMware instance.

What is the best method to determine the source of the latency?

Correct Answer: A. Analyze performance in the VM Topology in Pure1 for each component in the user's data path
Explanation:

Within the Pure Storage ecosystem, the absolute best method to troubleshoot and pinpoint the exact source of VMware latency is to use VM Analytics (VM Topology) in Pure1.

VM Analytics is a feature built directly into Pure1 that maps the entire data path from the virtual machine all the way down to the physical FlashArray. It provides a visual topology map detailing the VM, Virtual Disk, ESXi Host, Datastore, and FlashArray Volume. By analyzing performance across this topology, an administrator can instantly identify exactly where the latency is being introduced. For example, you can clearly see if the latency spikes at the ESXi host layer (indicating compute contention) or the network layer, even if the FlashArray volume itself is reporting sub-millisecond latency at the storage level.

Here is why the other options are incorrect:

Analyze load metrics in Pure1 for each volume in the user's data path (C): Looking exclusively at volume-level metrics on the FlashArray will only tell you the latency from the array's perspective. If the latency is being caused by an overloaded ESXi host CPU or a saturated SAN fabric, the FlashArray metrics will look perfectly healthy, and you will fail to identify the source of the problem.

Analyze performance charts in vSphere for CPU, Memory, Network, and Storage Path for the user's data path (B): While vCenter performance charts are useful, they often lack deep storage-array-level context. Pure1's VM Topology is the 'best' method because it correlates the vSphere stack data with the native FlashArray telemetry data in a single, unified view, making full-stack root cause analysis much faster.


Question 3

An administrator is running commands to verify NVME/TCP connectivity from the hosts to the FlashArray. They use the command ping -M do -s 8972 from the initiator and it fails.

What should the administrator do to resolve the issue?

Correct Answer: B. Check the MTU of 9000 is set on each hop to the FA.
Explanation:

When configuring NVMe/TCP (or iSCSI) for optimal performance on a Pure Storage FlashArray, configuring Jumbo Frames (an MTU of 9000) end-to-end is a standard best practice.

The command ping -M do -s 8972 <ip_addr> is specifically used to verify Jumbo Frame configuration across the network.

The -M do flag sets the 'Do Not Fragment' (DF) bit, meaning the network is not allowed to break the packet into smaller pieces.

The -s 8972 flag sets the ICMP data payload to 8972 bytes. When you add the standard 8-byte ICMP header and the 20-byte IP header, the total packet size equals exactly 9000 bytes.

If this ping command fails, it indicates that somewhere along the network path between the host (initiator) and the FlashArray (target), a switch port, router, or network interface is not configured to support an MTU of 9000. The packet is being dropped because it is too large and cannot be fragmented. The administrator must verify the MTU settings on every network hop (switches, routers, and host NICs) to resolve the issue.

Here is why the other options are incorrect:

Engage support to enable NVME/ TCP services (A): The failure of a Jumbo Frame ping test is a Layer 2/Layer 3 network configuration issue, not an indicator that the NVMe/TCP storage protocol service is disabled on the array.

Run the command from the target (C): While pinging from the FlashArray back to the host is a valid secondary troubleshooting step, it will likely also fail if the network path doesn't support Jumbo Frames. The actual resolution is to fix the MTU on the network hops.


Question 4

An engineer is tasked by the IT security team to pull audit trail logs from the last month. The engineer navigates to the audit trail section of the FlashArray GUI, but sees the audit trail only contains a maximum of 1000 records.

What step should the engineer take?

Correct Answer: B. Log in to Pure1 to access historical audit trail items.
Explanation:

Local Array Limitations: The FlashArray GUI and CLI maintain a local buffer for audit logs (which track commands, logins, and configuration changes). However, this local storage is limited in size and record count (typically around 1000 records or a short timeframe) to ensure that logging does not consume excessive system resources on the controllers. Once the limit is reached, older records are overwritten (FIFO - First In, First Out).

Pure1 as the Historical Repository: Pure1 is Pure Storage's cloud-based management and monitoring platform. One of its primary functions is to act as a long-term repository for array data. FlashArrays 'phone home' their audit logs to Pure1, where they are indexed and stored for much longer periods (typically up to one year or more, depending on the subscription level).

Auditing in Pure1: By logging into the Pure1 portal, an administrator can navigate to the Audits section. Unlike the local GUI, Pure1 allows users to filter by specific date ranges, specific arrays, and specific users across the entire fleet. This makes it the standard tool for security audits and compliance reporting.

Why Option A and C are incorrect: * Option A: While the CLI is powerful, it still pulls from the same limited local buffer as the GUI. If the record has been overwritten locally, the CLI cannot retrieve it.

Option C: Purity does not typically allow customers to modify 'tunables' to increase log storage, as this could impact the stability or performance of the Purity Operating Environment.


Question 5

If an NFS client can mount the FA File export shares with the IP address, but not the fully qualified domain name, what is most likely causing the issue?

Correct Answer: B. Issue with the DNS
Explanation:

When an NFS client successfully mounts an export using the target's IP address, it proves that the fundamental network connectivity (routing, firewalls) and the storage protocol layer (NFS export policies, host access permissions) are functioning correctly.

However, if the exact same mount attempt fails when using the Fully Qualified Domain Name (FQDN) of the FlashArray file service, the issue lies entirely with name resolution. The Domain Name System (DNS) is responsible for translating human-readable FQDNs into the IP addresses required for network communication. If the client cannot reach the DNS server, or if the DNS server lacks the correct A or AAAA records for the FlashArray's file Virtual IP (VIP) addresses, the client won't be able to resolve the name to the IP, causing the mount command to fail.

Here is why the other options are incorrect:

Issue with the Active Directory (AD) controller (A): Active Directory is primarily used for directory services, user authentication, and authorization (such as mapping permissions for SMB or NFSv4). While AD environments usually include DNS, an 'AD controller issue' in the context of storage protocols usually points to permission denials, not host name resolution failures. Furthermore, since the mount works via IP, basic access is already validated.

Issue with the OpenLDAP (C): Similar to AD, OpenLDAP provides directory services for user mappings (UID/GID) and authentication. It does not perform FQDN-to-IP resolution.


Question 6

A storage administrator has presented VMFS datastores from a FlashArray with 10TB of raw capacity.

Why would the administrator see system space when logging in to the FlashArray GUI?

Correct Answer: B. There is more than 2TB of reclaimable space on the FlashArray.
Explanation:

On a Pure Storage FlashArray, 'System Space' is a specific GUI-reported metric. Purity has a predefined, hidden internal space budget---typically around 20% of the raw mapped capacity (which would be 2TB on a 10TB array)---reserved for internal array operations. This budget covers RAID/parity overhead, metadata, and reclaimable space (data from deleted volumes, snapshots, or overwritten blocks that are waiting for the backend garbage collection process to fully erase them from the flash chips).

Normally, this internal overhead stays below the 20% budget, and 'System Space' displays as 0.00 in the GUI. However, if an administrator deletes a massive amount of data at once, causing the reclaimable space to exceed that 2TB budget, the overflow is prominently displayed in the GUI as 'System Space.'

Here is why the other options are incorrect:

Virtual machines have not yet issued an unmap command (A): If a VMware VM deletes a file but the OS hasn't issued an UNMAP/TRIM command, the FlashArray is completely unaware that the data was deleted. Therefore, the array continues to report that capacity as standard Volume Space, not System Space.

More than 2TB of volume snapshots were destroyed (C): While destroying snapshots leads to reclaimable space, 'reclaimable space' (Option B) is the specific, correct Purity architectural term and metric that the system uses to calculate the internal budget threshold.


Question 7

A customer with an X50R2 array connected to 110V power is due for an upgrade to the latest controller generation.

What is required to allow this upgrade to proceed?

Correct Answer: C. Switch the array to 220v power outlets.
Explanation:

As Pure Storage has iterated through FlashArray generations (moving from //X R2 to R3, R4, and beyond), the power density and performance capabilities of the controllers have increased significantly. Modern high-performance controllers, such as those found in the //X R4 or //XL series, have strict power requirements that often exceed what a standard 110V/120V (Low-Line) circuit can provide.

To support the higher wattage and current draw of modern CPUs and NVRAM modules, Pure Storage requires 200-240V (High-Line) power for its latest generation controllers. If an existing array is currently running on 110V power, it must be migrated to 220V power outlets before the upgrade can proceed. Attempting to run newer, high-spec controllers on 110V power could lead to power supply instability, insufficient cooling performance, or the controllers failing to boot entirely.

Here is why the other options are incorrect:

Call support to schedule a power supply replacement (A): The issue is not a faulty power supply; it is the external electrical infrastructure's inability to provide the necessary voltage/wattage for the new hardware. Replacing the power supply with the same model would not solve the voltage limitation.

Transition the array to DC power (B): While Pure Storage does offer DC power options for specific telco environments, this is not a standard requirement for a typical controller upgrade. Moving to standard high-line AC power (220V) is the standard prerequisite for data center environments.


Question 8

An administrator needs to enable Remote Assist (RA) on Purity version 6.8.4 to facilitate remote troubleshooting. Due to security restrictions, only certain commands can be executed on the array.

What type of access should the administrator grant when enabling RA?

Correct Answer: C. Restricted
Explanation:

Remote Assist (RA) Overview: Remote Assist is a secure, customer-initiated tunnel that allows Pure Storage Technical Support Engineers (TSEs) to log into a FlashArray to perform diagnostics and maintenance. It is disabled by default and must be explicitly opened by the customer.

Access Modes in Purity: In modern Purity versions (like 6.8.4), Pure Storage has introduced granular access controls for these support sessions to satisfy enterprise security and compliance requirements (such as SOC2 or HIPAA).

Restricted Access: This mode is specifically designed for high-security environments. When RA is enabled with the Restricted flag, the Support Engineer is limited to a pre-defined subset of non-destructive, read-only, or diagnostic commands. They cannot perform major configuration changes, delete data, or access sensitive metadata without further authorization.

Elevated vs. Secured: * Elevated access (often used during emergency recovery) provides the TSE with broader permissions, including the ability to run system-level scripts and configuration commands that go beyond standard diagnostics.

Secured is often a baseline state but does not imply the specific command-level filtering that 'Restricted' does.

Security Best Practice: If a security team mandates that 'only certain commands can be executed,' Restricted is the correct administrative choice. This ensures that the principle of least privilege is applied even to the vendor's support staff.


Question 9

Where can a snapshot be copied out to?

Correct Answer: A. A new volume or existing volume
Explanation:

On a Pure Storage FlashArray, volume snapshots are immutable, read-only, point-in-time representations of your data. Because they cannot be attached directly to a host to be read or modified, you must use the Copy function to make the data usable.

The Purity operating environment allows you to copy a snapshot to two specific destinations:

A new volume: This effectively creates a clone. It provisions a brand-new, writable volume using the exact data footprint of the snapshot. This is incredibly useful for test/dev environments, offline reporting, or granular file recovery where you don't want to disrupt the original production volume.

An existing volume: This takes the data from the snapshot and completely overwrites the target volume. This is the standard procedure when you need to perform a full rollback of a corrupted volume, or when you want to quickly refresh a lower-level environment (like refreshing a QA database with yesterday's Production snapshot).

Here is why the other options are incorrect:

A new Snapshot (B & C): You cannot directly 'copy' a snapshot to create another standalone snapshot. Snapshots are uniquely generated from active volumes. If you wanted to duplicate a snapshot's exact state, you would first copy it to a volume, and then take a new snapshot of that resulting volume.


Question 10

The administrator needs to remove a volume from a ratcheted protection group.

How can this be accomplished?

Correct Answer: A. Contact Pure Storage Support to help unlock the pgroup.
Explanation:

Ratcheted Protection Groups: A 'ratcheted' protection group is a security feature used to enforce data retention and prevent the accidental or malicious removal of volumes from a protection policy. Once a protection group is ratcheted, the configuration is essentially 'locked.'

The 'Ratchet' Mechanism: When a protection group is ratcheted, Purity prevents any modifications that would decrease the level of protection. This includes preventing the removal of volumes from the group, as removing a volume would stop its scheduled snapshots and replication, thus violating the established security posture.

Security and Compliance: Because ratcheting is often used for compliance (such as SEC Rule 17a-4 or HIPAA) or as a defense against ransomware, it is designed to be difficult to reverse. Neither the standard GUI (Option C) nor the standard CLI (Option B) provides a self-service 'unlock' button for a ratcheted group.

The Recovery Path: To remove a volume or change the settings of a ratcheted protection group, a FlashArray administrator must Contact Pure Storage Support. Support engineers have specific, high-level challenge-response procedures to verify the administrator's identity and intent before performing the back-end operations required to 'un-ratchet' or modify the group.