CompTIA Network+ (N10-009)Network OperationsHard

A monitoring dashboard alerts that a core switch's CPU utilization has risen from a documented normal baseline of 10% to a sustained 85%. The administrator compares the switch's current running configuration against the stored documentation and discovers an unauthorized change to the spanning tree priority. Which network operations practice enabled the administrator to detect this discrepancy?

  1. ANetFlow traffic analysis
  2. BSNMP trap notification
  3. CConfiguration baseline comparison
  4. DSyslog severity filtering
Show answer & explanation

Correct answer: C. Configuration baseline comparison

Comparing the current device configuration against a documented baseline configuration is how administrators detect unauthorized or unintended changes over time. While SNMP, syslog, and NetFlow are monitoring tools that can indicate abnormal behavior, only baseline comparison specifically reveals a configuration deviation like an altered STP priority.

Why the other options are wrong

  • A. NetFlow analyzes traffic flow patterns, not configuration settings like STP priority.
  • B. SNMP traps report events/thresholds (e.g., high CPU) but don't compare configurations directly.
  • D. Syslog severity filtering helps prioritize log messages but doesn't inherently compare configs to a baseline.

Configuration Baseline

A documented snapshot of a device's normal, approved configuration and performance metrics, used as a reference point to detect unauthorized changes or abnormal behavior.

  • Includes both performance metrics (CPU, bandwidth) and configuration settings
  • Deviations from baseline can indicate unauthorized changes or faults
  • Complements monitoring tools like SNMP/syslog but focuses on config comparison

Memory trick: Baseline is your 'before' photo — compare it to catch what changed.

More Network Operations questions