Implementing and Operating Cisco Enterprise Network Core Technologies (ENCOR) v1.2Network AssuranceEasy

A network engineer needs to monitor the network for unauthorized access attempts and security policy violations. The requirement is to collect detailed records of every IP conversation, including source/destination IP addresses, ports, protocols, and byte/packet counts, to feed into a security information and event management (SIEM) system. Which technology provides this type of data?

  1. ANetFlow
  2. BIP SLA
  3. CSyslog
  4. DSNMP
Show answer & explanation

Correct answer: A. NetFlow

NetFlow is specifically designed to collect and export IP traffic flow information. It provides detailed records of network conversations, including source/destination IPs, ports, protocols, byte, and packet counts, making it ideal for security monitoring and feeding into SIEM systems.

Why the other options are wrong

  • B. IP SLA measures network performance and reliability, not detailed flow records.
  • C. Syslog collects event messages and logs, not detailed flow statistics of every IP conversation.
  • D. SNMP monitors device health and status, not detailed traffic flow data.

NetFlow

NetFlow is a Cisco technology that provides the ability to collect IP network traffic information as it enters or exits an interface. It offers detailed visibility into traffic patterns, usage, and performance.

  • Records 'flows' which are unidirectional sequences of packets between a source and destination.
  • Captures key fields like source/destination IP, port, protocol, byte/packet counts.
  • Essential for network monitoring, security analysis, and capacity planning.

Memory trick: NetFlow: Know Every Traffic Flow, For Security Show.

More Network Assurance questions