Implementing and Operating Cisco Enterprise Network Core Technologies (ENCOR) v1.2Network AssuranceEasy
A network engineer needs to monitor the network for unauthorized access attempts and security policy violations. The requirement is to collect detailed records of every IP conversation, including source/destination IP addresses, ports, protocols, and byte/packet counts, to feed into a security information and event management (SIEM) system. Which technology provides this type of data?
- ANetFlow
- BIP SLA
- CSyslog
- DSNMP
Show answer & explanationAnswer & explanation
Correct answer: A. NetFlow
NetFlow is specifically designed to collect and export IP traffic flow information. It provides detailed records of network conversations, including source/destination IPs, ports, protocols, byte, and packet counts, making it ideal for security monitoring and feeding into SIEM systems.
Why the other options are wrong
- B. IP SLA measures network performance and reliability, not detailed flow records.
- C. Syslog collects event messages and logs, not detailed flow statistics of every IP conversation.
- D. SNMP monitors device health and status, not detailed traffic flow data.
NetFlow
NetFlow is a Cisco technology that provides the ability to collect IP network traffic information as it enters or exits an interface. It offers detailed visibility into traffic patterns, usage, and performance.
- Records 'flows' which are unidirectional sequences of packets between a source and destination.
- Captures key fields like source/destination IP, port, protocol, byte/packet counts.
- Essential for network monitoring, security analysis, and capacity planning.
Memory trick: NetFlow: Know Every Traffic Flow, For Security Show.