Implementing and Operating Cisco Enterprise Network Core Technologies (ENCOR) v1.2Network AssuranceEasy

A network security team requires detailed visibility into all network conversations to detect anomalous traffic patterns and potential security breaches. They need to analyze source/destination IP addresses, ports, protocols, and byte/packet counts for every flow. Which network assurance technology is best suited for this requirement?

  1. ASPAN
  2. BNetFlow
  3. CSNMP Traps
  4. DSyslog
Show answer & explanation

Correct answer: B. NetFlow

NetFlow (or IPFIX) provides detailed records of IP conversations, including source/destination IP and port, protocol, byte/packet counts, and more, making it ideal for traffic accounting, security analysis, and anomaly detection.

Why the other options are wrong

  • A. SPAN provides full packet captures, which is too granular and resource-intensive for 'all network conversations' across an entire network for security analysis; it's better for deep, localized troubleshooting.
  • C. SNMP Traps are for event-driven notifications about specific device conditions, not detailed flow data.
  • D. Syslog provides event logs from devices, useful for troubleshooting and security events, but not for detailed flow analysis.

NetFlow

A Cisco technology that provides statistics on network traffic passing through a router or switch, used for traffic accounting, security monitoring, and network planning.

  • Records IP flow metadata, not full packets.
  • Includes source/destination IP, ports, protocol, byte/packet counts.
  • Requires a NetFlow collector to store and analyze data.

Memory trick: For flows, NetFlow's the way; for events, Syslog and SNMP play; for packets, SPAN holds sway.

More Network Assurance questions