Implementing and Operating Cisco Enterprise Network Core Technologies (ENCOR) v1.2Network AssuranceEasy
A network security team requires detailed visibility into all network conversations to detect anomalous traffic patterns and potential security breaches. They need to analyze source/destination IP addresses, ports, protocols, and byte/packet counts for every flow. Which network assurance technology is best suited for this requirement?
- ASPAN
- BNetFlow
- CSNMP Traps
- DSyslog
Show answer & explanationAnswer & explanation
Correct answer: B. NetFlow
NetFlow (or IPFIX) provides detailed records of IP conversations, including source/destination IP and port, protocol, byte/packet counts, and more, making it ideal for traffic accounting, security analysis, and anomaly detection.
Why the other options are wrong
- A. SPAN provides full packet captures, which is too granular and resource-intensive for 'all network conversations' across an entire network for security analysis; it's better for deep, localized troubleshooting.
- C. SNMP Traps are for event-driven notifications about specific device conditions, not detailed flow data.
- D. Syslog provides event logs from devices, useful for troubleshooting and security events, but not for detailed flow analysis.
NetFlow
A Cisco technology that provides statistics on network traffic passing through a router or switch, used for traffic accounting, security monitoring, and network planning.
- Records IP flow metadata, not full packets.
- Includes source/destination IP, ports, protocol, byte/packet counts.
- Requires a NetFlow collector to store and analyze data.
Memory trick: For flows, NetFlow's the way; for events, Syslog and SNMP play; for packets, SPAN holds sway.