exam questions

Exam 200-310 All Questions

View all questions & answers for the 200-310 exam

Exam 200-310 topic 2 question 91 discussion

Actual exam question from Cisco's 200-310
Question #: 91
Topic #: 2
[All 200-310 Questions]

Which of the following is used by both NetFlow and NBAR to identify a traffic flow?

  • A. Network layer information
  • B. Transport layer information
  • C. Session layer information
  • D. Application layer information
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️
Section: Design Methodologies Explanation

NetFlow and NetworkBased Application Recognition (NBAR) both use Transport layer information to identify a traffic flow. NetFlow is a Cisco IOS feature that can be used to gather flow-based statistics such as packet counts, byte counts, and protocol distribution. A device configured with NetFlow examines packets for select Open Systems Interconnection (OSI) Network layer and Transport layer attributes that uniquely identify each traffic flow. The data gathered by NetFlow is typically exported to management software. You can then analyze the data to facilitate network planning, customer billing, and traffic engineering. For example,
NetFlow can be used to obtain information about the types of applications generating traffic flows through a router.
A traffic flow can be identified based on the unique combination of the following seven attributes:
✑ Source IP address
✑ Destination IP address
✑ Source port number
✑ Destination port number
✑ Protocol value
✑ Type of Service (ToS) value
✑ Input interface
Although NetFlow does not use Data Link layer information, such as a source Media Access Control (MAC) address, to identify a traffic flow, the input interface on a switch will be considered when identifying a traffic flow.
NBAR is a Quality of Service (QoS) feature that classifies application traffic that flows through a router interface. NBAR enables a router to perform deep packet inspection for all packets that pass through an NBARenabled interface. With deep packet inspection, an NBARenabled router can classify traffic based on the content of a Transmission Control Protocol (TCP) or a User Datagram Protocol (UDP) packet, instead of just the network header information. In addition, NBAR provides statistical reporting relative to each recognized application.
Reference:
Cisco: Cisco IOS Switching Services Configuration Guide, Release 12.2: Capturing Traffic Data

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
primetal
5 years, 6 months ago
As per explanation it should be transport...
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...