exam questions

Exam 350-501 All Questions

View all questions & answers for the 350-501 exam

Exam 350-501 topic 1 question 11 discussion

Actual exam question from Cisco's 350-501
Question #: 11
Topic #: 1
[All 350-501 Questions]


Refer to the exhibits. Which information is provided for traceback analysis when this configuration is applied?

  • A. source interface
  • B. packet size distribution
  • C. IP sub flow cache
  • D. BGP version
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
KNOPPER
Highly Voted 4 years, 6 months ago
I think it would be A, i believe this is referring to the netflow template format which has a field for source interface. Not to be confused with the output from "show ip cache flow" on a device.
upvoted 7 times
EdgardoAC
4 years, 6 months ago
I found this link to be helpful, based on the information it would seem C is correct. https://www.cisco.com/c/en/us/products/collateral/ios-nx-os-software/ios-netflow/prod_white_paper0900aecd80406232.html
upvoted 4 times
...
...
rans3001
Highly Voted 3 years, 9 months ago
So I would suppose that "information provided for traceback analysis" means netflow export data, not the output of the "show ip cache flow" (wich is a traceback analysis of the raw netflow data that the router itself generates). Is this right ? Packet size distribution and IP sub flow cache are visible in the show ip cache flow output, generated by the router, based on netflow data and they should not be part of the netflow export data. BGP version is not used in netflow export, but source interface it is. I would go with answer A
upvoted 5 times
chst
3 years, 1 month ago
I'ts A https://www.cisco.com/en/US/technologies/tk648/tk362/technologies_white_paper09186a00800a3db9.html
upvoted 1 times
...
...
Landawap
Most Recent 7 months ago
Selected Answer: A
The IP sub flow cache is a feature in Cisco IOS that allows you to store additional information about IP flows. The IP sub flow cache is a separate cache from the main NetFlow cache. This means that the IP sub flow cache can store information about flows that are not being exported using NetFlow. The IP sub flow cache can be enabled on a per-interface basis. To enable the IP sub flow cache on an interface, you can use the following command: ip flow-cache sub on
upvoted 1 times
...
karen1337
7 months ago
Selected Answer: A
I'm voting for A based on this paragraph from Cisco. It specifically talks about tracing the source of an attack and using NetFlow to know the source interface. Keywords are in all caps. "The originator of DoS attacks cannot be easily identified because the IP source address of the device sending the traffic is usually forged. However, you can easily TRACE the traffic BACK through the network to the router on which it is arriving by using the NetFlow Layer 2 and Security Monitoring Exports feature to capture the MAC address and VLAN-ID fields. If the router on which traffic is arriving supports NetFlow, you can configure the NetFlow Layer 2 and Security Monitoring Exports feature on it to identify the INTERFACE on which the traffic is ARRIVING." https://www.cisco.com/en/US/docs/ios-xml/ios/netflow/configuration/15-2s/nf-detct-analy-thrts.html
upvoted 2 times
...
ariasse
1 year, 2 months ago
Selected Answer: C
The whole purpose of Netflow is to provide information about data flows, so correct answer would be “C”. The other answers have no sense.
upvoted 1 times
...
Mubdir
1 year, 4 months ago
Selected Answer: A
A is the correct answer
upvoted 1 times
...
ces123ces
2 years, 6 months ago
The "ip route-cache flow" can be used only under the main interface, while the "ip flow ingress" was an enhancement to be used under subinterfaces.
upvoted 1 times
...
lasalsa
3 years, 8 months ago
Based on the following link https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/netflow/configuration/15-mt/nf-15-mt-book/get-start-cfg-nflow.html. I would the answer should be C
upvoted 2 times
...
THU
4 years, 5 months ago
I think it C is correct because of A,B,D are not applicable for the question.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago