exam questions

Exam 350-701 All Questions

View all questions & answers for the 350-701 exam

Exam 350-701 topic 1 question 80 discussion

Actual exam question from Cisco's 350-701
Question #: 80
Topic #: 1
[All 350-701 Questions]

What is a characteristic of Cisco ASA NetFlow v9 Secure Event Logging?

  • A. It tracks flow-create, flow-teardown, and flow-denied events.
  • B. It provides stateless IP flow tracking that exports all records of a specific flow.
  • C. It tracks the flow continuously and provides updates every 10 seconds.
  • D. Its events match all traffic classes in parallel.
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️
Reference:
https://www.cisco.com/c/en/us/td/docs/security/asa/asa92/configuration/general/asa-general-cli/monitor-nsel.html

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
willroute
5 months, 4 weeks ago
A is correct and also there is another question that what is specific to ASA NSEL, it is the capability to delay events, as it is noisy. both are in below .https://www.cisco.com/c/en/us/td/docs/security/asa/special/netflow/asa_netflow.html#delaysending
upvoted 1 times
...
Marshpillowz
1 year, 1 month ago
Selected Answer: A
A is correct
upvoted 1 times
...
sull3y
2 years, 3 months ago
A. It tracks flow-create, flow-teardown, and flow-denied events. Cisco ASA NetFlow v9 Secure Event Logging is a feature that allows the ASA to export detailed information about network traffic flow and security events to a NetFlow collector for analysis. The exported information includes information about flow-create, flow-teardown and flow-denied events, which provide insight into the behavior of the traffic passing through the firewall. This feature also allows for the collection of detailed information about the traffic passing through the firewall which can be used for security incident investigations, capacity planning and troubleshooting. It does not provide stateless IP flow tracking that exports all records of a specific flow (B) or tracks the flow continuously and provides updates every 10 seconds (C) and also it does not match all traffic classes in parallel (D)
upvoted 3 times
...
surforlife
2 years, 10 months ago
A is correct. In stateful flow tracking, tracked flows go through a series of state changes. NSEL events are used to export data about flow status and are triggered by the event that caused the state change. The significant events that are tracked include flow-create, flow-teardown, and flow-denied (excluding those flows that are denied by EtherType ACLs). In addition, the ASA and ASASM implementation of NSEL generates periodic NSEL events, flow-update events, to provide periodic byte counters over the duration of the flow. These events are usually time-driven, which makes them more in line with traditional NetFlow; however, they may also be triggered by state changes in the flow.
upvoted 3 times
...
Cyril_the_Squirl
2 years, 10 months ago
This is Correct
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago