CCNA AI and Network Operations Practice Question
A network team deploys an AI-assisted operations platform that analyzes streaming telemetry from switches and routers. The team wants the platform to detect degradation before users report trouble. Which two data characteristics most directly improve the platform's ability to detect anomalies early? (Choose two.)
⚠ Common exam trap
The trap here is treating telemetry volume alone as sufficient, when synchronized timing and high sampling frequency are what actually make early correlation possible.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
High-frequency, model-driven telemetry pushed from devices at short intervals.
Early anomaly detection depends on data that is both frequent and time-aligned. Short-interval, model-driven telemetry supplies the granular time series needed to see subtle degradation, while synchronized timestamps let the platform correlate events across devices. Coarse polling, manual gating, and single-device collection all starve the analytics engine of the density and context it needs.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
High-frequency, model-driven telemetry pushed from devices at short intervals.
Why this is correct
Model-driven telemetry streams structured data at short intervals, giving the analytics engine a dense time series. Dense sampling exposes subtle shifts such as rising queue drops or creeping latency well before a threshold breach, which is precisely the early-warning behavior the team wants from the AI platform.
- ✓
Consistent timestamping and synchronized clocks across all monitored devices.
Why this is correct
Anomaly detection correlates events across many devices, so samples must share a reliable time base. With synchronized clocks, the platform can align a latency spike on one device with a routing change on another, distinguishing a real correlated fault from unrelated noise and enabling earlier, more confident detection.
- ✗
Polling each device every 30 minutes with SNMP for CPU and memory counters.
Why it's wrong here
Half-hour polling produces sparse samples that miss transient congestion and microbursts entirely. An anomaly that begins and resolves between polls is invisible, and the coarse granularity delays any trend detection. This cadence is suitable for capacity reporting, not for the early degradation detection the team requires.
- ✗
Storing telemetry only after manual review by a network engineer.
Why it's wrong here
Human review inserts latency and inconsistency into the data pipeline. The AI platform needs continuous, machine-ingested data to build baselines and spot deviations; gating ingestion behind manual approval means the model sees delayed, filtered samples and cannot detect degradation in real time, defeating the purpose of the deployment.
- ✗
Collecting data from a single core switch to reduce pipeline complexity.
Why it's wrong here
Restricting collection to one device removes the cross-device context that reveals correlated failures. Degradation often begins on an access or distribution device before it affects the core, so a single vantage point both misses the origin and produces misleading baselines, weakening the platform's ability to warn the team early.
Go deeper
Related to this question
About these practice questions
This 200-301 question is part of Courseiva's 1,450-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-301 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-301 exam.