Courseiva
Network Services and SecurityhardMultiple ChoiceObjective-mapped

CCNA Network Services and Security Practice Question

An operations team wants a monitoring platform to periodically read interface counters and CPU statistics from routers. Which technology is most closely associated with that requirement?

⚠ Common exam trap

A common exam trap is selecting Syslog or NetFlow as the answer because they are also monitoring-related technologies. Syslog is tempting because it deals with messages from devices, but it only reports events and logs rather than polling counters periodically. NetFlow is often confused with SNMP because it provides traffic visibility, but it focuses on flow data, not general device statistics like CPU or interface counters. Another trap is port security, which is unrelated to monitoring and instead controls MAC address access on switch ports. Recognizing that SNMP uniquely supports periodic polling of device metrics helps avoid these mistakes.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

SNMP

SNMP is the best fit for that requirement. In practical terms, periodic reading of counters and statistics is polling-style monitoring, which is one of the classic SNMP use cases. A management system can query devices for interface status, utilization data, and other measurable values over time. This is different from Syslog, which is event-message oriented, and from NetFlow, which focuses on traffic-flow visibility rather than general device statistics. The question is really about routine monitoring and polling.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • SNMP

    Why this is correct

    SNMP is the standard protocol for network monitoring platforms to periodically poll managed devices for operational data. It uses community strings or SNMPv3 credentials to read MIB objects such as interface counters, CPU load, and temperature, making it ideal for routine status collection and alerting on thresholds.

  • Syslog

    Why it's wrong here

    Syslog is a logging protocol that transmits event messages and error notifications generated by network devices, such as configuration changes or interface flaps. Because it is push-based and asynchronous, it lacks the polling mechanism needed for routine metric collection and therefore does not suit a periodic monitoring platform.

    When this WOULD be correct

    If the exam question asked about a method for collecting and storing log messages from network devices for troubleshooting or auditing purposes, Syslog would be the correct answer, as it excels in capturing and transmitting log data.

  • NetFlow

    Why it's wrong here

    NetFlow is designed to capture and export metadata about IP traffic flows, including source/destination addresses, ports, and protocol, to analyze network usage patterns. It does not provide general device health counters or periodic status polling, so it would be inappropriate for a monitoring platform focused on routine operational metrics.

    When this WOULD be correct

    If the question asked for a technology that analyzes traffic patterns and provides detailed flow statistics from routers, then NetFlow would be the correct answer. For example, a scenario focused on traffic analysis and bandwidth optimization would make this option valid.

  • Port security

    Why it's wrong here

    Port security is a Layer 2 switch feature that restricts which MAC addresses can access a port to prevent unauthorized LAN access. It is a security enforcement mechanism, not a monitoring protocol or framework, and provides no facility for periodic collection of device statistics or health data.

    When this WOULD be correct

    If the exam question asked about securing network access and monitoring unauthorized devices on a switch, then port security would be the correct answer. For example, a question could ask which technology helps enforce access control on switch ports to enhance network security.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The 200-301 exam frequently reuses these exact scenarios with slightly different constraints.

SNMPCorrect answer

Why this is correct

SNMP is the standard protocol for network monitoring platforms to periodically poll managed devices for operational data. It uses community strings or SNMPv3 credentials to read MIB objects such as interface counters, CPU load, and temperature, making it ideal for routine status collection and alerting on thresholds.

SyslogWrong answer — click to see why

Why this is wrong here

Syslog is primarily used for logging system messages and events, not for periodically reading interface counters or CPU statistics from routers. It does not provide the polling mechanism required for monitoring performance metrics.

★ When this WOULD be the correct answer

If the exam question asked about a method for collecting and storing log messages from network devices for troubleshooting or auditing purposes, Syslog would be the correct answer, as it excels in capturing and transmitting log data.

Why candidates choose this

Candidates may choose Syslog because they associate it with network monitoring and management, mistakenly believing it can also handle performance metrics like SNMP does, leading to confusion about its primary function.

NetFlowWrong answer — click to see why

Why this is wrong here

NetFlow is primarily used for monitoring network traffic flow and analyzing bandwidth usage rather than directly reading interface counters and CPU statistics from routers. It does not provide the polling mechanism needed for periodic data retrieval.

★ When this WOULD be the correct answer

If the question asked for a technology that analyzes traffic patterns and provides detailed flow statistics from routers, then NetFlow would be the correct answer. For example, a scenario focused on traffic analysis and bandwidth optimization would make this option valid.

Why candidates choose this

Candidates may choose NetFlow due to its association with network monitoring and performance analysis, leading them to mistakenly believe it fulfills the requirement for reading interface counters and CPU statistics.

Port securityWrong answer — click to see why

Why this is wrong here

Port security is a feature that restricts access to a switch port based on MAC addresses, primarily focused on preventing unauthorized devices from connecting to the network. It does not provide monitoring capabilities for interface counters or CPU statistics from routers.

★ When this WOULD be the correct answer

If the exam question asked about securing network access and monitoring unauthorized devices on a switch, then port security would be the correct answer. For example, a question could ask which technology helps enforce access control on switch ports to enhance network security.

Why candidates choose this

Candidates may choose this option due to a misunderstanding of network monitoring concepts, confusing port security's role in device management with monitoring capabilities. They might recall that port security is related to network devices and mistakenly associate it with monitoring functions.

Analysis generated from the official 200-301blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

This 200-301 question is part of Courseiva's 1,389-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-301 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-301 exam.