CCNA Network Services and Security Practice Question
Exhibit: A collector is receiving traffic metadata from a router, including source IP, destination IP, protocol, and byte counts. Which feature is being used?
⚠ Common exam trap
A frequent exam trap is mistaking Syslog or SNMP traps for the feature that exports traffic metadata. Syslog messages only report system events and errors, not detailed flow data. SNMP traps notify about specific device events or threshold breaches but do not provide conversation-level traffic summaries. Another trap is confusing NTP, which only synchronizes device clocks, with traffic monitoring features. Candidates must recognize that only NetFlow exports detailed flow records including source IP, destination IP, protocol, and byte counts, which are essential for traffic analysis and capacity planning.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
NetFlow
NetFlow exports flow records that summarize traffic conversations. It does not carry full packet payloads, but it does provide useful metadata for analysis and capacity planning.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Syslog
Why it's wrong here
Syslog is a client/server protocol for transmitting event messages and system alerts, such as interface state changes, authentication failures, or configuration notifications, from network devices to a centralized log host. These messages are text-based and tagged with severity levels, but they do not contain flow statistics or packet-level per-conversation summaries. While syslog can indicate when an event occurred, it lacks the flow cache and counter information that NetFlow provides, so it cannot be the source of traffic metadata.
When this WOULD be correct
If the exam question asked about a method for collecting logging information from network devices, including system events and alerts, then Syslog would be the correct answer. For example, a question could specify that the focus is on logging network device status changes.
- ✗
SNMP trap
Why it's wrong here
SNMP traps are asynchronous notifications sent by a network agent to a management station to report an exceptional condition, like a link flapping or a high CPU threshold. Each trap is a single, discrete event message with OIDs and values, not a series of conversation records or flow data. Even though SNMP polling can retrieve interface counters, traps themselves do not carry the detailed flow-export payload; hence they are an event-alert mechanism, not a flow collector.
When this WOULD be correct
If the question were about receiving alerts regarding network device status or performance issues, such as 'What feature sends alerts when a device exceeds a certain CPU usage threshold?', then SNMP traps would be the correct answer, as they are designed for such event notifications.
- ✓
NetFlow
Why this is correct
NetFlow is a Cisco-developed traffic accounting technology that samples and aggregates IP packets into unidirectional flows, capturing key fields such as source/destination IP, ports, protocol, and byte/packet counters. The router exports these flow records to a collector over UDP, which aggregates and analyzes the data for traffic metering, capacity planning, and security analysis. Therefore, a collector receiving this data would indeed be receiving flow summaries, making NetFlow the correct answer.
- ✗
NTP
Why it's wrong here
NTP (Network Time Protocol) is designed solely to synchronize the internal clocks of networked devices with a time source, providing chronological accuracy for logs and timestamps. It operates on UDP port 123 and exchanges time-stamped packets, but it never inspects or records user traffic flows, byte counts, or conversation metadata. Because NTP's purpose is time discipline, not data-plane metering, it cannot supply the flow-based information captured on the router.
When this WOULD be correct
If the question were about the synchronization of time across network devices to ensure accurate logging and event correlation, then NTP would be the correct answer, as it plays a crucial role in maintaining time consistency in network operations.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The 200-301 exam frequently reuses these exact scenarios with slightly different constraints.
✓NetFlowCorrect answer▾
Why this is correct
NetFlow is a Cisco-developed traffic accounting technology that samples and aggregates IP packets into unidirectional flows, capturing key fields such as source/destination IP, ports, protocol, and byte/packet counters. The router exports these flow records to a collector over UDP, which aggregates and analyzes the data for traffic metering, capacity planning, and security analysis. Therefore, a collector receiving this data would indeed be receiving flow summaries, making NetFlow the correct answer.
✗SyslogWrong answer — click to see why▾
Why this is wrong here
Syslog is used for logging system events and messages, not for exporting traffic flow summaries. It does not provide the detailed per-flow metadata such as source IP, destination IP, protocol, and byte counts that NetFlow does.
★ When this WOULD be the correct answer
If the exam question asked about a method for collecting logging information from network devices, including system events and alerts, then Syslog would be the correct answer. For example, a question could specify that the focus is on logging network device status changes.
Why candidates choose this
Students might confuse Syslog with NetFlow because both involve sending data from network devices to a server. However, Syslog focuses on event logs, while NetFlow focuses on traffic flow records.
✗SNMP trapWrong answer — click to see why▾
Why this is wrong here
SNMP traps are unsolicited notifications sent by network devices to an SNMP manager to alert about events or conditions. They do not contain detailed traffic flow information like source/destination IP, protocol, and byte counts.
★ When this WOULD be the correct answer
If the question were about receiving alerts regarding network device status or performance issues, such as 'What feature sends alerts when a device exceeds a certain CPU usage threshold?', then SNMP traps would be the correct answer, as they are designed for such event notifications.
Why candidates choose this
SNMP is a common network management protocol, and traps are used for notifications. A student might think that SNMP traps can carry traffic statistics, but they are designed for event alerts, not flow data.
✗NTPWrong answer — click to see why▾
Why this is wrong here
NTP (Network Time Protocol) is used for clock synchronization between devices, not for exporting traffic metadata. It does not provide any information about network flows or traffic statistics.
★ When this WOULD be the correct answer
If the question were about the synchronization of time across network devices to ensure accurate logging and event correlation, then NTP would be the correct answer, as it plays a crucial role in maintaining time consistency in network operations.
Why candidates choose this
NTP is a well-known protocol in networking, and a student might mistakenly associate it with traffic monitoring because it is often used in conjunction with logging and monitoring systems. However, its sole purpose is time synchronization.
Analysis generated from the official 200-301blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Visual reference
Go deeper
Related to this question
Learn chapter
Diagnosing DNS Record Issues — A, AAAA, CNAME, MX, NS, and PTR Records
Key term
Router
A router is a networking device that connects different networks together and directs data traffic between them by choosing the best path for data to travel.
Key term
Packet
A packet is a small unit of data that is sent over a network, containing both the actual data and control information for delivery.
About these practice questions
This 200-301 question is part of Courseiva's 1,389-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-301 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-301 exam.