Courseiva
Network Services and SecuritymediumMultiple ChoiceObjective-mapped

CCNA Network Services and Security Practice Question

Exhibit

Requirement: report top applications and source-destination flows on WAN links

Exhibit: A network engineer wants to identify which applications are consuming most WAN bandwidth over time. Which feature should be enabled on the router?

⚠ Common exam trap

A frequent exam trap is mistaking features like DHCP snooping or DNS forwarding as tools for bandwidth monitoring. DHCP snooping is a Layer 2 security mechanism that prevents unauthorized DHCP servers but does not provide traffic usage data. DNS forwarding helps resolve domain names faster but does not track or analyze bandwidth consumption. Another trap is confusing NTP authentication, which secures time synchronization, with traffic profiling tools. Candidates must recognize that only NetFlow collects detailed flow information necessary to identify which applications consume the most WAN bandwidth over time.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

NetFlow

NetFlow records conversations and traffic characteristics so an external collector can analyze top talkers, protocols, and usage trends. Syslog and SNMP have different purposes.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • NTP authentication

    Why it's wrong here

    NTP authentication is a security mechanism that uses symmetric keys or certificates to validate the authenticity of time synchronization messages exchanged between NTP clients and servers. Its purpose is to protect the integrity of system time by preventing spoofed or malicious NTP responses, not to examine application-layer payloads or measure traffic flows. Therefore, it cannot be used to identify which applications are generating network traffic.

    When this WOULD be correct

    If the exam question asked about securing time synchronization in a network environment where accurate timekeeping is critical for logging and auditing purposes, NTP authentication would be the correct answer. For example, a scenario focusing on preventing time-based attacks would make this option valid.

  • NetFlow

    Why this is correct

    NetFlow is a flow-based telemetry technology on Cisco devices that captures packet metadata such as source and destination IP addresses, port numbers, protocol, and byte counts, aggregating them into unidirectional or bidirectional flows. By analyzing these flow records, an engineer can identify applications by matching well-known port numbers or using NBAR to classify application signatures, making it ideal for application visibility and traffic profiling.

  • DNS forwarding

    Why it's wrong here

    DNS forwarding is a configuration on a DNS server that relays client DNS queries to an upstream resolver when the server does not have the answer in its cache or zone data. This process merely facilitates domain-name-to-IP-address resolution and does not record or classify the underlying application traffic; it only handles DNS protocol messages, making it unsuitable for determining which applications are using the network.

    When this WOULD be correct

    If the exam question asked about optimizing DNS resolution times or troubleshooting DNS-related issues in a network, enabling DNS forwarding could be the correct answer, as it would help improve the efficiency of DNS queries.

  • DHCP snooping

    Why it's wrong here

    DHCP snooping is a Layer 2 security feature implemented on access switches to filter untrusted DHCP messages, building a DHCP snooping binding table that maps client MAC addresses to IP addresses, VLANs, and ports. This validation prevents DHCP starvation and rogue DHCP server attacks, but it strictly operates at Layer 2 and never inspects IP flow data or application signatures, so it provides no application identification capabilities.

    When this WOULD be correct

    If the exam question asked about securing a network against rogue DHCP servers or ensuring that only trusted DHCP responses are accepted, DHCP snooping would be the correct answer. This would focus on maintaining network integrity rather than monitoring bandwidth.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The 200-301 exam frequently reuses these exact scenarios with slightly different constraints.

NetFlowCorrect answer

Why this is correct

NetFlow is a flow-based telemetry technology on Cisco devices that captures packet metadata such as source and destination IP addresses, port numbers, protocol, and byte counts, aggregating them into unidirectional or bidirectional flows. By analyzing these flow records, an engineer can identify applications by matching well-known port numbers or using NBAR to classify application signatures, making it ideal for application visibility and traffic profiling.

NTP authenticationWrong answer — click to see why

Why this is wrong here

NTP authentication is used to secure time synchronization between devices, which does not provide any insight into application bandwidth usage on a WAN. It is unrelated to monitoring or analyzing traffic patterns.

★ When this WOULD be the correct answer

If the exam question asked about securing time synchronization in a network environment where accurate timekeeping is critical for logging and auditing purposes, NTP authentication would be the correct answer. For example, a scenario focusing on preventing time-based attacks would make this option valid.

Why candidates choose this

Candidates may confuse NTP's role in network operations, thinking that time synchronization could somehow relate to bandwidth monitoring, especially if they are not fully aware of specific features like NetFlow that directly address traffic analysis.

DNS forwardingWrong answer — click to see why

Why this is wrong here

DNS forwarding is responsible for directing DNS queries to the appropriate DNS servers and does not provide insights into WAN bandwidth consumption by applications. Therefore, it does not address the requirement of identifying application bandwidth usage.

★ When this WOULD be the correct answer

If the exam question asked about optimizing DNS resolution times or troubleshooting DNS-related issues in a network, enabling DNS forwarding could be the correct answer, as it would help improve the efficiency of DNS queries.

Why candidates choose this

Candidates may confuse DNS forwarding with network monitoring tools, mistakenly believing that it could help analyze traffic patterns, especially if they are not fully aware of the specific functions of each network feature.

DHCP snoopingWrong answer — click to see why

Why this is wrong here

DHCP snooping is a security feature that helps prevent unauthorized DHCP servers from providing IP addresses to clients. It does not provide any insights into application bandwidth usage over the WAN, making it irrelevant for identifying bandwidth consumption.

★ When this WOULD be the correct answer

If the exam question asked about securing a network against rogue DHCP servers or ensuring that only trusted DHCP responses are accepted, DHCP snooping would be the correct answer. This would focus on maintaining network integrity rather than monitoring bandwidth.

Why candidates choose this

Candidates may confuse DHCP snooping with network monitoring features due to their shared context in network management, leading them to mistakenly believe it could help in assessing bandwidth usage.

Analysis generated from the official 200-301blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

Visual reference

Client DHCP Server 1 Discover (broadcast) 2 Offer (IP: 192.168.1.10) 3 Request (I accept) 4 Acknowledge (lease confirmed) DORA — the four-step DHCP lease process

About these practice questions

This 200-301 question is part of Courseiva's 1,389-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-301 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-301 exam.