Courseiva
hardMultiple Choice

CCNP Practice Question: Is troubleshooting a performance issue on a Cisco…

A network engineer is troubleshooting a performance issue on a Cisco Catalyst 9300 switch. The engineer suspects that a specific application is using excessive bandwidth. The switch supports Flexible NetFlow. The engineer wants to monitor only the traffic from that application without affecting the switch's CPU. What is the most efficient way to configure this?

⚠ Common exam trap

Cisco often tests the misconception that NetFlow must be enabled globally or that all flows must be exported, when in fact Flexible NetFlow allows targeted monitoring with samplers to minimize CPU impact.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Define a flow record that matches the specific application using NBAR or an ACL, and apply a flow monitor with a sampler rate to reduce CPU impact.

Flexible NetFlow allows you to define a flow record that matches specific application traffic using NBAR or an ACL, and applying a flow monitor with a sampler rate reduces the number of packets processed, minimizing CPU impact. This approach targets only the desired traffic without the overhead of monitoring all flows, making it the most efficient method for the engineer's goal.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Define a flow record that matches the specific application using NBAR or an ACL, and apply a flow monitor with a sampler rate to reduce CPU impact.

    Why this is correct

    This is correct because Flexible NetFlow permits a flow record that matches only the target application via NBAR (e.g., using an application match in a flow record) or an ACL in a flow monitor. Adding a sampler rate—for instance, sampling 1 out of every N packets—reduces the number of packets that must be inspected and cached, lowering CPU utilization and export bandwidth while still providing statistically accurate application-level visibility. This confines resource consumption to the specific traffic of interest rather than processing every flow on the switch.

  • ✗

    Enable NetFlow on all interfaces and export all flows to the collector, then filter at the collector.

    Why it's wrong here

    Enabling NetFlow on all interfaces and exporting every flow creates a flow cache entry for each unique flow, requiring CPU-intensive lookups and timer maintenance for every packet. The switch must process and export all flows, which can saturate the CPU and exacerbate the very performance problem being diagnosed. Filtering at the collector occurs after the switch has already incurred the cost of exporting all flows, so it does nothing to alleviate the switch-side resource drain.

  • ✗

    Use SNMP to poll interface counters and calculate the bandwidth used by the application.

    Why it's wrong here

    SNMP polling retrieves interface MIB counters (e.g., ifHCInOctets, ifHCOutOctets) that aggregate all traffic on an interface into a single total, providing no visibility into which application generated the traffic. It cannot distinguish between HTTP, video, or database flows, and calculating bandwidth from counter deltas yields only a coarse sum, not per-application usage. Moreover, frequent SNMP polling adds management traffic and still does not identify the application causing the issue.

  • ✗

    Configure port mirroring (SPAN) to send all traffic to an external probe for analysis.

    Why it's wrong here

    SPAN copies packets of interest to a probe, but without a granular filter—or with a broad filter—it replicates all traffic to the SPAN destination, requiring the switching engine to duplicate every frame and consume extra CPU and bandwidth. This added overhead can further degrade switch performance, and the external probe must do all the analysis, which is not a native flow-based monitoring method. It also doesn't provide flow-level statistics unless the probe reassembles and correlates, making it inefficient for ongoing application bandwidth monitoring.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.