Which data source provides the most detailed information about the application layer payload in network traffic?
Full packet capture records entire packet contents, including application layer headers and payload, enabling deep inspection of protocols and data. Flow logs and metadata sources only summarise traffic, so PCAP provides the detailed payload visibility required.
Why this answer
Full packet capture (PCAP) provides the most detailed information because it records the entire raw network packet, including headers and the complete application-layer payload. This allows deep inspection of protocols like HTTP, DNS, or SMTP at the byte level, which is essential for detecting malware, data exfiltration, or application-specific anomalies.
Exam trap
Cisco often tests the misconception that NetFlow provides deep packet inspection because it can report application information via NBAR, but NBAR is a classification engine that still does not capture the raw payload; the trap is confusing flow metadata with full packet content.
How to eliminate wrong answers
Option A is wrong because NetFlow only exports metadata (e.g., IP addresses, ports, protocol, byte counts) and never includes the application payload; it summarizes flows rather than capturing full packet contents. Option B is wrong because Syslog is a logging protocol for system events and messages from devices or applications, not a network traffic capture mechanism; it cannot provide packet-level payload data. Option D is wrong because SNMP is used for monitoring and managing network device status (e.g., CPU, interface counters) via MIBs, and it does not capture or transmit network traffic payloads.