Courseiva
easyMultiple Choice

300-410 Practice Question: Runs the following command to verify Flexible…

A network engineer runs the following command to verify Flexible NetFlow record configuration:

R1# show flow record FLOW-RECORD-1

flow record FLOW-RECORD-1 match ipv4 source address match ipv4 destination address match ip protocol collect counter bytes collect counter packets collect timestamp sys-uptime first collect timestamp sys-uptime last

What does this output indicate?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The record matches on source and destination IP addresses and protocol, and collects byte/packet counters and timestamps.

The output shows the definition of a Flexible NetFlow record. It matches on source IP, destination IP, and protocol, and collects byte and packet counters along with timestamps for the first and last packet of the flow.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The record collects only packet counts, not byte counts.

    Why it's wrong here

    Both collect counter bytes and collect counter packets appear in the output, so byte counts are gathered alongside packet counts. A record collecting only packets would omit the bytes line, which is the configuration used when byte volume is irrelevant.

  • ✓

    The record matches on source and destination IP addresses and protocol, and collects byte/packet counters and timestamps.

    Why this is correct

    The record's match fields define the flow key from IPv4 source, destination and protocol, while collect statements gather byte and packet counters plus first and last sys-uptime timestamps. This combination determines what traffic is tracked and which statistics are exported.

  • ✗

    The record does not include any timestamp information.

    Why it's wrong here

    The output explicitly lists collect timestamp sys-uptime first and last, so timestamp data is present. The absence of a timestamp match would be the case only if the record omitted those collect statements, which is what the option wrongly claims here.

  • ✗

    The record matches on TCP flags.

    Why it's wrong here

    No match statement references TCP flags; the record matches only IPv4 source, destination and protocol. TCP flags would appear as match ipv4 protocol tcp flags, which is the correct choice when filtering flows by flag values such as SYN or ACK.

About these practice questions

One of 1,401 original 300-410 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.