easyMultiple Choice
300-410 Practice Question: Runs the following command to verify Flexible…
A network engineer runs the following command to verify Flexible NetFlow record configuration:
R1# show flow record FLOW-RECORD-1
flow record FLOW-RECORD-1 match ipv4 source address match ipv4 destination address match ip protocol collect counter bytes collect counter packets collect timestamp sys-uptime first collect timestamp sys-uptime last
What does this output indicate?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The record matches on source and destination IP addresses and protocol, and collects byte/packet counters and timestamps.
The output shows the definition of a Flexible NetFlow record. It matches on source IP, destination IP, and protocol, and collects byte and packet counters along with timestamps for the first and last packet of the flow.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The record collects only packet counts, not byte counts.
Why it's wrong here
Both collect counter bytes and collect counter packets appear in the output, so byte counts are gathered alongside packet counts. A record collecting only packets would omit the bytes line, which is the configuration used when byte volume is irrelevant.
- ✓
The record matches on source and destination IP addresses and protocol, and collects byte/packet counters and timestamps.
Why this is correct
The record's match fields define the flow key from IPv4 source, destination and protocol, while collect statements gather byte and packet counters plus first and last sys-uptime timestamps. This combination determines what traffic is tracked and which statistics are exported.
- ✗
The record does not include any timestamp information.
Why it's wrong here
The output explicitly lists collect timestamp sys-uptime first and last, so timestamp data is present. The absence of a timestamp match would be the case only if the record omitted those collect statements, which is what the option wrongly claims here.
- ✗
The record matches on TCP flags.
Why it's wrong here
No match statement references TCP flags; the record matches only IPv4 source, destination and protocol. TCP flags would appear as match ipv4 protocol tcp flags, which is the correct choice when filtering flows by flag values such as SYN or ACK.
Go deeper
Related to this question
About these practice questions
One of 1,401 original 300-410 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.