Courseiva
easyMultiple Choice

300-410 Practice Question: Runs the following command to verify Flexible…

A network engineer runs the following command to verify Flexible NetFlow cache entries:

R1# show flow monitor FLOW-MONITOR-1 cache format record

Cache entry for flow 1: ipv4 source address: 10.0.0.1 ipv4 destination address: 192.168.1.100

ip protocol: 6

counter bytes: 1500 counter packets: 10 timestamp sys-uptime first: 123456 timestamp sys-uptime last: 123556

Cache entry for flow 2: ipv4 source address: 10.0.0.2 ipv4 destination address: 192.168.1.101

ip protocol: 17

counter bytes: 500 counter packets: 5 timestamp sys-uptime first: 123457 timestamp sys-uptime last: 123557

What does this output indicate?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The cache shows two flows with source/destination IP, protocol, byte/packet counts, and timestamps.

The output shows two active flows in the Flexible NetFlow cache. Flow 1 is a TCP (protocol 6) flow from 10.0.0.1 to 192.168.1.100 with 1500 bytes and 10 packets. Flow 2 is a UDP (protocol 17) flow from 10.0.0.2 to 192.168.1.101 with 500 bytes and 5 packets. The timestamps show the first and last packet times.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Both flows are TCP connections.

    Why it's wrong here

    Flow 1 shows ip protocol 6 (TCP), but flow 2 shows 17 (UDP), so they are not both TCP. It is tempting because most inspected traffic is TCP, and identifying TCP sessions is correct when every cache entry's protocol field reads 6.

  • ✓

    The cache shows two flows with source/destination IP, protocol, byte/packet counts, and timestamps.

    Why this is correct

    The record-format output lists each cached flow with its IPv4 source and destination addresses, IP protocol number, byte and packet counters, and first/last timestamps. This confirms two distinct flows are being tracked with the expected fields.

  • ✗

    The cache does not include protocol information.

    Why it's wrong here

    Each cache entry explicitly lists 'ip protocol' with values 6 and 17, so protocol information is present. It is tempting because a cache configured with a reduced key or non-record format can omit fields, which is correct when the flow record itself excludes protocol.

  • ✗

    The flows are being exported immediately.

    Why it's wrong here

    The cache still holds both entries with accumulating byte and packet counters and first/last timestamps, indicating flows remain cached rather than exported on creation. It is tempting because immediate export is a valid mode, correct when the export protocol is configured to send each flow as it is created.

About these practice questions

This 300-410 question is part of Courseiva's 1,401-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.