Courseiva
Network Assurance →hardMultiple Choice

350-401 Network Assurance Practice Question

A network administrator is troubleshooting high CPU utilization on a Catalyst 9300 switch. The output of 'show processes cpu sorted' shows the 'IP Input' process consuming 45% CPU. Which tool should be used to identify the specific packets causing the issue?

⚠ Common exam trap

It's easy for candidates to confuse SPAN (traffic mirroring) with a diagnostic tool, but SPAN does not provide built-in traffic analysis and can worsen CPU load, whereas NetFlow is designed for flow-level analysis without adding significant overhead.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable IP traffic export (NetFlow) on the switch.

The 'IP Input' process handles incoming IP packets that require CPU processing, such as routing protocol updates, management traffic, or packets destined to the switch itself. Enabling IP traffic export (NetFlow) on the switch allows the administrator to analyze traffic flows and identify the specific source/destination IP addresses, ports, and protocols consuming CPU cycles, without overwhelming the CPU further. NetFlow provides granular visibility into the types of packets being processed, making it the correct tool for this scenario.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use extended ping from the switch to generate traffic.

    Why it's wrong here

    Extended ping generates synthetic ICMP test traffic from the switch itself, but it cannot reveal the identity or characteristics of the existing unknown traffic that is already saturating the 'IP Input' process. Because the problem is ongoing and unrelated to generated pings, this approach merely adds more packets to the CPU queue, potentially worsening the very condition under investigation. It provides no flow-level detail about the source or destination of the offending packets.

  • ✗

    Configure a SPAN session to capture all traffic to the CPU.

    Why it's wrong here

    SPAN (Switched Port Analyzer) merely mirrors selected traffic to a monitoring port; it does not classify or summarize flows, so the administrator would still have to manually analyze large captures to find the offending packets. When used to capture traffic destined to the CPU, local SPAN can actually increase CPU load because the CPU must process the mirrored copies, aggravating the high CPU problem. NetFlow, by contrast, exports aggregated flow metadata directly to a collector with minimal overhead.

  • ✗

    Check CDP neighbors to see if any devices are flooding.

    Why it's wrong here

    CDP (Cisco Discovery Protocol) only discloses the identity, platform, and capabilities of directly connected Cisco devices, not the type or volume of IP packets they are sending toward the CPU. A flooding neighbor would require examining interface counters, packet captures, or flow records; CDP reveals nothing about Layer 3 traffic patterns or the 'IP Input' process. This check is thus irrelevant to diagnosing which specific flows are consuming CPU cycles.

  • ✓

    Enable IP traffic export (NetFlow) on the switch.

    Why this is correct

    NetFlow (IP traffic export) samples and exports flow records containing source/destination IP addresses, Layer 4 ports, protocol numbers, and packet/byte counts to a NetFlow collector. By analyzing these exported records, the administrator can pinpoint exactly which flows are contributing to the saturated 'IP Input' process, such as specific hosts generating large volumes of routed traffic. This local, low-overhead mechanism is specifically designed for flow-level visibility and is the correct tool for this troubleshooting scenario.

Quick reference

Routing Protocol Comparison

ProtocolMetricMax HopsAlgorithmType
RIP v2Hop count15Bellman-FordDistance vector
OSPFCost (bandwidth)UnlimitedDijkstra (SPF)Link state
EIGRPComposite metricUnlimitedDUALHybrid
IS-ISCostUnlimitedDijkstraLink state
BGPPolicy / attributesUnlimitedPath vectorPath vector

RIP's 15-hop limit makes it unsuitable for large networks. OSPF and EIGRP dominate modern enterprise deployments.

About these practice questions

This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.