Courseiva
Network Assurance →easyMultiple Choice

350-401 Network Assurance Practice Question

A network engineer is configuring a Cisco Catalyst switch to send flow data to a NetFlow collector for traffic analysis. The engineer wants to ensure that only ingress traffic on a specific interface is exported. Which command is required to enable NetFlow on that interface?

⚠ Common exam trap

The trap here is mixing up the interface-level command to enable NetFlow with the global command to define the collector destination.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

ip flow ingress

To enable NetFlow for ingress traffic on a specific interface, the 'ip flow ingress' command must be applied in interface configuration mode. This command activates flow capture for packets entering the interface. The other options either enable egress flow, use an outdated method, or configure the export destination rather than enabling flow capture.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    ip flow egress

    Why it's wrong here

    The 'ip flow egress' command enables NetFlow for egress traffic on the interface. It captures flow data for packets leaving the interface, not entering it. Since the requirement is to export only ingress traffic, this command would not achieve the desired result and is therefore incorrect.

  • ✗

    ip route-cache flow

    Why it's wrong here

    The 'ip route-cache flow' command is an older method to enable NetFlow on an interface, but it is not the standard command on modern Cisco Catalyst switches. It may not be supported or may enable both ingress and egress depending on the platform. It does not specifically enable only ingress traffic, so it is not the best answer.

  • ✗

    ip flow-export destination

    Why it's wrong here

    The 'ip flow-export destination' command is used to specify the IP address and port of the NetFlow collector, not to enable NetFlow on an interface. It is a global configuration command that defines where flow data is sent. It does not activate flow capture on the interface, so it does not fulfill the requirement.

  • ✓

    ip flow ingress

    Why this is correct

    The 'ip flow ingress' command enables NetFlow for ingress traffic on the interface. It tells the switch to capture flow data for packets entering that interface and export it to the configured collector. This is the correct command to meet the requirement of exporting only ingress traffic from a specific interface.

About these practice questions

Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.