350-401 Network Assurance Practice Question
A network engineer is configuring a Cisco Catalyst switch to send flow data to a NetFlow collector for traffic analysis. The engineer wants to ensure that only ingress traffic on a specific interface is exported. Which command is required to enable NetFlow on that interface?
⚠ Common exam trap
The trap here is mixing up the interface-level command to enable NetFlow with the global command to define the collector destination.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
ip flow ingress
To enable NetFlow for ingress traffic on a specific interface, the 'ip flow ingress' command must be applied in interface configuration mode. This command activates flow capture for packets entering the interface. The other options either enable egress flow, use an outdated method, or configure the export destination rather than enabling flow capture.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
ip flow egress
Why it's wrong here
The 'ip flow egress' command enables NetFlow for egress traffic on the interface. It captures flow data for packets leaving the interface, not entering it. Since the requirement is to export only ingress traffic, this command would not achieve the desired result and is therefore incorrect.
- ✗
ip route-cache flow
Why it's wrong here
The 'ip route-cache flow' command is an older method to enable NetFlow on an interface, but it is not the standard command on modern Cisco Catalyst switches. It may not be supported or may enable both ingress and egress depending on the platform. It does not specifically enable only ingress traffic, so it is not the best answer.
- ✗
ip flow-export destination
Why it's wrong here
The 'ip flow-export destination' command is used to specify the IP address and port of the NetFlow collector, not to enable NetFlow on an interface. It is a global configuration command that defines where flow data is sent. It does not activate flow capture on the interface, so it does not fulfill the requirement.
- ✓
ip flow ingress
Why this is correct
The 'ip flow ingress' command enables NetFlow for ingress traffic on the interface. It tells the switch to capture flow data for packets entering that interface and export it to the configured collector. This is the correct command to meet the requirement of exporting only ingress traffic from a specific interface.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.