Courseiva
mediumMultiple Choice

350-401 Practice Question: A large enterprise is migrating from traditional…

A large enterprise is migrating from traditional SNMP-based monitoring to streaming telemetry for better scalability and real-time visibility. The network team has Cisco Nexus 9000 switches running NX-OS. They want to stream interface counters and BGP neighbor state changes to a collector. Which telemetry technology should they implement?

⚠ Common exam trap

Cisco often tests the distinction between streaming telemetry (push-based, model-driven) and legacy monitoring methods like SNMP or NetFlow, where candidates mistakenly choose NetFlow because it sounds similar to 'streaming' or SNMP traps because they think 'state changes' imply event-driven traps, but the key is that MDT provides structured, scalable, and real-time data for operational state, not just flow records or performance metrics.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure model-driven telemetry (MDT) using gRPC or gNMI to subscribe to the desired YANG data models for interface counters and BGP state.

Model-driven telemetry (MDT) using gRPC or gNMI is the correct choice because it provides a push-based, scalable, and real-time streaming mechanism for subscribing to specific YANG data paths, such as interface counters and BGP neighbor state, directly from Cisco Nexus 9000 switches running NX-OS. This approach eliminates the polling overhead of SNMP and supports high-frequency data collection, making it ideal for large-scale enterprise monitoring.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Configure model-driven telemetry (MDT) using gRPC or gNMI to subscribe to the desired YANG data models for interface counters and BGP state.

    Why this is correct

    Model-driven telemetry (MDT) with gRPC or gNMI creates a persistent subscription to YANG-defined data models, allowing the NX-OS device to push interface counters and BGP state at a configured cadence or immediately on change. This push model scales to thousands of counters without collector polling overhead and supports structured encoding (protobuf/JSON), making it ideal for real-time visibility. Unlike flow or event mechanisms, MDT is purpose-built for streaming operational state from network devices.

  • ✗

    Enable NetFlow v9 on the switches and configure the collector to receive flow records that include interface statistics.

    Why it's wrong here

    NetFlow v9 is an export protocol for IP flow records—summaries of conversations identified by 5-tuple, timestamps, and byte/packet counts—not a transport for device state like interface counters or BGP RIB contents. While NetFlow can be configured on NX-OS, its collector receives sampled or unsampled flow data over UDP; it cannot subscribe to YANG models or push BGP adjacency state. Thus NetFlow answers 'what traffic is crossing the wire,' not 'what is the device's current operational state.'

  • ✗

    Use SNMP traps to send interface and BGP state changes to the collector.

    Why it's wrong here

    SNMP traps are asynchronous, event-driven notifications (e.g., linkUp/linkDown, bgpEstablished) but lack a generic mechanism to periodically stream high-frequency counter values; interface counters require either polling (SNMP GET) or vendor-specific trap instrumentation that is not standardized. Traps are sent over UDP, making delivery best-effort and prone to loss under bursts, so they cannot guarantee reliable telemetry for capacity or state monitoring. Furthermore, SNMP MIBs are flat and limited compared to YANG models, which complicates representing nested BGP state.

  • ✗

    Deploy IP SLA responders on the switches to measure performance and send results via syslog.

    Why it's wrong here

    IP SLA is an active measurement tool that generates synthetic probes—such as ICMP echo, UDP jitter, or HTTP requests—to assess network performance between endpoints; it does not export the device's own operational state. Deploying IP SLA responders on switches would measure path metrics but cannot provide interface counter deltas or BGP peer state, which are local device data. Sending results via syslog adds a text-based, unstructured side channel that is unsuitable for high-frequency structured telemetry and is not a replacement for MDT.

About these practice questions

One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.