hardMultiple Choice
350-401 Practice Question: A service provider is using Cisco ASR 9000…
A service provider is using Cisco ASR 9000 routers and needs to collect NetFlow data from multiple customers' traffic. The engineer wants to ensure that flow records from different customers are not mixed and can be identified separately. The router supports Flexible NetFlow. What is the best approach?
⚠ Common exam trap
Cisco often tests the misconception that you must use separate flow monitors or collectors for each customer, when in fact Flexible NetFlow's VRF or VLAN match fields allow a single monitor to separate flows, reducing configuration and resource usage.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Define a custom flow record that includes the 'match ipv4 vlan' or 'match ipv4 vrf' field to identify each customer's traffic, and apply a single flow monitor on the shared interface.
Flexible NetFlow allows you to define a custom flow record that includes key fields such as 'match ipv4 vrf' (VRF-aware NetFlow) to uniquely identify each customer's traffic. By applying a single flow monitor on a shared interface (e.g., a trunk or core link), the router can tag flows with the VRF or VLAN identifier, ensuring per-customer separation without needing multiple monitors or collectors. This approach is efficient and leverages the router's ability to export differentiated flow records to a single collector, which can then filter based on the VRF or VLAN field.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Define a custom flow record that includes the 'match ipv4 vlan' or 'match ipv4 vrf' field to identify each customer's traffic, and apply a single flow monitor on the shared interface.
Why this is correct
A custom flow record built with Flexible NetFlow can reference the VRF name or VLAN tag alongside the standard 5-tuple, so flows from different customers sharing the same physical interface are tagged at the source router. Because the flow monitor is attached to the shared interface, it captures all traffic in a single pass, and the collector uses the VRF/VLAN key to separate per-customer statistics. This eliminates reliance on IP uniqueness and scales to many VPNs or VLANs without needing a separate monitor per tenant.
- ✗
Configure a separate flow monitor for each customer interface and export to different collectors.
Why it's wrong here
Creating a separate flow monitor per customer interface assumes each customer has its own interface, but the question states they share a single interface (e.g., an MPLS VPN), so there are no distinct per-customer interfaces to attach monitors to. Even if you tried to apply multiple monitors to the same interface, each monitor without a filter would capture identical traffic, and exporting to different collectors would double the export bandwidth while still not separating the flows. This approach adds operational complexity and does not solve the core problem of flow attribution on the shared link.
- ✗
Use NetFlow v9 export with the 'match ipv4 source address' field only, and rely on the collector to separate by source IP.
Why it's wrong here
NetFlow v9 export using only the source IP address as the identifying key fails when customers use overlapping private address space, such as RFC 1918 10.x addresses inside different VRFs. The collector would merge flows that share a source IP, making it impossible to tell which customer generated them, and the actual destination and port may also be identical. VRF or VLAN context is the only reliable way to disambiguate customers in a shared infrastructure; source IP alone is insufficient.
- ✗
Enable SNMP interface polling to track per-customer traffic statistics.
Why it's wrong here
SNMP interface polling reads cumulative counters like ifInOctets and ifOutOctets for the entire shared interface every polling interval, so it provides only aggregate bandwidth utilization with no per-flow or per-customer visibility. NetFlow is specifically designed to record individual flows with timestamps, IP addresses, protocols, and ports, whereas SNMP cannot tell you which customer's TCP session contributed to the byte count. Moreover, polling at 5-minute intervals misses short-lived flows and provides no attribution on a multi-tenant link.
Visual reference
Go deeper
Related to this question
Learn chapter
SDN Controllers and Cisco ACI
Key term
Virtual Routing and Forwarding
Virtual Routing and Forwarding (VRF) is a technology that allows a single physical router to operate like multiple independent routers by keeping separate routing tables and forwarding decisions for each instance.
Key term
NetFlow
NetFlow is a network protocol developed by Cisco that collects and monitors IP traffic data to provide visibility into network usage, performance, and security.
About these practice questions
One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.