Courseiva
easyMultiple Select

350-401 Practice Question: Which two statements about NetFlow flow records…

Which two statements about NetFlow flow records and export are correct? (Choose two.)

⚠ Common exam trap

The trap is assuming that NetFlow v5 supports modern features like IPv6 or variable-length fields, or that export uses TCP for reliability, when in fact UDP is standard.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

NetFlow v9 uses a template-based export format.

Option A is correct because NetFlow v9 introduced a template-based export format, where the exporter periodically sends template records that define the layout and field types of subsequent data records, allowing flexible and extensible flow record definitions. Option B is correct because IPFIX (Internet Protocol Flow Information Export) is the IETF standard (RFC 7011) derived from and based on NetFlow v9, adopting its template-based architecture while standardizing field specifications. Option C is incorrect because NetFlow v5 uses a fixed, predefined record format with fixed-length fields and a fixed flow key, not variable-length fields or custom keys. Option D is incorrect because NetFlow export traditionally uses UDP (typically port 2055) for efficiency, not TCP by default, though TCP is an option in some implementations like IPFIX. Option E is incorrect because NetFlow v5 only supports IPv4 flow information; IPv6 support was introduced with NetFlow v9 and IPFIX.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    NetFlow v9 uses a template-based export format.

    Why this is correct

    NetFlow v9 replaces the fixed-format records of v5 with reusable templates, letting a collector interpret varied field layouts without prior knowledge of each exporter's configuration. This satisfies the scenario's requirement for flexible, extensible flow export, since templates are periodically resent so collectors can decode records dynamically.

  • ✓

    IPFIX is the IETF standard version of NetFlow, based on NetFlow v9.

    Why this is correct

    IPFIX, standardised by the IETF in RFC 7011, derives directly from Cisco NetFlow v9, adopting its template-based export format. This satisfies the question's requirement for a correct statement about NetFlow evolution, confirming the vendor-neutral standardisation path rather than the fixed-format NetFlow v5 alternative.

  • ✗

    NetFlow v5 supports variable-length fields and custom flow keys.

    Why it's wrong here

    NetFlow v5 uses a fixed 48-byte record format with a fixed set of fields, so variable-length fields and custom flow keys are impossible. It is tempting because flexible templates are genuinely useful for non-standard keys, but that capability belongs to v9 and IPFIX, which carry template definitions; v5 cannot.

  • ✗

    NetFlow export uses TCP by default to ensure reliable delivery.

    Why it's wrong here

    NetFlow export runs over UDP, which the exporter does not acknowledge, so TCP reliability is not the default mechanism. It is tempting because reliable delivery sounds desirable for billing-grade records, and TCP export does exist as an option, but the default transport remains UDP with sequence numbers used to detect loss.

  • ✗

    NetFlow v5 can export IPv6 flow information.

    Why it's wrong here

    NetFlow v5 records carry only IPv4 address fields, so IPv6 flow information cannot be exported. It is tempting because v5 is widely deployed and appears capable, but IPv6 support arrived with NetFlow v9 and IPFIX, whose template-based records accommodate the longer addresses; v5 has no field for them.

Quick reference

Common DNS Record Types

RecordPurposeExample
AIPv4 address mappingexample.com → 93.184.216.34
AAAAIPv6 address mappingexample.com → 2606:2800::1
CNAMEAlias to another hostnamewww → example.com
MXMail server for domainexample.com → mail.example.com (priority 10)
TXTText data (SPF, DKIM, verification)v=spf1 include:_spf.example.com ~all
NSAuthoritative name serversexample.com NS ns1.example.com
PTRReverse DNS (IP → hostname)34.216.184.93.in-addr.arpa → example.com
SOAZone authority recordPrimary NS, admin email, serial, TTL defaults

About these practice questions

Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.