N10-009 Network Operations Practice Question
An NOC technician receives an alert that latency on a critical WAN link has increased significantly. The technician needs to analyze the latency trend over the past week to identify patterns. Which approach is the most efficient for gathering this historical data?
⚠ Common exam trap
A common mix-up: candidates confuse SNMP traps (event-driven alerts) with SNMP polling (periodic data collection), assuming traps can provide historical trend data when they are designed only for real-time notifications.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use SNMP polling with a suitable MIB to collect latency metrics at regular intervals
SNMP polling with a suitable MIB (e.g., IF-MIB for interface statistics or IP-MIB for performance metrics) allows the NOC to collect latency data at regular, configurable intervals over time. This historical data can be stored in a management system and analyzed for trends, making it the most efficient method for identifying patterns in WAN latency over a week. SNMP traps, by contrast, are event-driven and do not provide the continuous, periodic data needed for trend analysis.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use SNMP traps to alert on each latency spike
Why it's wrong here
SNMP traps are asynchronous notifications sent by a network device to a management station when a specific event or threshold is met, such as a critical interface going down or a high CPU utilization. While useful for immediate alerts on latency *spikes* (if configured), traps are event-driven and do not provide the continuous, granular data collection necessary for building a historical record of latency trends. They signal an occurrence, rather than systematically logging ongoing performance metrics.
When this WOULD be correct
A question asking for the best method to receive real-time alerts for critical latency spikes, where immediate notification is required and historical analysis is not needed.
- ✓
Use SNMP polling with a suitable MIB to collect latency metrics at regular intervals
Why this is correct
SNMP (Simple Network Management Protocol) polling involves a management station periodically querying network devices for specific data points defined in a Management Information Base (MIB). For latency, an appropriate MIB object (e.g., RTT or interface statistics that can infer latency) would be queried at regular intervals. This systematic collection allows for the creation of historical trends, baseline establishment, and long-term performance analysis, making it ideal for monitoring critical network latency over time.
- ✗
Run a continuous ping test and manually log timestamps
Why it's wrong here
A continuous ping test measures the round-trip time to a single destination, providing real-time latency data. However, manually logging timestamps and results is highly inefficient, prone to human error, and not scalable for monitoring critical network infrastructure. This method lacks the automation, data storage, and reporting capabilities required for effective historical trend analysis and proactive management of network performance.
When this WOULD be correct
This approach would be correct if the question asked for a real-time, ad-hoc latency check on a specific link without any monitoring infrastructure, and the technician only needed a few minutes of data.
- ✗
Use traceroute to identify each hop and measure latency per hop
Why it's wrong here
Traceroute (or `tracert`) is a diagnostic tool that maps the path a packet takes to a destination, showing each router (hop) and the round-trip time to each hop. While useful for identifying specific points of high latency or path changes at a given moment, it provides only a snapshot. It is not designed for continuous, automated, historical data collection across an entire network for trend analysis, nor does it typically integrate into network monitoring systems for long-term storage and reporting.
When this WOULD be correct
A technician needs to identify which specific hop along a WAN path is introducing the highest latency during a current performance issue. Traceroute would be the correct tool to isolate the problematic hop in real time.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The N10-009 exam frequently reuses these exact scenarios with slightly different constraints.
✓Use SNMP polling with a suitable MIB to collect latency metrics at regular intervalsCorrect answer▾
Why this is correct
SNMP (Simple Network Management Protocol) polling involves a management station periodically querying network devices for specific data points defined in a Management Information Base (MIB). For latency, an appropriate MIB object (e.g., RTT or interface statistics that can infer latency) would be queried at regular intervals. This systematic collection allows for the creation of historical trends, baseline establishment, and long-term performance analysis, making it ideal for monitoring critical network latency over time.
✗Use SNMP traps to alert on each latency spikeWrong answer — click to see why▾
Why this is wrong here
SNMP traps are event-driven notifications for immediate alerts, not designed for gathering historical trend data over a week. They would not provide the regular interval data needed to analyze latency patterns.
★ When this WOULD be the correct answer
A question asking for the best method to receive real-time alerts for critical latency spikes, where immediate notification is required and historical analysis is not needed.
Why candidates choose this
Candidates may confuse SNMP traps with SNMP polling, thinking traps can also be used for data collection, or they may focus on the 'alert' aspect of the question without considering the need for historical trend analysis.
✗Run a continuous ping test and manually log timestampsWrong answer — click to see why▾
Why this is wrong here
Continuous ping and manual logging is inefficient for analyzing a week-long latency trend, as it requires constant human intervention and does not provide automated, structured historical data.
★ When this WOULD be the correct answer
This approach would be correct if the question asked for a real-time, ad-hoc latency check on a specific link without any monitoring infrastructure, and the technician only needed a few minutes of data.
Why candidates choose this
Candidates may think ping is a simple and direct way to measure latency, and manual logging seems like a straightforward method to collect data without needing to configure SNMP or MIBs.
✗Use traceroute to identify each hop and measure latency per hopWrong answer — click to see why▾
Why this is wrong here
Traceroute measures per-hop latency at a single point in time, not historical trends over a week. It is inefficient for gathering continuous historical data and does not provide a consolidated latency trend.
★ When this WOULD be the correct answer
A technician needs to identify which specific hop along a WAN path is introducing the highest latency during a current performance issue. Traceroute would be the correct tool to isolate the problematic hop in real time.
Why candidates choose this
Candidates may think traceroute provides detailed path information and assume it can be used repeatedly to build a trend, but they overlook that it is not designed for automated, scheduled historical data collection.
Analysis generated from the official N10-009blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Go deeper
Related to this question
Learn chapter
Change and Configuration Management
Key term
WAN
A Wide Area Network (WAN) is a telecommunications network that connects multiple smaller networks, like local area networks, across large geographical distances.
Key term
SNMP
SNMP (Simple Network Management Protocol) is an application-layer protocol used to collect and organize information about managed devices on IP networks and to modify that information to change device behavior.
About these practice questions
This N10-009 question is part of Courseiva's 464-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This N10-009 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the N10-009 exam.