N10-009 Network Operations Practice Question
A network administrator needs to analyze bandwidth usage on a WAN link to determine which applications are generating the most traffic. The administrator requires detailed flow-level data including source/destination IP, ports, and protocol. Which technology should be used to collect this information?
⚠ Common exam trap
A common mix-up: candidates confuse SNMP's interface utilization statistics with the detailed per-flow data that NetFlow provides, leading them to choose SNMP when the question explicitly asks for source/destination IP, ports, and protocol.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
NetFlow
NetFlow is the correct choice because it provides detailed flow-level data, including source and destination IP addresses, ports, and protocols, which is exactly what the administrator needs to analyze bandwidth usage per application on a WAN link. Unlike SNMP or Syslog, NetFlow captures per-flow metadata that allows identification of which applications are generating the most traffic.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
NetFlow
Why this is correct
NetFlow, or similar IP Flow Information Export (IPFIX) technologies, is specifically designed to collect and export detailed information about network traffic flows. It aggregates packets into logical conversations based on common attributes like source/destination IP addresses, ports, and protocols. This granular per-flow data allows network administrators to precisely identify which applications, users, or services are consuming bandwidth on a WAN link, enabling in-depth analysis for capacity planning and troubleshooting.
- ✗
SNMP
Why it's wrong here
Simple Network Management Protocol (SNMP) is primarily used for monitoring the operational status and performance metrics of network devices. It collects aggregate statistics such as interface utilization, CPU load, and error rates from Management Information Bases (MIBs). While SNMP can report the total bandwidth consumed by an interface, it does not provide the necessary per-flow details to determine *what specific applications or conversations* are responsible for that bandwidth usage, making it insufficient for deep traffic analysis.
When this WOULD be correct
A network administrator needs to monitor overall bandwidth utilization and interface errors on a router over time, without requiring per-flow application details. SNMP polling with MIBs like IF-MIB would be appropriate.
- ✗
Syslog
Why it's wrong here
Syslog is a standard protocol for collecting system log messages from network devices and servers to a central logging server. Devices use Syslog to report events like configuration changes, security alerts, interface status changes, and authentication attempts. While crucial for operational monitoring and troubleshooting system-level issues, Syslog does not capture or analyze the actual IP packet flows or bandwidth consumption patterns, thus it cannot be used for application-level traffic analysis on a WAN link.
When this WOULD be correct
Syslog would be correct if the question asked for collecting and centralizing system logs (e.g., authentication failures, device errors) from network devices for security monitoring or troubleshooting, without needing traffic flow details.
- ✗
ICMP
Why it's wrong here
Internet Control Message Protocol (ICMP) is a network layer protocol used for sending error messages and operational information, primarily for diagnostic purposes. It is fundamental to tools like `ping` for testing network reachability and latency, and `traceroute` for mapping network paths. However, ICMP's function is limited to control and error reporting; it does not collect or analyze ongoing traffic flow data, nor does it provide any mechanism to identify bandwidth consumption by specific applications or services.
When this WOULD be correct
When the question asks for a tool to test basic network connectivity or measure round-trip time between hosts, ICMP (e.g., ping) would be the correct answer.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The N10-009 exam frequently reuses these exact scenarios with slightly different constraints.
✓NetFlowCorrect answer▾
Why this is correct
NetFlow, or similar IP Flow Information Export (IPFIX) technologies, is specifically designed to collect and export detailed information about network traffic flows. It aggregates packets into logical conversations based on common attributes like source/destination IP addresses, ports, and protocols. This granular per-flow data allows network administrators to precisely identify which applications, users, or services are consuming bandwidth on a WAN link, enabling in-depth analysis for capacity planning and troubleshooting.
✗SNMPWrong answer — click to see why▾
Why this is wrong here
SNMP provides aggregate statistics (e.g., total bytes/packets) but not flow-level details like source/destination IP, ports, and protocol. It cannot identify individual application traffic flows.
★ When this WOULD be the correct answer
A network administrator needs to monitor overall bandwidth utilization and interface errors on a router over time, without requiring per-flow application details. SNMP polling with MIBs like IF-MIB would be appropriate.
Why candidates choose this
Candidates know SNMP is used for network monitoring and bandwidth usage, but they overlook that it lacks the granular flow-level data (IPs, ports, protocols) that NetFlow provides.
✗SyslogWrong answer — click to see why▾
Why this is wrong here
Syslog is used for logging system events and messages, not for collecting detailed flow-level data like source/destination IP, ports, and protocol. It lacks the granular traffic analysis capabilities required for this scenario.
★ When this WOULD be the correct answer
Syslog would be correct if the question asked for collecting and centralizing system logs (e.g., authentication failures, device errors) from network devices for security monitoring or troubleshooting, without needing traffic flow details.
Why candidates choose this
Candidates may confuse Syslog with NetFlow because both involve network monitoring and data collection, but Syslog focuses on event logs rather than traffic flows.
✗ICMPWrong answer — click to see why▾
Why this is wrong here
ICMP is used for network diagnostics (e.g., ping, traceroute) and does not provide flow-level data such as source/destination IP, ports, or protocol details needed for application traffic analysis.
★ When this WOULD be the correct answer
When the question asks for a tool to test basic network connectivity or measure round-trip time between hosts, ICMP (e.g., ping) would be the correct answer.
Why candidates choose this
Candidates may confuse ICMP with a traffic monitoring tool because it is commonly used in network troubleshooting and can indicate packet loss or latency, but it lacks the detailed flow information required.
Analysis generated from the official N10-009blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Go deeper
Related to this question
Learn chapter
Network Documentation and Diagrams
Key term
NetFlow
NetFlow is a network protocol developed by Cisco that collects and monitors IP traffic data to provide visibility into network usage, performance, and security.
Key term
WAN
A Wide Area Network (WAN) is a telecommunications network that connects multiple smaller networks, like local area networks, across large geographical distances.
About these practice questions
One of 464 original N10-009 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This N10-009 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the N10-009 exam.