nerdexam
Cisco

200-201 · Question #551

An engineer must analyze a security event from last month. The engineer has access to a .pcap file collected from traffic mirroring and NetFlow data. The engineer must perform checks quickly on a busy

The correct answer is C. both sources, first NetFlow because collection is easy, then .pcap. Flow data is fast to query and summarizes communications, making it ideal for quickly scoping an unknown event on a busy segment. After identifying relevant hosts, time windows, and conversations from the flows, packet capture can be used to drill into payload and protocol detail

Submitted by tarun92· Mar 6, 2026Network Intrusion Analysis

Question

An engineer must analyze a security event from last month. The engineer has access to a .pcap file collected from traffic mirroring and NetFlow data. The engineer must perform checks quickly on a busy network segment without knowing details. Which source of data must be used for analysis?

Options

  • A.pcap file because it is easy to track all activity for the last month
  • BNetFlow because it has all needed data
  • Cboth sources, first NetFlow because collection is easy, then .pcap
  • Dboth sources, first .pcap based on a simple query, then NetFlow

How the community answered

(60 responses)
  • A
    5% (3)
  • B
    3% (2)
  • C
    80% (48)
  • D
    12% (7)

Explanation

Flow data is fast to query and summarizes communications, making it ideal for quickly scoping an unknown event on a busy segment. After identifying relevant hosts, time windows, and conversations from the flows, packet capture can be used to drill into payload and protocol details for the specific traffic of interest.

Topics

#NetFlow#.pcap#network traffic analysis#incident response

Community Discussion

No community discussion yet for this question.

Full 200-201 Practice