nerdexam
Cisco

300-445 · Question #24

Which protocols are commonly used for passive monitoring in network assurance?

The correct answer is B. DNS C. NetFlow D. SNMP. DNS (B), NetFlow (C), and SNMP (D) are used for passive monitoring because they collect or observe network data without injecting synthetic test traffic. NetFlow captures metadata about IP traffic flows as they naturally pass through routers and switches; SNMP gathers device…

Data Collection Implementation

Question

Which protocols are commonly used for passive monitoring in network assurance?

Options

  • AHTTP
  • BDNS
  • CNetFlow
  • DSNMP
  • ESMTP
  • FICMP

How the community answered

(26 responses)
  • A
    12% (3)
  • B
    81% (21)
  • E
    4% (1)
  • F
    4% (1)

Explanation

DNS (B), NetFlow (C), and SNMP (D) are used for passive monitoring because they collect or observe network data without injecting synthetic test traffic. NetFlow captures metadata about IP traffic flows as they naturally pass through routers and switches; SNMP gathers device statistics and receives unsolicited trap alerts from network equipment; and DNS query/response data is passively captured to detect anomalies, misconfigurations, and threats. HTTP (A) and SMTP (E) are application-layer communication protocols for web and email delivery respectively - they carry user data, not monitoring telemetry. ICMP (F) is the classic distractor: it's used for active monitoring (ping, traceroute) because it requires deliberately sending probe packets to test reachability.

Memory tip: Think "NSD = Non-Sending Diagnostics" - NetFlow, SNMP, and DNS all listen and collect rather than send probes, making them passive. If a protocol sends packets to test something (like ICMP ping), it's active, not passive.

Topics

#passive-monitoring#NetFlow#SNMP#data-collection

Community Discussion

No community discussion yet for this question.

Full 300-445 Practice