nerdexam
Cisco

300-710 · Question #296

When an engineer captures traffic on a Cisco FTD to troubleshoot a connectivity problem, they receive a large amount of output data in the GUI tool. The engineer found that viewing the Captures this w

The correct answer is B. PCAP. To effectively analyze a large amount of captured traffic data from a Cisco FTD using dedicated network analysis tools, the engineer should export the data in PCAP format.

Management and Troubleshooting

Question

When an engineer captures traffic on a Cisco FTD to troubleshoot a connectivity problem, they receive a large amount of output data in the GUI tool. The engineer found that viewing the Captures this way is time-consuming and difficult to son and filter. Which file type must the engineer export the data in so that it can be reviewed using a tool built for this type of analysis?

Options

  • ANetFlow v9
  • BPCAP
  • CNetFlow v5
  • DIPFIX

How the community answered

(50 responses)
  • A
    2% (1)
  • B
    90% (45)
  • C
    4% (2)
  • D
    4% (2)

Why each option

To effectively analyze a large amount of captured traffic data from a Cisco FTD using dedicated network analysis tools, the engineer should export the data in PCAP format.

ANetFlow v9

NetFlow v9 is a protocol for collecting IP traffic information, summarizing flow statistics, not capturing raw packet data for deep inspection.

BPCAPCorrect

PCAP (Packet CAPture) is a standard file format for storing network traffic data. Tools like Wireshark are specifically designed to open, analyze, filter, and sort PCAP files, making it the ideal format for detailed troubleshooting of connectivity issues with large capture sets.

CNetFlow v5

NetFlow v5 is an older version of the NetFlow protocol, also for flow statistics, not raw packet capture.

DIPFIX

IPFIX (IP Flow Information Export) is a universal standard based on NetFlow v9 for exporting flow information, similar to NetFlow, and does not capture full packet data.

Concept tested: FTD traffic capture export format for analysis

Source: https://www.cisco.com/c/en/us/td/docs/security/firepower/670/configuration/guide/fpmc-config-guide-v67/fpmc-access-policies.html#task_CE6E3D8523A744C2A44B0568B8D1494F

Topics

#Cisco FTD#Traffic Capture#PCAP#Troubleshooting Tools

Community Discussion

No community discussion yet for this question.

Full 300-710 Practice