350-501 · Question #66
Refer to the exhibit. Which information is provided for traceback analysis when this configuration is applied?
The correct answer is D. IP sub flow cache. The exhibit likely shows a NetFlow or IP traffic export configuration that enables the 'ip flow-export' or 'ip flow-aggregation cache' feature with sub-flow tracking. The 'IP sub flow cache' is a NetFlow feature that provides more granular flow data by tracking sub-flows within a
Question
Refer to the exhibit. Which information is provided for traceback analysis when this configuration is applied?
Exhibit
Options
- ABGP version
- Bpacket size distribution
- Csource interface
- DIP sub flow cache
How the community answered
(17 responses)- B6% (1)
- D94% (16)
Explanation
The exhibit likely shows a NetFlow or IP traffic export configuration that enables the 'ip flow-export' or 'ip flow-aggregation cache' feature with sub-flow tracking. The 'IP sub flow cache' is a NetFlow feature that provides more granular flow data by tracking sub-flows within a single NetFlow flow record. This information is used for traceback analysis - tracing the origin of attack traffic or anomalous packets back to the source. The sub-flow cache captures additional detail beyond standard flow records, such as sampled packet information, making it valuable for security traceback. BGP version, packet size distribution, and source interface are available through other means but are not what this specific configuration enables for traceback.
Topics
Community Discussion
No community discussion yet for this question.
