N10-009 exam dumps

N10-009 practice question 202 of 329

Network+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

N10-009 Question 202

Single answer3.2 Given a scenario, use network monitoring technologies.

A network administrator is troubleshooting intermittent slowness reported by users in a branch office. The issue affects multiple applications at random times during the day, and basic connectivity tests show no outages. The administrator wants to identify which hosts and applications are consuming the most bandwidth on the WAN link without capturing full packet payloads. Which monitoring technology should the administrator use?

  1. A

    Configure NetFlow on the branch router and analyze the exported flow records

  2. B

    Enable port mirroring on the switch and review traffic counters only

  3. C

    Use SNMP polling to check whether the router interface is up or down

  4. D

    Run a continuous ICMP ping from a workstation to the data center gateway

Show answer and explanation

Correct answer: A

Explanation

Flow-based monitoring technologies such as NetFlow, IPFIX, and sFlow are commonly used to analyze bandwidth consumption, top talkers, and application usage patterns while avoiding the storage and privacy concerns of full packet capture. In this scenario, the administrator needs visibility into who is using the WAN link and for what type of traffic, not just whether the circuit is operational. SNMP is valuable for baseline monitoring of utilization and interface health, and ICMP is useful for reachability and latency testing, but neither provides per-flow usage data. Port mirroring is more appropriate when deep packet inspection with a protocol analyzer is required. Vendor and industry documentation for Cisco NetFlow and IETF IPFIX describe exporting metadata about traffic flows for performance monitoring, accounting, and capacity planning, which aligns directly with the requirement in this scenario.

  • A. Correct.

    Correct. NetFlow and similar flow-based monitoring technologies summarize conversations by source/destination IP, ports, protocol, interface, and byte/packet counts. This allows the administrator to identify top talkers and high-bandwidth applications on the WAN link without collecting full packet payloads. This is the most appropriate choice when the goal is traffic visibility and usage analysis with lower overhead than full packet capture.

  • B. Incorrect.

    Incorrect. Port mirroring can be useful when sending traffic to a packet analyzer, but reviewing switch traffic counters alone will not identify application-level bandwidth consumers across the WAN. In addition, port mirroring typically supports packet capture workflows rather than summarized usage reporting. The scenario specifically calls for identifying hosts and applications without capturing full payloads, which makes flow monitoring a better fit.

  • C. Incorrect.

    Incorrect. SNMP polling is useful for monitoring interface utilization, errors, discards, device health, and operational status. However, checking only whether an interface is up or down does not reveal which hosts or applications are responsible for congestion. A candidate might choose this because SNMP is a monitoring technology, but it does not provide the needed traffic flow detail by itself.

  • D. Incorrect.

    Incorrect. Continuous ping can help detect latency, jitter, and packet loss trends between two points, but it does not identify which internal hosts or application flows are consuming bandwidth. This is a common troubleshooting step, but it is not the best monitoring technology for analyzing WAN usage patterns.

Timed practice exam

Take a N10-009 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam