Soru

Zorluk: ZorNetwork Performance Monitoring and Metrics

A network administrator is tasked with setting up a high-performance network monitoring solution for an enterprise core switch. The monitoring system must collect flow-level traffic statistics to analyze bandwidth utilization by application, while also enabling secure management polling and alerting without exposing telemetry data or authentication credentials to eavesdropping on the management network. Which of the following protocol configurations and telemetry methods should the administrator implement to meet these requirements? (Select TWO.)

  1. Implement IPFIX/NetFlow with flow sampling on interface ports to export application traffic statistics to a flow collector.Cevap
  2. Configure SNMPv3 with the authPriv security level on core switches for encrypted metric polling and event notifications.Cevap
  3. C
    Configure Syslog to stream complete TCP packet headers over port 23 to capture real-time flow throughput metrics.
  4. D
    Deploy SNMPv2c with read-only community strings to provide encrypted transmission of switch interface performance metrics.

Cevap

The network administrator should implement IPFIX/NetFlow flow sampling for application traffic statistics and deploy SNMPv3 configured with the authPriv security level to ensure encrypted metric polling and traps.
The combination of IPFIX/NetFlow and SNMPv3 with authPriv addresses both core monitoring requirements. IPFIX/NetFlow aggregates connection metadata to measure bandwidth and application traffic distribution effectively. SNMPv3 with authPriv adds cryptographic authentication and encryption to management polling and traps, protecting performance data from eavesdropping.

Adım Adım Çözüm

1
Analyze requirement 1: Gathering flow-level application traffic and bandwidth utilization statistics.
Identify that NetFlow or IPFIX (IP Flow Information Export) is designed specifically for flow-level data collection and traffic analysis.
Flow technologies track metadata such as source/destination IP, port, and byte counts per flow without requiring full packet capture overhead.
2
Analyze requirement 2: Secure telemetry polling and alerting against eavesdropping.
Identify SNMPv3 with authPriv security level as the standard for authenticated and encrypted network device management.
SNMPv3 authPriv ensures both user authentication (auth) and payload encryption (priv), preventing unauthorized viewing or modification of management traffic.
3
Evaluate wrong alternatives against network protocols and security models.
Reject SNMPv2c due to plain-text community string vulnerability and reject Syslog over port 23 for flow metric analysis.
SNMPv2c lacks encryption, and Syslog is intended for logging text alerts, not streaming raw packet headers or high-frequency performance metrics.

Anahtar Kavram

Network Telemetry, Flow Export Protocols, and SNMPv3 Security Levels
Bu soruyu puanla