Question 1 of 25

Refer to the exhibits. Which information is provided for traceback analysis when this configuration is applied?
Show answer
How others answered
- A80%
- C20%
Explanation
I'm voting for A based on this paragraph from Cisco. It specifically talks about tracing the source of an attack and using NetFlow to know the source interface. Keywords are in all caps. "The originator of DoS attacks cannot be easily identified because the IP source address of the device sending the traffic is usually forged. However, you can easily TRACE the traffic BACK through the network to the router on which it is arriving by using the NetFlow Layer 2 and Security Monitoring Exports feature to capture the MAC address and VLAN-ID fields. If the router on which traffic is arriving supports NetFlow, you can configure the NetFlow Layer 2 and Security Monitoring Exports feature on it to identify the INTERFACE on which the traffic is ARRIVING." https://www.cisco.com/en/US/docs/ios-xml/ios/netflow/configuration/15-2s/nf-detct-analy-thrts.html
Adapted from community discussion by karen1337 · 2024-09-30 · 2 community upvotes. Third-party contribution; reviewed by our quality filter, not independently verified.
Supporting references














