Which NetFlow version/type does Cisco Threat Defense use for network visibility?
Choose an answer
Tap an option to check your answer.
Correct answer: flexible.
Why this is the answer
Cisco Threat Defense (FTD) uses Flexible NetFlow for network visibility. Flexible NetFlow is a highly customizable and scalable version of NetFlow that allows administrators to define specific flow records to capture detailed information about network traffic, including security-relevant data. This flexibility is crucial for threat detection and analysis. NBAR2 (Network-Based Application Recognition 2) is used for application recognition and classification, not for exporting flow data. NetFlow version 8 is an older, less flexible version primarily used for aggregation and is not the primary mechanism for FTD. IPFIX (IP Flow Information Export) is an IETF standard based on NetFlow v9, and while FTD can export to IPFIX collectors, the internal mechanism FTD uses for generating these flows is Flexible NetFlow.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed