PrepAway - Latest Free Exam Questions & Answers

Which two actions can you take to allow the greatest number of pertinent packets to be stored in the temporary

Which two actions can you take to allow the greatest number of pertinent packets to be stored in
the temporary buffer of Cisco IOS Embedded Packet Capture? (Choose two.)

PrepAway - Latest Free Exam Questions & Answers

A.
Specify the sampling interval.

B.
Specify the capture buffer type.

C.
Specify a reflexive ACL.

D.
Specify the minimum packet capture rate.

E.
Specify the packet size.

F.
Store the capture simultaneously onto an external memory card as the capture occurs.

21 Comments on “Which two actions can you take to allow the greatest number of pertinent packets to be stored in the temporary

  1. Snoopy says:

    Embedded Packet Capture (EPC) provides an embedded systems management facility that helps
    in tracing and troubleshooting packets. This feature allows network administrators to capture data
    packets flowing through, to, and from a Cisco device. The network administrator may define the
    capture buffer size and type (circular, or linear) and the maximum number of bytes of each packet
    to capture. The packet capture rate can be throttled using further administrative controls. For
    example, options allow for filtering the packets to be captured using an Access Control List and,
    optionally, further defined by specifying a maximum packet capture rate or by specifying a
    sampling interval.
    Reference. http://www.cisco.com/c/en/us/td/docs/ios-xml/ios/epc/configuration/xe-3s/asr1000/epcxe-3s-asr1000-book/nm-packet-capture-xe.html




    0



    0
  2. grwgrwgrwgrw says:

    The goal is to have MAX number of RELEVANT PACKETS in buffer.
    (B) Changing the buffer type doesn’t improve neither MAX number nor making sure they are relevant.
    (A) “Spreads” out the capturing, would improve the relevant aspect. Sounds correct to me.
    (E) Would increase the max number of packets the buffer can hold. Sound correct to me.




    0



    0
  3. Sergej says:

    B is correct:

    R1#monitor capture buffer EPC-BUFFER-1 size 512 max-size 1024 circular

    R1#sh monitor capture buffer all parameters
    Capture buffer EPC-BUFFER-1 (circular buffer)
    Buffer Size : 524288 bytes, Max Element Size : 1024 bytes, Packets : 0
    Allow-nth-pak : 0, Duration : 0 (seconds), Max packets : 0, pps : 0




    0



    0
  4. Mg says:

    Personally I like B and E …

    E for sure can increase the number of interesting packets if we are for example tracking DNS or probe packets of a max length length …

    B is not really increasing the number of interesting packets, but I thing that the guy writing the question based on that … A circular buffer can increase your chance of grab interesting packets, for example if you are waiting to capture something after a specific event.

    I think that the guy writing the question based it on the following text:

    http://www.cisco.com/c/en/us/support/docs/ios-nx-os-software/ios-embedded-packet-capture/116045-productconfig-epc-00.html

    Basic EPC Configuration

    Define a ‘capture buffer’, which is a temporary buffer that the captured packets are stored within. There are various options that can be selected when the buffer is defined; such as size, maxium packet size, and circular/linear:

    monitor capture buffer BUF size 2048 max-size 1518 linear




    1



    0

Leave a Reply