A network administrator received reports that a 40Gb connection is saturated. The only server the administrator can use for data collection in that location has a 10Gb connection to the network. Which of the following is the best method to use on the server to determine the source of the saturation?
Correct Answer: C
Flow data is the most effective method for identifying network traffic patterns and pinpointing the source of saturation on a network connection. It provides a high-level overview of traffic flow without requiring full packet capture, which would be impractical on a 10Gb connection when the saturation occurs on a 40Gb link.
Flow data allows the administrator to analyze metadata about the traffic, such as source and destination IP addresses, ports, and protocols, which can help determine the cause of the congestion.