What is the correct order of steps to capture and analyze traffic on IOS-XE using the embedded packet capture feature, and in Wireshark to isolate a Layer 2 or Layer 3 fault?
Drag or tap steps into the slots.
Why this order
The correct order for embedded packet capture on IOS-XE is to first define the capture point with the desired interface and optional filter, then start the capture, stop it after capturing the needed traffic, and finally export the file for analysis in Wireshark. Option A accurately reflects this sequence. Option B fails because the capture must be defined before starting.
Option C fails because exporting should occur after stopping the capture. Option D fails because analysis is performed externally, not on the router.
Exam trap
Do not confuse the order of operations: you must define the capture point before starting, and you must stop the capture before exporting. Also, remember that analysis is done externally, not on the router itself.
Why candidates pick the wrong answer
Candidates might think that starting the capture is the first step, similar to enabling a debug, but EPC requires configuration first.
Candidates may think exporting is just copying a buffer that can be done anytime, but the capture must be stopped to finalize the file.
Candidates might assume that since the router has the capture, it can also analyze it, but IOS-XE lacks a full packet analyzer.