Courseiva
easyMultiple Choice

CCNP Practice Question: Is monitoring traffic from a server connected to…

A network engineer is monitoring traffic from a server connected to a Cisco Catalyst 3850 switch. The engineer configures a SPAN session with source interface Gi1/0/1 and destination interface Gi1/0/24. The monitoring station receives traffic, but the engineer notices that the destination port is not forwarding any normal traffic. What is the most likely reason?

⚠ Common exam trap

Cisco often tests the misconception that a SPAN destination port can still forward normal traffic or that it requires a specific switchport mode (trunk or access), when in fact the switch automatically disables all normal switching on that port.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The destination port is automatically configured as a SPAN destination port, which disables normal switching on that port.

When a port is configured as a SPAN destination port, the switch automatically disables normal switching (Layer 2 forwarding) on that interface. This is because the destination port is dedicated to receiving mirrored copies of traffic from the source port and forwarding them to an external monitoring device. As a result, the destination port will not forward any normal traffic, which explains the engineer's observation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The destination port is automatically configured as a SPAN destination port, which disables normal switching on that port.

    Why this is correct

    In a SPAN configuration, the switch automatically reconfigures the designated destination port as a SPAN destination port. This places the port into a specialized monitoring mode where it no longer participates in the normal Layer 2 forwarding process, meaning it will not forward unicast or broadcast frames destined for end stations. Consequently, any device connected to that port will lose normal network connectivity and only receive the copied traffic from the SPAN session. This automatic behavior is a core characteristic of Cisco switches and is the direct cause of the observed symptom.

  • ✗

    The destination port must be configured as a trunk port to forward SPAN traffic.

    Why it's wrong here

    The claim that the destination port must be a trunk is incorrect because the SPAN destination port's role is independent of its VLAN encapsulation type. Even if the port were configured as a trunk, it would still be placed into the SPAN monitoring state, which disables normal switching for all VLANs, including tagged traffic. The purpose of using a trunk in SPAN is only to preserve VLAN tags on the mirrored frames for analysis, not to enable or facilitate normal forwarding. Therefore, the lack of normal connectivity is not due to the absence of trunk configuration.

  • ✗

    The destination port must be configured as an access port to forward SPAN traffic.

    Why it's wrong here

    Similarly, configuring the destination port as an access port does not restore or enable normal forwarding. The SPAN destination configuration overrides the port's access or trunk settings, and the switch disables all normal switching on that port regardless of its mode. Whether the port is an access port or a trunk, the result is identical: it becomes a dedicated monitor port and will not forward traffic for connected hosts. Thus, the issue is not that the port is an access port; it is that the port is now a SPAN destination.

  • ✗

    The destination port is in an err-disabled state due to a loop.

    Why it's wrong here

    The err-disabled state is a switch security/protection feature triggered by events like loop detection, UDLD failures, or port-security violations, not by SPAN configuration. When a port is err-disabled, it is typically shut down and shows 'err-disabled' in the show interfaces output, and the switch logs the cause. In this scenario, the port is likely up and receiving mirrored packets, but the user perceives it as non-functional because normal traffic is not being forwarded. SPAN does not cause err-disabled; it places the port in a special monitor mode, which is a completely different operational state.

About these practice questions

One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.