mediumMultiple Choice
CCNP Practice Question: Examine the following RSPAN configuration on a…
Examine the following RSPAN configuration on a Cisco switch:
vlan 200
name RSPAN_VLAN remote-span
monitor session 3 source interface GigabitEthernet1/0/5 both monitor session 3 destination remote vlan 200
interface GigabitEthernet1/0/10 switchport mode trunk switchport trunk allowed vlan 200
What is missing for RSPAN to function correctly across multiple switches?
⚠ Common exam trap
Cisco often tests the misconception that the monitor session number must be consistent across switches, but the trap here is that the RSPAN VLAN must be created on all intermediate switches with the 'remote-span' command, not just the source and destination switches.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The RSPAN VLAN 200 must be created on all switches that will forward the mirrored traffic.
For RSPAN to operate across multiple switches, the RSPAN VLAN (VLAN 200) must be created and configured with the 'remote-span' command on every switch that will forward the mirrored traffic. Without this, intermediate switches will not treat VLAN 200 as a special RSPAN VLAN, causing the mirrored frames to be dropped or mishandled. The configuration shown only creates the RSPAN VLAN on the local switch, but other switches in the path also need the VLAN and the 'remote-span' command to propagate the mirrored traffic correctly.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The RSPAN VLAN 200 must be created on all switches that will forward the mirrored traffic.
Why this is correct
RSPAN mirrors traffic onto a dedicated VLAN, and in order for those mirrored frames to be bridged from the source switch to the destination switch, every switch along the path must have VLAN 200 created and permitted on its trunks. This VLAN is special: it is configured with the 'remote-span' command so that it is not treated as a regular user data VLAN, and if it is missing or pruned on any intermediate switch, the analyzed traffic will simply be dropped, and the network analyzer will never see the mirrored frames.
- ✗
The destination remote vlan 200 command should include 'encapsulation replicate'.
Why it's wrong here
The 'encapsulation replicate' keyword is only meaningful on an RSPAN source session because it instructs the switch to preserve the original 802.1Q or ISL encapsulation when copying frames onto the RSPAN VLAN. A destination session that references 'remote vlan 200' only receives traffic from that VLAN and has no use for this keyword; the destination switch is not replicating any ingress encapsulation. Therefore, omitting it does not affect basic RSPAN functionality, and adding it to the destination configuration would not change the monitoring behavior.
- ✗
The source interface must be in trunk mode to monitor VLANs.
Why it's wrong here
The statement confuses a trunk's VLAN membership with the SPAN source ability to select a VLAN list. An SPAN source can be any physical port, whether access or trunk; an access port just monitors its single assigned access VLAN, while a trunk port can monitor all allowed VLANs or a specific VLAN subset using the 'source interface' command with VLAN keywords. In the given configuration, the source interface is valid in whatever mode it is currently in, and trunk mode is not a prerequisite for monitoring VLANs.
- ✗
The monitor session number must match on all switches.
Why it's wrong here
Monitor session numbers are entirely local to each switch and are merely identifiers for the local SPAN configuration. The source session number on the switch where traffic is captured and the destination session number on the switch where an analyzer is connected do not have to match; you simply configure each session independently on its own device. The only global consistency requirement is that the RSPAN VLAN (here VLAN 200) is identical and allowed on all participating switches.
Visual reference
About these practice questions
Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.