Courseiva
mediumMultiple Choice

CCNP Practice Question: Is troubleshooting a performance issue between…

A network engineer is troubleshooting a performance issue between two hosts connected to a Cisco Catalyst 3850 switch. The engineer wants to capture all traffic sent and received by Host A (Gi1/0/1) and send it to a monitoring station connected to Gi1/0/24. The engineer configures 'monitor session 1 source interface Gi1/0/1 both' and 'monitor session 1 destination interface Gi1/0/24'. However, the monitoring station receives only traffic sent by Host A, not traffic received. What is the most likely cause?

⚠ Common exam trap

Cisco often tests the misconception that SPAN captures all traffic regardless of VLAN membership, but the trap here is that the destination port's VLAN membership can cause the switch to drop egress copies due to loop prevention, even though the configuration appears correct.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The destination port is in the same VLAN as the source interface, causing the switch to drop the copied frames due to loop prevention.

The most likely cause is that the destination port (Gi1/0/24) is in the same VLAN as the source interface (Gi1/0/1). When a SPAN destination port resides in the same VLAN as the source, the switch may drop the copied egress frames to prevent a switching loop, because the destination port would otherwise re-inject the traffic back into the same VLAN. This behavior is specific to local SPAN on Catalyst switches, where the destination port must be in a different VLAN or configured as a trunk with only the monitoring VLAN allowed.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The source interface is configured as an access port, and the SPAN session cannot capture both directions on an access port.

    Why it's wrong here

    SPAN sources can be access or trunk ports, and the direction of capture is explicitly controlled with the 'both' keyword. An access port is fully supported for ingress, egress, or bidirectional monitoring, so the access-port mode does not prevent capturing both directions. The failure here is unrelated to the source port mode.

  • ✓

    The destination port is in the same VLAN as the source interface, causing the switch to drop the copied frames due to loop prevention.

    Why this is correct

    When the SPAN destination port resides in the same VLAN as the source interface, the switch forwards the replicated frames into the same broadcast domain, which can cause a bridging loop. To prevent this, loop prevention mechanisms—typically STP and hardware protections—drop those copied frames, resulting in no traffic arriving at the analyzer. The destination port must be placed in a different VLAN or made a dedicated SPAN destination to avoid this loop-avoidance drop.

  • ✗

    The 'monitor session 1 destination interface Gi1/0/24' command does not support egress SPAN; only ingress SPAN is allowed.

    Why it's wrong here

    The 'monitor session destination interface' command configures only where copies are sent; directionality (ingress, egress, or both) is a property of the source interface, not the destination. A SPAN session can simultaneously capture both directions on the source, and the destination port simply receives the replicated frames. Thus, the claim that egress SPAN is unsupported for the destination is a misinterpretation of the command's role.

  • ✗

    The engineer must also configure 'monitor session 1 filter ip' to capture both directions.

    Why it's wrong here

    The 'filter ip' keyword is an optional traffic filter that restricts SPAN copies to IP packets using an ACL or VLAN list; it does not enable or affect the direction of capture. Without it, the session copies all traffic on the source in the configured directions, including both ingress and egress. Therefore, adding this filter is not a required step for bidirectional monitoring and would narrow the capture scope.

Visual reference

Switch VLAN 10 Sales (192.168.10.0/24) PC-A PC-B VLAN 20 HR (192.168.20.0/24) PC-C PC-D Router VLANs isolate traffic — inter-VLAN routing requires a Layer 3 device

About these practice questions

This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.