Courseiva
easyMultiple Choice

200-201 Practice Question: A network administrator has configured a SPAN…

A network administrator has configured a SPAN port to send traffic to an intrusion detection system (IDS). However, the IDS is not seeing traffic from a specific VLAN. What is the most likely cause?

⚠ Common exam trap

Cisco often tests the misconception that SPAN automatically mirrors all VLANs on a trunk port, when in fact the administrator must explicitly specify which VLANs to monitor using the `vlan` keyword in the SPAN configuration.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The SPAN source does not include that VLAN.

A SPAN (Switched Port Analyzer) port copies traffic from specified source interfaces or VLANs to a destination port. If the IDS is not seeing traffic from a specific VLAN, the most likely cause is that the SPAN configuration does not include that VLAN as a source. The administrator must explicitly specify the VLAN(s) to monitor using the `monitor session` command with the `vlan` keyword; otherwise, traffic from that VLAN will not be forwarded to the IDS.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The SPAN source does not include that VLAN.

    Why this is correct

    A SPAN session only mirrors traffic from the sources explicitly defined in its configuration, so a VLAN omitted from the source list is never copied to the destination port. Since the IDS receives only mirrored frames, it cannot detect traffic from that VLAN until the source is amended to include it.

  • ✗

    The IDS interface is set to promiscuous mode.

    Why it's wrong here

    Promiscuous mode is required for a SPAN destination to accept copied frames; disabling it would drop all monitored traffic, not just one VLAN. It is the correct setting for capturing mirrored traffic, so it cannot explain a single missing VLAN.

  • ✗

    The SPAN destination port is in trunk mode.

    Why it's wrong here

    A SPAN destination port carries copied frames as ordinary untagged traffic; configuring it as a trunk does not add VLAN tags, so the IDS still cannot identify the missing VLAN. Trunking the destination is tempting because trunk links carry multiple VLANs, and it would be right if the IDS needed to receive tagged frames from several VLANs.

  • ✗

    The IDS is in inline mode.

    Why it's wrong here

    Inline mode describes a deployment where traffic passes through the sensor; it does not prevent a SPAN port from delivering copied frames. Inline placement is chosen deliberately when the device must block malicious traffic, not merely monitor it passively.

Visual reference

Switch VLAN 10 Sales (192.168.10.0/24) PC-A PC-B VLAN 20 HR (192.168.20.0/24) PC-C PC-D Router VLANs isolate traffic — inter-VLAN routing requires a Layer 3 device

About these practice questions

This 200-201 question is part of Courseiva's 968-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.