Courseiva
mediumMultiple Choice

200-201 Practice Question: Configures a SPAN port to send traffic from a…

A network engineer configures a SPAN port to send traffic from a critical server to an IDS. After configuration, the IDS sees no traffic. What is the most likely issue?

⚠ Common exam trap

Cisco often tests the distinction between source and destination misconfiguration in SPAN, trapping candidates who assume the IDS must be in the same subnet (Option A) or that VLAN tagging (Option D) would block mirrored traffic, when the real issue is an incorrect source interface specification.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The monitor session source interface is incorrectly specified.

The most likely issue is that the monitor session source interface is incorrectly specified. SPAN (Switched Port Analyzer) requires the engineer to designate the correct source interface (the port connected to the critical server) and a destination interface (the port connected to the IDS). If the source interface is misconfigured—for example, pointing to the wrong switch port or using a VLAN instead of a specific port—the IDS will receive no mirrored traffic. This is a common configuration error when setting up local SPAN on Cisco switches.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The IDS is in a different subnet.

    Why it's wrong here

    A SPAN port mirrors frames at Layer 2, so subnet addressing is irrelevant; the IDS receives copies regardless of IP placement. The likely fault is the SPAN source/destination VLAN or port configuration. Subnet separation matters for routed traffic capture, such as placing a tap on a different segment, not for local port mirroring.

  • ✓

    The monitor session source interface is incorrectly specified.

    Why this is correct

    A SPAN session only mirrors traffic when its source interface matches the actual ingress or egress port carrying the server's frames. If the source is misconfigured, the switch replicates nothing, so the IDS receives no packets despite the destination being reachable.

  • ✗

    The SPAN destination interface is not connected to the IDS.

    Why it's wrong here

    A SPAN session forwards copies only once the destination port links up; an unconnected interface leaves the session administratively down, so no frames egress. It is tempting because a missing cable is a common cause of silent capture, and this would be the answer if the IDS showed link but no packets.

  • ✗

    The server is using VLAN tagging.

    Why it's wrong here

    VLAN tagging does not prevent a SPAN port from mirroring frames; the switch copies them with their tags intact, so the IDS would still receive traffic. Tagging is relevant when the sensor's interface must strip or interpret 802.1Q headers, a configuration concern rather than a cause of total traffic absence.

Visual reference

Switch VLAN 10 Sales (192.168.10.0/24) PC-A PC-B VLAN 20 HR (192.168.20.0/24) PC-C PC-D Router VLANs isolate traffic — inter-VLAN routing requires a Layer 3 device

About these practice questions

Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.