hardMultiple ChoiceObjective-mapped
300-410 Practice Question: An engineer configures ERSPAN on a Cisco router…
An engineer configures ERSPAN on a Cisco router to monitor traffic from a VRF. The mirrored traffic reaches the collector, but the source IP address in the ERSPAN header is the router's loopback, not the expected interface IP. What is the most likely cause?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The ERSPAN session does not specify a source IP address, so the router uses the loopback as the best source for the destination.
When configuring ERSPAN with a source interface in a VRF, the ERSPAN session uses the VRF's routing table to determine the source IP. If the 'ip address' of the source interface is not used, the router may use the loopback if it is the preferred source for the destination. The 'monitor session' command allows specifying the source IP explicitly; otherwise, the router selects based on routing.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The ERSPAN session does not specify a source IP address, so the router uses the loopback as the best source for the destination.
Why this is correct
Without an explicit source IP, the router uses the routing table to pick the source, often the loopback.
- ✗
The VRF has a default route pointing to the loopback, forcing all traffic to use that IP.
Why it's wrong here
The VRF routing does not force source IP selection; it is based on the egress interface for the destination.
- ✗
The ERSPAN session is configured with 'erspan-id' that overrides the source IP.
Why it's wrong here
The erspan-id is a session identifier, not a source IP.
- ✗
The collector expects the loopback IP for filtering, so the router automatically uses it.
Why it's wrong here
The router does not adapt to the collector's expectations.
Go deeper
Related to this question
Learn chapter
ACL-Based Traffic Filtering and Policy-Based Routing
Key term
MPLS Layer 3 VPN
A technology that uses Multiprotocol Label Switching to create secure, scalable virtual private networks that connect multiple sites at the network layer, where the service provider manages routing between customer sites.
About these practice questions
One of 1,966 original 300-410 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.