hardMultiple Choice
350-401 Practice Question: An engineer is configuring RSPAN to monitor…
An engineer is configuring RSPAN to monitor traffic from multiple switches in a data center. The monitoring station is connected to a central switch. The engineer has configured an RSPAN VLAN (VLAN 999) on all switches and set up the source sessions on the remote switches. However, the monitoring station receives no traffic. On the central switch, the engineer verifies that the RSPAN VLAN is active and that the destination session is configured. What is a likely missing configuration?
⚠ Common exam trap
Cisco often tests the subtle requirement that the RSPAN VLAN must be explicitly permitted on trunk ports, as candidates may assume that a VLAN created and active on both ends is automatically carried across a trunk.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The trunk ports between the switches do not have the RSPAN VLAN (999) in their allowed VLAN list.
RSPAN traffic is carried over an RSPAN VLAN that must be allowed on all trunk links between the source switches and the central switch. If the RSPAN VLAN (999) is not included in the allowed VLAN list on the trunk ports, the mirrored frames will be dropped, and the monitoring station will receive no traffic. This is the most likely missing configuration because the engineer verified the VLAN is active and the destination session is set, but did not check the trunk pruning.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The trunk ports between the switches do not have the RSPAN VLAN (999) in their allowed VLAN list.
Why this is correct
The trunk ports between the switches do not have the RSPAN VLAN (999) in their allowed VLAN list. This is the root cause because RSPAN relies on a dedicated VLAN to carry mirrored traffic across the Layer 2 fabric. Even if the VLAN is active on each switch, an ISL or 802.1Q trunk will prune or drop any VLAN not explicitly permitted in its allowed list. Since the default allowed list typically includes only VLANs 1-1005, a higher VLAN such as 999 may be silently omitted. Without VLAN 999 allowed on every trunk in the path, the mirrored frames never reach the destination switch, so the analyzer sees no traffic.
- ✗
The destination session on the central switch is configured with 'monitor session 2 destination remote vlan 999' instead of 'monitor session 2 destination interface Gi1/0/1'.
Why it's wrong here
The destination session on the RSPAN destination switch should use 'monitor session 2 source remote vlan 999' to receive mirrored frames from the RSPAN VLAN, combined with 'monitor session 2 destination interface Gi1/0/1' to send those frames to the local analyzer port. The command 'monitor session 2 destination remote vlan 999' shown in the option is actually the syntax used on the source switch to direct mirrored traffic into the RSPAN VLAN, not on the destination switch. Since the question explicitly states that the destination session is configured, this misconfiguration cannot be the missing piece; the failure must lie in the Layer 2 path between the switches.
- ✗
The source sessions on the remote switches are configured with 'monitor session 1 source vlan 100' but the destination is not set to 'remote vlan 999'.
Why it's wrong here
A valid RSPAN source session must include both a monitored source and an output destination of 'remote vlan 999' — for example, 'monitor session 1 source vlan 100' followed by 'monitor session 1 destination remote vlan 999'. Without the destination remote clause, the session would not inject mirrored frames into the RSPAN VLAN and would instead behave as a local SPAN session. However, the question states that the source sessions are already configured, implying they have the required destination remote configuration. Therefore, the missing piece is not an incomplete source session but rather the trunk allowed list on the link connecting the source switches to the central switch.
- ✗
The RSPAN VLAN is not created as a remote SPAN VLAN; it must be configured with 'remote-span' command.
Why it's wrong here
Incorrect; the 'remote-span' command is used on the VLAN to designate it as an RSPAN VLAN, but the question says the VLAN is active, implying it is configured. However, this is a common missing step, but the most likely missing configuration is the trunk allowance.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.