easyMultiple Choice
350-401 Practice Question: Is monitoring traffic from a server connected to…
A network engineer is monitoring traffic from a server connected to a Cisco Catalyst 3850 switch. The engineer configures a SPAN session with source interface Gi1/0/1 and destination interface Gi1/0/24. The monitoring station receives traffic, but the engineer notices that the destination port is not forwarding any normal traffic. What is the most likely reason?
⚠ Common exam trap
Cisco often tests the misconception that a SPAN destination port can still forward normal traffic or that it requires a specific switchport mode (trunk or access), when in fact the switch automatically disables all normal switching on that port.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The destination port is automatically configured as a SPAN destination port, which disables normal switching on that port.
When a port is configured as a SPAN destination port, the switch automatically disables normal switching (Layer 2 forwarding) on that interface. This is because the destination port is dedicated to receiving mirrored copies of traffic from the source port and forwarding them to an external monitoring device. As a result, the destination port will not forward any normal traffic, which explains the engineer's observation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The destination port is automatically configured as a SPAN destination port, which disables normal switching on that port.
Why this is correct
In a SPAN configuration, the switch automatically reconfigures the designated destination port as a SPAN destination port. This places the port into a specialized monitoring mode where it no longer participates in the normal Layer 2 forwarding process, meaning it will not forward unicast or broadcast frames destined for end stations. Consequently, any device connected to that port will lose normal network connectivity and only receive the copied traffic from the SPAN session. This automatic behavior is a core characteristic of Cisco switches and is the direct cause of the observed symptom.
- ✗
The destination port must be configured as a trunk port to forward SPAN traffic.
Why it's wrong here
The claim that the destination port must be a trunk is incorrect because the SPAN destination port's role is independent of its VLAN encapsulation type. Even if the port were configured as a trunk, it would still be placed into the SPAN monitoring state, which disables normal switching for all VLANs, including tagged traffic. The purpose of using a trunk in SPAN is only to preserve VLAN tags on the mirrored frames for analysis, not to enable or facilitate normal forwarding. Therefore, the lack of normal connectivity is not due to the absence of trunk configuration.
- ✗
The destination port must be configured as an access port to forward SPAN traffic.
Why it's wrong here
Similarly, configuring the destination port as an access port does not restore or enable normal forwarding. The SPAN destination configuration overrides the port's access or trunk settings, and the switch disables all normal switching on that port regardless of its mode. Whether the port is an access port or a trunk, the result is identical: it becomes a dedicated monitor port and will not forward traffic for connected hosts. Thus, the issue is not that the port is an access port; it is that the port is now a SPAN destination.
- ✗
The destination port is in an err-disabled state due to a loop.
Why it's wrong here
The err-disabled state is a switch security/protection feature triggered by events like loop detection, UDLD failures, or port-security violations, not by SPAN configuration. When a port is err-disabled, it is typically shut down and shows 'err-disabled' in the show interfaces output, and the switch logs the cause. In this scenario, the port is likely up and receiving mirrored packets, but the user perceives it as non-functional because normal traffic is not being forwarded. SPAN does not cause err-disabled; it places the port in a special monitor mode, which is a completely different operational state.
Go deeper
Related to this question
Learn chapter
EtherChannel and Advanced Switching Technologies
Key term
Network Visibility
Network visibility is the ability to see, monitor, and understand all traffic and devices on a network to ensure security, performance, and troubleshooting.
Key term
SPAN and RSPAN
SPAN and RSPAN are Cisco features that copy network traffic from one or more ports to another port for analysis, with RSPAN extending this capability across multiple switches.
About these practice questions
One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.