Courseiva
mediumMultiple Choice

350-401 Practice Question: Runs the following command on Switch SW4: SW4#…

A network engineer runs the following command on Switch SW4:

SW4# show monitor session 4

Session 4 --------- Type : Local Session Source VLANs : RX Only : 10,20 Destination Ports : Gi1/0/25

Encapsulation      : Native

Ingress : Disabled

Based on this output, what can be concluded?

⚠ Common exam trap

Cisco often tests the distinction between 'RX Only', 'TX Only', and 'both' in SPAN sessions, and candidates mistakenly assume that a source VLAN automatically mirrors all traffic in both directions unless explicitly stated otherwise.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Only incoming traffic on VLANs 10 and 20 is mirrored to Gi1/0/25.

The output shows a local SPAN session with source VLANs 10 and 20 configured for RX Only, meaning only incoming traffic on those VLANs is mirrored to the destination port Gi1/0/25. The 'Ingress: Disabled' confirms that the destination port does not inject any traffic back into the switch, and 'Encapsulation: Native' indicates the mirrored frames are sent without an additional VLAN tag. Therefore, option A is correct because the session explicitly mirrors only received (incoming) traffic from VLANs 10 and 20.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Only incoming traffic on VLANs 10 and 20 is mirrored to Gi1/0/25.

    Why this is correct

    The SPAN session is configured with source VLANs 10 and 20 and an explicit direction of 'receive only' (Rx). As frames ingress on any port that is an active member of those VLANs, the switch copies them to the destination port Gi1/0/25, while leaving the normal forwarding path untouched. No outgoing or transmitted frames from those VLANs are captured because the monitor direction is limited to ingress traffic.

  • ✗

    Both incoming and outgoing traffic on VLANs 10 and 20 are mirrored.

    Why it's wrong here

    For an option to be 'both' (or full-duplex) traffic, the SPAN configuration would need to specify 'monitor session X source vlan 10,20 both' or 'Tx' and 'Rx' separately. Instead, the session restricts the mirroring to the Rx direction only, which captures frames received into the switch on those VLANs but does not copy frames that the switch transmits out of ports in those VLANs. Thus the claim that both directions are mirrored is false because the RX-only keyword explicitly excludes the egress direction.

  • ✗

    This is an RSPAN session using VLANs 10 and 20 as remote VLANs.

    Why it's wrong here

    An RSPAN (Remote SPAN) session would use a dedicated remote VLAN configured with 'remote-span' to carry mirrored traffic between switches. In this configuration, VLANs 10 and 20 are the source VLANs whose traffic is being monitored, not the transport VLAN for the SPAN session, and the session type is explicitly 'Local'. RSPAN requires the session to be defined as remote in its 'monitor session' syntax and the destination port to reside on a different switch, neither of which applies here.

  • ✗

    The destination port Gi1/0/25 is configured to receive mirrored traffic.

    Why it's wrong here

    The destination port in a SPAN session, Gi1/0/25, is an egress port that transmits the mirrored traffic to an attached analyzer or monitoring device. It is not a receiver; the switch port does not 'receive' mirrored traffic — it replicates outgoing frames from the source VLANs and sends them out of this port. If the port were configured to receive, it would be a source port or part of a different feature, but SPAN destination ports are always enabled to transmit the copied frames.

Visual reference

Switch VLAN 10 Sales (192.168.10.0/24) PC-A PC-B VLAN 20 HR (192.168.20.0/24) PC-C PC-D Router VLANs isolate traffic — inter-VLAN routing requires a Layer 3 device

About these practice questions

This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.