Courseiva
mediumMultiple Choice

350-401 Practice Question: Is troubleshooting a security issue and needs to…

A network engineer is troubleshooting a security issue and needs to capture all traffic between two servers connected to different switches. The switches are connected via a trunk link. The monitoring station is connected to a third switch. The engineer decides to use RSPAN. Which of the following is a mandatory requirement for RSPAN to function correctly?

⚠ Common exam trap

Cisco often tests the misconception that the RSPAN VLAN must be pruned or set as native, when in fact the critical requirement is the 'remote-span' command on all switches to isolate the VLAN for mirroring purposes.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The RSPAN VLAN must be configured with the 'remote-span' command on all switches.

RSPAN (Remote SPAN) requires the RSPAN VLAN to be configured with the 'remote-span' command on all switches that participate in the RSPAN session. This command marks the VLAN as a dedicated RSPAN VLAN, preventing it from being used for normal data traffic and ensuring that the mirrored frames are flooded correctly across the trunk links to the destination switch. Without this command, the VLAN behaves as a regular data VLAN, which can cause forwarding loops or incorrect delivery of mirrored traffic.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The RSPAN VLAN must be configured as the native VLAN on all trunk ports.

    Why it's wrong here

    Setting the RSPAN VLAN to the native VLAN on trunks is incorrect because the native VLAN carries untagged traffic (typically for CDP, DTP, BPDUs, and management frames), while the RSPAN VLAN must carry only 802.1Q-tagged mirrored traffic across the network. If the RSPAN VLAN were the native VLAN, its frames would be sent without tags, defeating the isolation that makes RSPAN viable and risking the mirroring traffic being treated as normal data. There is no relationship between native VLAN selection and RSPAN operation; an RSPAN VLAN is simply an arbitrary VLAN ID designated with 'remote-span' and must be tagged on every trunk in the path.

  • ✗

    The RSPAN VLAN must be pruned from all trunk ports to prevent loops.

    Why it's wrong here

    Pruning the RSPAN VLAN from trunk ports is the opposite of what is required—RSPAN depends on the RSPAN VLAN being present and permitted on every trunk link between the source and destination switches. If this VLAN is pruned (via VTP pruning or an explicit 'allowed vlan remove' statement), the mirrored frames cannot traverse the switch fabric, and the remote monitoring session will fail. Loop prevention is handled by Spanning Tree Protocol on the RSPAN VLAN just like any other VLAN; pruning is a VLAN-allowed-list mechanism, not a loop-avoidance feature, and it would simply black-hole the RSPAN traffic.

  • ✓

    The RSPAN VLAN must be configured with the 'remote-span' command on all switches.

    Why this is correct

    The 'remote-span' command, issued in config-vlan mode, is the definitive way to designate a VLAN as an RSPAN VLAN on each switch that participates in the RSPAN domain. This command tells the switch not to use the VLAN for normal user traffic or routing, and it enables the switch to treat that VLAN as a transport for mirrored packets. Without this configuration on all switches in the path, the switches could erroneously flood or drop the RSPAN traffic, or attempt to use the VLAN for normal switching; the command guarantees consistent RSPAN behavior across intermediate and endpoint switches.

  • ✗

    The RSPAN VLAN must be the same as the management VLAN for the switches.

    Why it's wrong here

    The RSPAN VLAN and the management VLAN are logically independent and serve entirely different purposes: the management VLAN carries out-of-band control traffic (SSH, SNMP, syslog) to and from the switch's management interface, while the RSPAN VLAN is a dedicated Layer 2 carrier for mirrored traffic. Nothing in the IEEE 802.1Q or Cisco RSPAN implementation requires them to be the same, and making them the same would mix mirror traffic with control traffic, risking interoperation issues and compromising both security and monitor integrity. An RSPAN VLAN should be an unused, non-management VLAN with stable trunk permissions, not tied to the management VLAN.

Visual reference

Switch VLAN 10 Sales (192.168.10.0/24) PC-A PC-B VLAN 20 HR (192.168.20.0/24) PC-C PC-D Router VLANs isolate traffic — inter-VLAN routing requires a Layer 3 device

About these practice questions

One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.