mediumMultiple Choice
350-401 Practice Question: Given the following SPAN configuration on a Cisco…
Given the following SPAN configuration on a Cisco IOS-XE switch:
monitor session 4 source interface GigabitEthernet1/0/6 tx monitor session 4 destination interface GigabitEthernet1/0/7
What does this configuration do?
⚠ Common exam trap
Cisco often tests the subtle difference between the default SPAN behavior (both ingress and egress) and the explicit 'tx' or 'rx' keywords, leading candidates to assume both directions are always monitored.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Only traffic transmitted from GigabitEthernet1/0/6 is copied to GigabitEthernet1/0/7.
The configuration uses the 'tx' keyword to specify that only traffic transmitted (egress) from GigabitEthernet1/0/6 should be copied to the destination interface GigabitEthernet1/0/7. Without the 'tx' keyword, the default behavior would be to monitor both ingress and egress traffic, but the explicit 'tx' limits the SPAN session to egress traffic only.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Only traffic transmitted from GigabitEthernet1/0/6 is copied to GigabitEthernet1/0/7.
Why this is correct
The 'tx' keyword in the monitor session command restricts copying to egress traffic only, meaning frames that the source interface GigabitEthernet1/0/6 transmits out of itself. The switch captures those frames and forwards a copy out of the destination interface GigabitEthernet1/0/7, which is configured as a SPAN destination. No ingress frames received on the source are considered, so the description is accurate.
- ✗
Both ingress and egress traffic on GigabitEthernet1/0/6 is copied to GigabitEthernet1/0/7.
Why it's wrong here
This statement would only be true if the source were configured with the 'both' keyword, which copies both received (ingress) and transmitted (egress) frames. Since the command uses 'tx', only frames the source interface transmits are copied, and any frames it receives are ignored. Thus the answer is incorrect because it overstates the coverage of the SPAN session.
- ✗
Traffic on GigabitEthernet1/0/7 is mirrored to GigabitEthernet1/0/6.
Why it's wrong here
SPAN operation is unidirectional: the source interface's traffic is mirrored to the destination interface, not the other way around. GigabitEthernet1/0/7 acts solely as a receive-only tap for the analyzer, and it never generates a mirrored copy of its own traffic toward GigabitEthernet1/0/6. The direction defined in the configuration clearly sets 1/0/6 as the source and 1/0/7 as the destination.
- ✗
The configuration is invalid because the destination interface must be in the same VLAN as the source.
Why it's wrong here
There is no requirement that a SPAN destination interface belong to the same VLAN as the source; the destination is typically configured as a passive monitor port and can be placed in any VLAN or even as an access port. The switch internally separates the monitored traffic and delivers it to the destination regardless of VLAN memberships. Therefore the configuration is valid, and the claim about VLAN matching is false.
Go deeper
Related to this question
Learn chapter
EIGRP: Basics and Advanced Configuration
Key term
SPAN and RSPAN
SPAN and RSPAN are Cisco features that copy network traffic from one or more ports to another port for analysis, with RSPAN extending this capability across multiple switches.
Key term
Network Visibility
Network visibility is the ability to see, monitor, and understand all traffic and devices on a network to ensure security, performance, and troubleshooting.
About these practice questions
This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.