Courseiva
hardMultiple Choice

350-401 Practice Question: Needs to monitor traffic between two VLANs on a…

A network engineer needs to monitor traffic between two VLANs on a Cisco Catalyst 9300 switch. The engineer wants to capture all packets that traverse the switch between VLAN 10 and VLAN 20. The monitoring station is connected to port Gi1/0/24. Which configuration should the engineer use to capture this inter-VLAN traffic?

⚠ Common exam trap

Cisco often tests the misconception that inter-VLAN traffic must be captured by monitoring a physical port (like the SVI or a trunk), when in fact VLAN-based SPAN captures all traffic on the VLAN, including routed traffic, without needing to specify a particular interface.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure 'monitor session 1 source vlan 10 - 20 both' and 'monitor session 1 destination interface Gi1/0/24'.

Inter-VLAN traffic on a switch is routed by the switch virtual interface (SVI) and appears on the VLANs themselves. By using 'monitor session 1 source vlan 10 - 20 both', the SPAN session captures all packets entering or leaving VLANs 10 and 20, which includes the routed traffic between them. The destination interface Gi1/0/24 receives this mirrored traffic, allowing the monitoring station to see all inter-VLAN packets.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure 'monitor session 1 source interface Gi1/0/1 both' and 'monitor session 1 destination interface Gi1/0/24'.

    Why it's wrong here

    This command set restricts the SPAN source to a single physical port (Gi1/0/1) and copies both ingress and egress traffic from that port to the analyzer port. However, the requirement is to capture all inter-VLAN traffic between VLANs 10 and 20, which traverses the switch fabric and is not confined to any one access port. Inter-VLAN traffic is typically routed by the Switch Virtual Interface (SVI), not by a physical interface, so this configuration would miss the routed packets entirely and only see traffic on that one access link.

  • ✓

    Configure 'monitor session 1 source vlan 10 - 20 both' and 'monitor session 1 destination interface Gi1/0/24'.

    Why this is correct

    This is the correct approach because VLAN-based SPAN with 'source vlan 10 - 20 both' copies every frame that enters or leaves any port in those VLANs, including the routed traffic that is forwarded by the SVI between VLANs. The keyword 'both' ensures that both ingress (received by the VLAN) and egress (transmitted from the VLAN) traffic are mirrored, which is exactly what is needed to observe the complete inter-VLAN communication. The destination interface Gi1/0/24 is a local analyzer port on the same switch, so no remote encapsulation is required.

  • ✗

    Configure an RSPAN VLAN and use 'monitor session 1 source vlan 10 - 20' and 'monitor session 1 destination remote vlan 100'.

    Why it's wrong here

    RSPAN (Remote SPAN) is designed to transport mirrored traffic from a source switch to a monitoring station on a different switch by using a dedicated RSPAN VLAN. Here, the monitoring station and the source traffic are both on the same switch, so using an RSPAN VLAN would add unnecessary configuration complexity and require that VLAN to be carried across trunk links. Additionally, the command 'destination remote vlan 100' only specifies the RSPAN VLAN, not the actual analyzer port, so the traffic would not be delivered to the monitoring host without further configuration on the destination switch.

  • ✗

    Configure an ERSPAN session with source IP and destination IP.

    Why it's wrong here

    ERSPAN (Encapsulated Remote SPAN) tunnels mirrored packets over IP by adding a GRE header, which is only needed when the monitoring station is on a different IP subnet or reachable only through routed networks. This scenario involves a local switch and a directly connected analyzer port, so IP encapsulation is completely unnecessary and would introduce overhead and require valid source and destination IP addressing. Moreover, the configuration syntax for ERSPAN would not include a simple 'destination interface' statement; instead it uses 'destination ip', which does not match the requirement of mirroring to a local interface.

Visual reference

Switch VLAN 10 Sales (192.168.10.0/24) PC-A PC-B VLAN 20 HR (192.168.20.0/24) PC-C PC-D Router VLANs isolate traffic — inter-VLAN routing requires a Layer 3 device

About these practice questions

One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.