hardMultiple Choice
350-401 Practice Question: Needs to monitor traffic between two VLANs on a…
A network engineer needs to monitor traffic between two VLANs on a Cisco Catalyst 9300 switch. The engineer wants to capture all packets that traverse the switch between VLAN 10 and VLAN 20. The monitoring station is connected to port Gi1/0/24. Which configuration should the engineer use to capture this inter-VLAN traffic?
⚠ Common exam trap
Cisco often tests the misconception that inter-VLAN traffic must be captured by monitoring a physical port (like the SVI or a trunk), when in fact VLAN-based SPAN captures all traffic on the VLAN, including routed traffic, without needing to specify a particular interface.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure 'monitor session 1 source vlan 10 - 20 both' and 'monitor session 1 destination interface Gi1/0/24'.
Inter-VLAN traffic on a switch is routed by the switch virtual interface (SVI) and appears on the VLANs themselves. By using 'monitor session 1 source vlan 10 - 20 both', the SPAN session captures all packets entering or leaving VLANs 10 and 20, which includes the routed traffic between them. The destination interface Gi1/0/24 receives this mirrored traffic, allowing the monitoring station to see all inter-VLAN packets.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure 'monitor session 1 source interface Gi1/0/1 both' and 'monitor session 1 destination interface Gi1/0/24'.
Why it's wrong here
This command set restricts the SPAN source to a single physical port (Gi1/0/1) and copies both ingress and egress traffic from that port to the analyzer port. However, the requirement is to capture all inter-VLAN traffic between VLANs 10 and 20, which traverses the switch fabric and is not confined to any one access port. Inter-VLAN traffic is typically routed by the Switch Virtual Interface (SVI), not by a physical interface, so this configuration would miss the routed packets entirely and only see traffic on that one access link.
- ✓
Configure 'monitor session 1 source vlan 10 - 20 both' and 'monitor session 1 destination interface Gi1/0/24'.
Why this is correct
This is the correct approach because VLAN-based SPAN with 'source vlan 10 - 20 both' copies every frame that enters or leaves any port in those VLANs, including the routed traffic that is forwarded by the SVI between VLANs. The keyword 'both' ensures that both ingress (received by the VLAN) and egress (transmitted from the VLAN) traffic are mirrored, which is exactly what is needed to observe the complete inter-VLAN communication. The destination interface Gi1/0/24 is a local analyzer port on the same switch, so no remote encapsulation is required.
- ✗
Configure an RSPAN VLAN and use 'monitor session 1 source vlan 10 - 20' and 'monitor session 1 destination remote vlan 100'.
Why it's wrong here
RSPAN (Remote SPAN) is designed to transport mirrored traffic from a source switch to a monitoring station on a different switch by using a dedicated RSPAN VLAN. Here, the monitoring station and the source traffic are both on the same switch, so using an RSPAN VLAN would add unnecessary configuration complexity and require that VLAN to be carried across trunk links. Additionally, the command 'destination remote vlan 100' only specifies the RSPAN VLAN, not the actual analyzer port, so the traffic would not be delivered to the monitoring host without further configuration on the destination switch.
- ✗
Configure an ERSPAN session with source IP and destination IP.
Why it's wrong here
ERSPAN (Encapsulated Remote SPAN) tunnels mirrored packets over IP by adding a GRE header, which is only needed when the monitoring station is on a different IP subnet or reachable only through routed networks. This scenario involves a local switch and a directly connected analyzer port, so IP encapsulation is completely unnecessary and would introduce overhead and require valid source and destination IP addressing. Moreover, the configuration syntax for ERSPAN would not include a simple 'destination interface' statement; instead it uses 'destination ip', which does not match the requirement of mirroring to a local interface.
Visual reference
Go deeper
Related to this question
Learn chapter
EIGRP: Basics and Advanced Configuration
Key term
Switch Virtual Interface
A logical interface on a network switch that allows it to be managed and communicate with other devices using IP addresses.
Key term
SPAN and RSPAN
SPAN and RSPAN are Cisco features that copy network traffic from one or more ports to another port for analysis, with RSPAN extending this capability across multiple switches.
About these practice questions
One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.