mediumMultiple Choice
350-401 Practice Question: Is troubleshooting a performance issue between…
A network engineer is troubleshooting a performance issue between two hosts connected to a Cisco Catalyst 3850 switch. The engineer wants to capture all traffic sent and received by Host A (Gi1/0/1) and send it to a monitoring station connected to Gi1/0/24. The engineer configures 'monitor session 1 source interface Gi1/0/1 both' and 'monitor session 1 destination interface Gi1/0/24'. However, the monitoring station receives only traffic sent by Host A, not traffic received. What is the most likely cause?
⚠ Common exam trap
Cisco often tests the misconception that SPAN captures all traffic regardless of VLAN membership, but the trap here is that the destination port's VLAN membership can cause the switch to drop egress copies due to loop prevention, even though the configuration appears correct.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The destination port is in the same VLAN as the source interface, causing the switch to drop the copied frames due to loop prevention.
The most likely cause is that the destination port (Gi1/0/24) is in the same VLAN as the source interface (Gi1/0/1). When a SPAN destination port resides in the same VLAN as the source, the switch may drop the copied egress frames to prevent a switching loop, because the destination port would otherwise re-inject the traffic back into the same VLAN. This behavior is specific to local SPAN on Catalyst switches, where the destination port must be in a different VLAN or configured as a trunk with only the monitoring VLAN allowed.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The source interface is configured as an access port, and the SPAN session cannot capture both directions on an access port.
Why it's wrong here
SPAN sources can be access or trunk ports, and the direction of capture is explicitly controlled with the 'both' keyword. An access port is fully supported for ingress, egress, or bidirectional monitoring, so the access-port mode does not prevent capturing both directions. The failure here is unrelated to the source port mode.
- ✓
The destination port is in the same VLAN as the source interface, causing the switch to drop the copied frames due to loop prevention.
Why this is correct
When the SPAN destination port resides in the same VLAN as the source interface, the switch forwards the replicated frames into the same broadcast domain, which can cause a bridging loop. To prevent this, loop prevention mechanisms—typically STP and hardware protections—drop those copied frames, resulting in no traffic arriving at the analyzer. The destination port must be placed in a different VLAN or made a dedicated SPAN destination to avoid this loop-avoidance drop.
- ✗
The 'monitor session 1 destination interface Gi1/0/24' command does not support egress SPAN; only ingress SPAN is allowed.
Why it's wrong here
The 'monitor session destination interface' command configures only where copies are sent; directionality (ingress, egress, or both) is a property of the source interface, not the destination. A SPAN session can simultaneously capture both directions on the source, and the destination port simply receives the replicated frames. Thus, the claim that egress SPAN is unsupported for the destination is a misinterpretation of the command's role.
- ✗
The engineer must also configure 'monitor session 1 filter ip' to capture both directions.
Why it's wrong here
The 'filter ip' keyword is an optional traffic filter that restricts SPAN copies to IP packets using an ACL or VLAN list; it does not enable or affect the direction of capture. Without it, the session copies all traffic on the source in the configured directions, including both ingress and egress. Therefore, adding this filter is not a required step for bidirectional monitoring and would narrow the capture scope.
Visual reference
Go deeper
Related to this question
Learn chapter
QoS and Network Performance Management
Key term
Network Visibility
Network visibility is the ability to see, monitor, and understand all traffic and devices on a network to ensure security, performance, and troubleshooting.
Key term
SPAN and RSPAN
SPAN and RSPAN are Cisco features that copy network traffic from one or more ports to another port for analysis, with RSPAN extending this capability across multiple switches.
About these practice questions
This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.