Courseiva
hardMultiple Choice

350-401 Practice Question: Needs to monitor traffic from a specific VLAN…

A network engineer needs to monitor traffic from a specific VLAN (VLAN 100) on a Cisco Catalyst 9300 switch and send the mirrored traffic to a monitoring station on a different switch across a routed network. The engineer decides to use ERSPAN. Which configuration is required on the source switch?

⚠ Common exam trap

Cisco often tests the distinction between local SPAN, RSPAN, and ERSPAN, and the trap here is that candidates confuse RSPAN (which uses a remote VLAN and Layer 2 transport) with ERSPAN (which uses GRE and Layer 3 transport), leading them to select option C.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure 'monitor session 1 type erspan-source' and then 'source vlan 100' and 'destination ip 192.168.1.100'.

ERSPAN (Encapsulated Remote SPAN) is used to send mirrored traffic across a routed network by encapsulating the mirrored packets in GRE (Generic Routing Encapsulation) and sending them to a destination IP address. Option A correctly configures an ERSPAN source session with 'monitor session 1 type erspan-source', specifies the source VLAN 100, and sets the destination IP address of the monitoring station (192.168.1.100), which allows the traffic to traverse Layer 3 boundaries.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Configure 'monitor session 1 type erspan-source' and then 'source vlan 100' and 'destination ip 192.168.1.100'.

    Why this is correct

    This is the only configuration that actually creates an ERSPAN source session. The 'type erspan-source' keyword puts the session into ERSPAN mode, and the 'source vlan 100' selects the VLAN to mirror while 'destination ip 192.168.1.100' defines the remote IPv4 address of the collector or destination switch. ERSPAN encapsulates the mirrored packets in GRE with an IP outer header, enabling the traffic to traverse a routed Layer 3 network that local SPAN and RSPAN cannot cross.

  • ✗

    Configure 'monitor session 1 source vlan 100' and 'monitor session 1 destination interface Gi1/0/24'.

    Why it's wrong here

    This command set creates a standard local SPAN session, not ERSPAN. A local SPAN session copies selected VLAN traffic to a destination interface (Gi1/0/24) on the same switch and does not add any GRE/IP encapsulation. Because the analyzer must be attached to that specific local port, the mirrored traffic can never be carried across a routed IP network to a remote collector.

  • ✗

    Configure 'monitor session 1 source vlan 100' and 'monitor session 1 destination remote vlan 999'.

    Why it's wrong here

    These commands define an RSPAN source session, which is designed to carry mirrored traffic over a Layer 2 RSPAN VLAN (here VLAN 999) between switches in the same switched domain. RSPAN relies on a Layer 2 VLAN being trunked across the path, so it has no IP routing and cannot be used across a routed L3 network. The destination is a VLAN, not an IP address, which is immediately incompatible with the requirement of delivering traffic to a remote IP destination.

  • ✗

    Configure 'monitor session 1 source vlan 100' and 'monitor session 1 destination interface Gi1/0/24' and then 'monitor session 1 encapsulation replicate'.

    Why it's wrong here

    This is still a local SPAN session, even though 'encapsulation replicate' is added. The 'encapsulation replicate' option only instructs the switch to preserve the original frame's encapsulation tags (such as dot1Q or QinQ) on the mirrored copy when sending it to the destination interface; it does not create a GRE/IP tunnel. Therefore, the mirrored packets remain untunneled Layer 2 frames and cannot cross an IP routed network to reach 192.168.1.100.

Visual reference

Switch VLAN 10 Sales (192.168.10.0/24) PC-A PC-B VLAN 20 HR (192.168.20.0/24) PC-C PC-D Router VLANs isolate traffic — inter-VLAN routing requires a Layer 3 device

About these practice questions

One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.