Courseiva
Networking and Protocols →mediumMultiple Choice

GSEC Networking and Protocols Practice Question

A network engineer is deploying a new IDS sensor on a switched segment and needs it to see all unicast traffic between two hosts on the same VLAN, including traffic not addressed to the sensor. The switch supports port mirroring. Which configuration should the engineer implement?

⚠ Common exam trap

The trap here is assuming that enabling promiscuous mode on a NIC is sufficient to capture all traffic on a switched network, when port mirroring or a network tap is actually required.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure a SPAN session on the switch, designating the sensor port as the destination and the VLAN or relevant ports as the source.

On a switch, unicast frames are forwarded only out the port leading to the destination MAC, so a sensor on an ordinary access port cannot see other hosts' conversations. A SPAN session with the sensor as the destination port and the monitored ports or VLAN as the source copies those frames to the sensor. This preserves normal forwarding while giving the IDS the full traffic view it needs.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create an EtherChannel bundle between the sensor and the switch, and enable trunking on the link.

    Why it's wrong here

    An EtherChannel trunk aggregates bandwidth and carries multiple VLANs, but it does not copy traffic from other ports. The sensor would only see frames the switch chooses to forward out that link, which excludes the unicast conversation between the two hosts. Aggregation and trunking change capacity and tagging, not visibility, so this does not meet the monitoring requirement.

  • ✓

    Configure a SPAN session on the switch, designating the sensor port as the destination and the VLAN or relevant ports as the source.

    Why this is correct

    A Switched Port Analyzer (SPAN) session copies frames from selected source ports or VLANs to a destination port, allowing the sensor to passively observe unicast traffic it would otherwise never receive. This is the standard, vendor-supported way to gain visibility on a switched segment without disrupting forwarding, and it satisfies the requirement that the sensor see traffic not addressed to it.

  • ✗

    Configure a SPAN session on the switch, designating the sensor port as the source and the monitored host ports as the destination.

    Why it's wrong here

    This reverses the roles of source and destination. In a SPAN configuration, the monitored traffic originates from the source ports or VLAN, and the copy is delivered to the destination port where the analysis device resides. Making the sensor the source would cause the switch to mirror whatever the sensor transmits to the hosts, which is the opposite of the required monitoring design.

  • ✗

    Enable promiscuous mode on the sensor NIC and connect it to an access port in the same VLAN as the two hosts.

    Why it's wrong here

    Promiscuous mode lets a NIC accept frames not addressed to its MAC, but on a switch each access port only receives unicast frames destined to the devices behind it plus broadcasts. The sensor would not see the unicast conversation between the two other hosts. Promiscuous mode alone cannot overcome the switch's forwarding table behavior; port mirroring or a tap is required.

Visual reference

Switch VLAN 10 Sales (192.168.10.0/24) PC-A PC-B VLAN 20 HR (192.168.20.0/24) PC-C PC-D Router VLANs isolate traffic — inter-VLAN routing requires a Layer 3 device

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

This GSEC question is part of Courseiva's 351-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.