GSEC Network Security Devices Practice Question
A security analyst needs to capture raw packet data from a high-speed core switch to analyze suspicious east-west traffic movements without interrupting production data flows. Which device feature should be configured on the switch?
⚠ Common exam trap
Candidates often select 'port forwarding' or 'VLAN trunking'. These are network connectivity configurations that do not provide the packet duplication functionality required for security monitoring.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Switched Port Analyzer (SPAN) or port mirroring
A Switched Port Analyzer (SPAN), also known as port mirroring, duplicates ingress and egress traffic from specified source ports or VLANs and forwards the copied frames to a dedicated monitoring port connected to a packet analyzer or intrusion detection sensor without disrupting production flows.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Network Address Translation (NAT) overloading
Why it's wrong here
NAT overloading maps multiple private IP addresses to a single public IP address using distinct source ports to facilitate internet access. It alters packet headers and is used for routing, not for capturing or duplicating traffic for security analysis.
- ✓
Switched Port Analyzer (SPAN) or port mirroring
Why this is correct
SPAN copies frames from selected switch ports or VLANs to a monitoring port, giving passive visibility of east-west traffic without inline interception. This satisfies the constraint of capturing raw packets while production flows continue uninterrupted.
- ✗
Virtual Router Redundancy Protocol (VRRP) failover
Why it's wrong here
VRRP provides default gateway redundancy by electing a master router, so it addresses availability rather than traffic visibility. It is configured where hosts need a resilient next-hop address, whereas capturing raw packets requires port mirroring or a SPAN/TAP configuration on the switch.
- ✗
Dynamic Host Configuration Protocol (DHCP) snooping
Why it's wrong here
DHCP snooping filters rogue DHCP server offers by inspecting DHCP messages on untrusted ports; it does not copy frames to a monitoring destination. It is deployed to prevent DHCP spoofing and starvation attacks, not to mirror east-west traffic for packet capture.
Visual reference
About these practice questions
Courseiva writes every GSEC question from scratch — 351 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.