Filtering a SPAN Session with a Host-Specific ACL
Refer to the exhibit. An engineer reported suspicious behavior in a server farm that is deployed on the 198.19.1.0/24 subnet. The traffic must be captured only from the server with the IP address of 198.19.1.19/24. The traffic analyzer is connected to the same switch as the server farm. Which configuration set captures the traffic? - 
Community Votes
100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
A SPAN session uses
filter access-groupwith an IP ACL; a host wildcard (0.0.0.0) restricts the mirror to one server, while a /24 permit or subnet mask would capture the whole segment.
To mirror only traffic from server 198.19.1.19, reference a SPAN ACL that permits that host with a wildcard mask; NX-OS SPAN filtering uses wildcard masking, not subnet masks.
Using a subnet mask instead of a wildcard mask in the SPAN ACL, or permitting the entire 198.19.1.0/24 subnet instead of the single host the question requires.
Community Discussion (6 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
The goal is to mirror only the traffic from server 198.19.1.19/24, not the whole subnet. A SPAN session can reference an IP ACL withfilter access-group to select mirrored packets. The correct ACL permits IP from host 198.19.1.19 using a host wildcard (0.0.0.0), so only that single server's frames reach the traffic analyzer; all other addresses in 198.19.1.0/24 are excluded.