SPAN Configuration for Traffic Baseline on Cisco Switch
Refer to the exhibit. An engineer must forward all web traffic sent from Client-SiteA to the monitoring server to build a baseline of expected traffic once a new Cisco Secure Web Appliance is deployed. What must be configured on the switch to meet the requirement? - 
Community Votes
100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The exam tests the ability to distinguish between traffic redirection services and traffic monitoring/mirroring technologies, highlighting the common trap of confusing WCCP (redirection) with SPAN (monitoring).
This question addresses the correct method for mirroring traffic to a monitoring server for baseline analysis before deploying a new Cisco Secure Web Appliance (WSA). It establishes that Source Port Access Control (SPAN) is the standard mechanism for local traffic mirroring on a single switch.
Candidates often select WCCP because the scenario mentions a 'Secure Web Appliance,' assuming WCCP is required for web filtering. However, the goal here is merely to build a traffic baseline, not to enforce policy or redirect live traffic through the appliance yet.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Correct answer: D — Configure SPAN (Switched Port Analyzer) to mirror the web traffic from Client-SiteA to the monitoring server. The requirement is to capture and analyze traffic to establish a baseline. SPAN is the native Cisco IOS feature designed specifically for copying network traffic from source ports or VLANs to a destination port where an analyzer (the monitoring server) is connected. Since the client site and the monitoring server are likely on the same switch infrastructure (as implied by the single-switch context of typical baselining questions), SPAN is the most direct and appropriate solution.Why the Other Options Are Wrong
Option A (ERSPAN) is used when the source and destination are in different Layer 2 domains or require encapsulation in GRE packets; it is unnecessary complexity for a local baseline. Option B (RSPAN) is used for remote spanning across multiple switches, which is not indicated here. Option C (WCCP) is used to dynamically redirect traffic to a service engine (like a WSA) for inspection/filtering. While the ultimate goal might be to deploy the WSA, the current step is purely observational ('build a baseline'), making WCCP incorrect as it would actively divert traffic rather than just monitor it.Community Comment Notes
Community consensus strongly supports SPAN. One user noted, "Monitoring on the same switch SPAN is correct," emphasizing the local nature of the task. Another user questioned why WCCP wasn't the answer, reflecting the common confusion between redirection and monitoring, but ultimately agreed with SPAN for general baselining purposes. The comments highlight that SPAN is the generic tool for visibility, whereas WCCP is for active service integration.Exam Strategy
When you see keywords like 'baseline', 'monitoring', 'analyze', or 'capture', think SPAN/RSPAN/ERSPAN. When you see 'redirect', 'filter', 'scan', or 'service insertion' for a specific appliance like WSA or ISR, think WCCP or PBR. Do not jump to WCCP just because a security appliance is mentioned; read the action verb carefully.
Frequently Asked Questions
Why can't I use WCCP to send traffic to the monitoring server?
WCCP is used to redirect live traffic to a service engine for processing (like filtering). It changes the traffic flow. SPAN is non-intrusive and copies traffic for observation only, which is required for baselining.
What is the difference between SPAN and RSPAN?
SPAN mirrors traffic within the same switch. RSPAN (Remote SPAN) requires a dedicated VLAN to carry mirrored traffic across multiple switches to a remote destination.