VLAN misconfiguration is one of the top sources of connectivity failures in real networks and one of the most tested areas on the CCNA. These questions cover VLAN access ports, 802.1Q trunks, native VLANs, and router-on-a-stick or layer-3 switch inter-VLAN routing.
Start Scenario PracticeAn engineer is configuring RSPAN to monitor traffic from multiple switches in a data center. The monitoring station is connected to a central switch. The engineer has configured an RSPAN VLAN (VLAN 999) on all switches and set up the source sessions on the remote switches. However, the monitoring station receives no traffic. On the central switch, the engineer verifies that the RSPAN VLAN is active and that the destination session is configured. What is a likely missing configuration?
Explanation: RSPAN traffic is carried over an RSPAN VLAN that must be allowed on all trunk links between the source switches and the central switch. If the RSPAN VLAN (999) is not included in the allowed VLAN list on the trunk ports, the mirrored frames will be dropped, and the monitoring station will receive no traffic. This is the most likely missing configuration because the engineer verified the VLAN is active and the destination session is set, but did not check the trunk pruning.
A network engineer is configuring a Cisco switch for 802.1X port-based authentication. The switch is configured with a RADIUS server for authentication. The engineer wants to allow devices that fail 802.1X authentication to still access a limited guest VLAN. The engineer configures 'authentication port-control auto' and 'authentication host-mode multi-host' on the interface. However, when a non-802.1X-capable device is connected, the port remains in the unauthorized state and does not fall into the guest VLAN. What is missing?
Explanation: The 'authentication guest-vlan <vlan-id>' command is missing. This command explicitly defines the VLAN to which the port will assign devices that fail 802.1X authentication or are non-802.1X-capable. Without it, the switch has no configured fallback VLAN, so the port remains in the unauthorized state even with 'authentication port-control auto' and 'authentication host-mode multi-host' configured.
A network engineer runs the following command on Switch SW1: SW1# show interfaces gi0/1 switchport Name: Gi0/1 Switchport: Enabled Administrative Mode: trunk Operational Mode: trunk Administrative Trunking Encapsulation: dot1q Operational Trunking Encapsulation: dot1q Negotiation of Trunking: On Access Mode VLAN: 1 (default) Trunking Native Mode VLAN: 1 (default) Administrative Native VLAN tagging: enabled Voice VLAN: none Administrative private-vlan host-association: none Administrative private-vlan mapping: none Administrative private-vlan trunk native VLAN: none Administrative private-vlan trunk Native VLAN tagging: enabled Administrative private-vlan trunk encapsulation: dot1q Administrative private-vlan trunk normal VLANs: none Administrative private-vlan trunk private VLANs: none Operational private-vlan: none Trunking VLANs Enabled: ALL Pruning VLANs Enabled: 2-1001 Capture Mode Disabled Capture VLANs Allowed: ALL Based on this output, what can be concluded?
Explanation: The output shows 'Negotiation of Trunking: On', which indicates that Dynamic Trunking Protocol (DTP) is enabled on the interface. DTP is a Cisco proprietary protocol used to negotiate trunking between switches. Since the interface is in trunk mode and DTP is on, option B is correct.
A network engineer runs the following command on Switch SW1: SW1# show vlan brief VLAN Name Status Ports ---- -------------------------------- --------- ------------------------------- 1 default active Gi0/1, Gi0/2, Gi0/3 10 Sales active Gi0/4, Gi0/5 20 Engineering active Gi0/6, Gi0/7 1002 fddi-default act/unsup 1003 token-ring-default act/unsup 1004 fddinet-default act/unsup 1005 trnet-default act/unsup Based on this output, what can be concluded?
Explanation: The 'show vlan brief' output explicitly lists Gi0/1, Gi0/2, and Gi0/3 under VLAN 1 (default), confirming these interfaces are access ports assigned to VLAN 1. VLAN 1 is the default VLAN on Cisco switches, and all ports not explicitly configured otherwise belong to it.
Consider this VLAN configuration on a Cisco switch: vlan 10 name Sales vlan 20 name Engineering interface GigabitEthernet0/1 switchport mode trunk switchport trunk allowed vlan 10,20 What is missing if the switch needs to carry VLAN 30 traffic on this trunk?
Explanation: A trunk port only forwards traffic for VLANs that exist in the switch's VLAN database and are explicitly permitted in the allowed VLAN list. VLAN 30 is neither created (no 'vlan 30' command) nor added to the trunk's allowed list (missing 'switchport trunk allowed vlan add 30'), so the switch will drop any frames tagged with VLAN 30. Creating the VLAN and updating the allowed list ensures the trunk can forward VLAN 30 traffic.
+10 more scenario questions available
Practice all VLAN and Inter-VLAN Routing ScenariosVLAN misconfiguration is one of the top sources of connectivity failures in real networks and one of the most tested areas on the CCNA. These questions cover VLAN access ports, 802.1Q trunks, native VLANs, and router-on-a-stick or layer-3 switch inter-VLAN routing. These appear throughout the 350-401 and require you to apply your knowledge, not just recall facts.
Cisco doesn't publish an exact breakdown, but scenario-based questions (especially exhibit and command-output formats) make up a significant portion of the 350-401. Practicing each scenario type ensures you're ready for any format.
Yes. Courseiva provides free 350-401 scenario practice across all official exam domains. The platform includes scenario-based questions, command-output interpretation, topic-based practice, mock exams, and readiness tracking — no account required.
Launch a full VLAN and Inter-VLAN Routing Scenarios session with instant scoring and detailed explanations.
Start Scenario Practice →