CCNA Network Infrastructure and Connectivity Practice Question
A network engineer is configuring a new Cisco Catalyst 9300 switch. The switch currently has all interfaces in VLAN 1, and the engineer needs to segment traffic for the Finance department. The engineer creates VLAN 20 and assigns it the name 'Finance'. Which command sequence is required to place access ports FastEthernet 1/0/1 through 1/0/10 into VLAN 20?
⚠ Common exam trap
Candidates often confuse trunk commands like 'switchport trunk allowed vlan' with access VLAN assignment, or forgetting to set the port mode to access, leading to dynamic mode behavior.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Switch(config)# interface range FastEthernet 1/0/1 - 10 Switch(config-if-range)# switchport mode access Switch(config-if-range)# switchport access vlan 20
To assign multiple access ports to a VLAN, you must enter interface range configuration, set the ports to access mode, and then assign the VLAN. The switchport mode access command ensures the ports operate as access ports, and switchport access vlan 20 assigns the VLAN. This is the standard and efficient way to configure multiple ports simultaneously on Cisco switches.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Switch(config)# interface range FastEthernet 1/0/1 - 10 Switch(config-if-range)# switchport mode access Switch(config-if-range)# switchport access vlan 20
Why this is correct
This sequence correctly enters interface range configuration mode, sets the ports to access mode, and assigns VLAN 20 as the access VLAN. On Cisco switches, access ports must be explicitly set to access mode if they are not already, and the switchport access vlan command assigns the VLAN. Without setting the mode, the ports might remain in dynamic mode, causing issues. This is the standard method to assign multiple ports to a VLAN efficiently.
- ✗
Switch(config)# vlan 20 Switch(config-vlan)# name Finance Switch(config-vlan)# exit Switch(config)# interface range FastEthernet 1/0/1 - 10 Switch(config-if-range)# switchport trunk allowed vlan 20
Why it's wrong here
The switchport trunk allowed vlan command is used on trunk ports to restrict which VLANs can traverse the trunk. Applying it to access ports does not assign them to a VLAN; it would cause an error or have no effect. The scenario requires access ports for end devices, not trunk ports. The correct approach is to use switchport access vlan, not trunk allowed vlan.
- ✗
Switch(config)# interface range FastEthernet 1/0/1 - 10 Switch(config-if-range)# switchport mode trunk Switch(config-if-range)# switchport trunk native vlan 20
Why it's wrong here
Configuring the ports as trunk ports with native VLAN 20 is incorrect because the requirement is to segment traffic for a department, which typically uses access ports. Trunk ports carry multiple VLANs and are used for switch-to-switch or switch-to-router links. Setting native VLAN 20 on a trunk does not place end devices into VLAN 20; untagged traffic would be in VLAN 20, but the ports would be trunks, not access ports.
- ✗
Switch(config)# vlan 20 Switch(config-vlan)# name Finance Switch(config-vlan)# interface FastEthernet 1/0/1 - 10 Switch(config-if-range)# switchport access vlan 20
Why it's wrong here
This sequence attempts to enter interface range configuration from within VLAN configuration mode, which is not valid. After creating the VLAN, you must exit to global configuration mode before entering interface configuration. Additionally, the switchport mode access command is missing, so the ports might not be in access mode. The correct method requires exiting VLAN config and then entering interface range config.
Visual reference
Go deeper
Related to this question
Learn chapter
Troubleshoot: NAT Not Translating Traffic
Key term
Switch
A switch is a networking device that connects devices on a local area network and uses MAC addresses to forward data only to the intended recipient.
Key term
Interface
An interface is a point of connection or interaction between two systems, devices, or software components that allows them to exchange information or signals.
About these practice questions
Courseiva writes every 200-301 question from scratch — 1,450 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-301 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-301 exam.