Courseiva

CCNA Network Infrastructure and Connectivity Practice Question

A network engineer is configuring a new Cisco Catalyst 9300 switch. The switch currently has all interfaces in VLAN 1, and the engineer needs to segment traffic for the Finance department. The engineer creates VLAN 20 and assigns it the name 'Finance'. Which command sequence is required to place access ports FastEthernet 1/0/1 through 1/0/10 into VLAN 20?

⚠ Common exam trap

Candidates often confuse trunk commands like 'switchport trunk allowed vlan' with access VLAN assignment, or forgetting to set the port mode to access, leading to dynamic mode behavior.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Switch(config)# interface range FastEthernet 1/0/1 - 10 Switch(config-if-range)# switchport mode access Switch(config-if-range)# switchport access vlan 20

To assign multiple access ports to a VLAN, you must enter interface range configuration, set the ports to access mode, and then assign the VLAN. The switchport mode access command ensures the ports operate as access ports, and switchport access vlan 20 assigns the VLAN. This is the standard and efficient way to configure multiple ports simultaneously on Cisco switches.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Switch(config)# interface range FastEthernet 1/0/1 - 10 Switch(config-if-range)# switchport mode access Switch(config-if-range)# switchport access vlan 20

    Why this is correct

    This sequence correctly enters interface range configuration mode, sets the ports to access mode, and assigns VLAN 20 as the access VLAN. On Cisco switches, access ports must be explicitly set to access mode if they are not already, and the switchport access vlan command assigns the VLAN. Without setting the mode, the ports might remain in dynamic mode, causing issues. This is the standard method to assign multiple ports to a VLAN efficiently.

  • ✗

    Switch(config)# vlan 20 Switch(config-vlan)# name Finance Switch(config-vlan)# exit Switch(config)# interface range FastEthernet 1/0/1 - 10 Switch(config-if-range)# switchport trunk allowed vlan 20

    Why it's wrong here

    The switchport trunk allowed vlan command is used on trunk ports to restrict which VLANs can traverse the trunk. Applying it to access ports does not assign them to a VLAN; it would cause an error or have no effect. The scenario requires access ports for end devices, not trunk ports. The correct approach is to use switchport access vlan, not trunk allowed vlan.

  • ✗

    Switch(config)# interface range FastEthernet 1/0/1 - 10 Switch(config-if-range)# switchport mode trunk Switch(config-if-range)# switchport trunk native vlan 20

    Why it's wrong here

    Configuring the ports as trunk ports with native VLAN 20 is incorrect because the requirement is to segment traffic for a department, which typically uses access ports. Trunk ports carry multiple VLANs and are used for switch-to-switch or switch-to-router links. Setting native VLAN 20 on a trunk does not place end devices into VLAN 20; untagged traffic would be in VLAN 20, but the ports would be trunks, not access ports.

  • ✗

    Switch(config)# vlan 20 Switch(config-vlan)# name Finance Switch(config-vlan)# interface FastEthernet 1/0/1 - 10 Switch(config-if-range)# switchport access vlan 20

    Why it's wrong here

    This sequence attempts to enter interface range configuration from within VLAN configuration mode, which is not valid. After creating the VLAN, you must exit to global configuration mode before entering interface configuration. Additionally, the switchport mode access command is missing, so the ports might not be in access mode. The correct method requires exiting VLAN config and then entering interface range config.

Visual reference

Switch VLAN 10 Sales (192.168.10.0/24) PC-A PC-B VLAN 20 HR (192.168.20.0/24) PC-C PC-D Router VLANs isolate traffic — inter-VLAN routing requires a Layer 3 device

About these practice questions

Courseiva writes every 200-301 question from scratch — 1,450 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-301 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-301 exam.