CCNA Switching and Network Access Practice Question
A network engineer is configuring a switch port for a new wireless access point that will support multiple SSIDs mapped to different VLANs. The AP will be powered by PoE and will tag traffic for each SSID. Which configuration on the switch port is most appropriate?
⚠ Common exam trap
The trap here is assuming an access port with voice VLAN can handle multiple SSIDs, or that allowing all VLANs is acceptable.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure the port as a trunk port, set the native VLAN to the AP management VLAN, and allow the SSID VLANs on the trunk.
For an access point supporting multiple SSIDs, the switch port should be configured as a trunk. The native VLAN is used for untagged management traffic from the AP, while each SSID's traffic is tagged with its corresponding VLAN. Allowing only the necessary VLANs on the trunk is a best practice. This configuration ensures proper segmentation and security.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure the port as a trunk port and set the native VLAN to VLAN 1, allowing all VLANs.
Why it's wrong here
Setting the native VLAN to VLAN 1 is a security risk and does not align with best practices. While allowing all VLANs would permit the SSID VLANs, it also allows unnecessary VLANs, which is inefficient and insecure. The AP management VLAN should be explicitly set as the native VLAN, not left as VLAN 1.
- ✓
Configure the port as a trunk port, set the native VLAN to the AP management VLAN, and allow the SSID VLANs on the trunk.
Why this is correct
This is the correct configuration for an AP supporting multiple SSIDs. The AP management traffic is typically untagged and placed in the native VLAN, while each SSID's traffic is tagged with its respective VLAN. The trunk allows multiple VLANs to traverse the link. This setup enables the AP to map each SSID to a different VLAN and tag frames accordingly.
- ✗
Configure the port as an access port in the management VLAN and use 802.1X authentication for the SSIDs.
Why it's wrong here
An access port can only carry one VLAN, so it cannot support multiple SSIDs mapped to different VLANs. 802.1X authentication is for network access control, not for VLAN tagging. This configuration would not allow the AP to separate traffic from different SSIDs into distinct VLANs.
- ✗
Configure the port as an access port in the management VLAN and enable voice VLAN for the SSIDs.
Why it's wrong here
An access port with voice VLAN is designed for IP phones, not for access points with multiple SSIDs. The voice VLAN feature allows only one additional VLAN for voice traffic. The AP needs to carry multiple VLANs (one per SSID), which requires a trunk. This configuration would not support multiple SSIDs on different VLANs.
Visual reference
Go deeper
Related to this question
Learn chapter
Network Management Approaches: Device, Cloud, Controller, Automation, and IaC
Key term
Switch
A switch is a networking device that connects devices on a local area network and uses MAC addresses to forward data only to the intended recipient.
Key term
VLAN
A VLAN logically segments a physical network into isolated broadcast domains without requiring separate physical switches.
About these practice questions
This 200-301 question is part of Courseiva's 1,450-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-301 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-301 exam.