Courseiva

CCNA Network Infrastructure and Connectivity Practice Question

A network technician is configuring a new Cisco switch and needs to secure unused switch ports to prevent unauthorized access. The technician decides to disable the ports and place them in an unused VLAN. Which two commands are required to accomplish this on each unused interface? (Choose two.)

⚠ Common exam trap

The trap here is thinking that setting the port to access mode or using trunk commands is sufficient to secure unused ports, when the key actions are disabling the port and placing it in an unused VLAN.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

shutdown

To secure unused ports, you should administratively disable them with the 'shutdown' command and assign them to an unused VLAN using 'switchport access vlan 999'. This prevents unauthorized devices from connecting and isolates any potential traffic. Setting the port to access mode is also good practice but not one of the two required commands in this scenario.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    shutdown

    Why this is correct

    The 'shutdown' command administratively disables the interface, preventing any traffic from being sent or received. This is a critical step to secure unused ports. When a port is shut down, it cannot be used for unauthorized access. This command is entered in interface configuration mode. It is one of the two required commands to disable the ports as specified in the scenario.

  • ✗

    switchport mode access

    Why it's wrong here

    Setting the port to access mode is a common step for access ports, but it does not disable the port or place it in an unused VLAN. While it is good practice to set access mode on unused ports, it alone does not secure them. The requirement is to disable the ports and assign them to an unused VLAN, so this command is not sufficient. It is often used in conjunction with other commands but is not one of the two required here.

  • ✓

    switchport access vlan 999

    Why this is correct

    Assigning the port to an unused VLAN (e.g., VLAN 999) ensures that even if the port is enabled, it is isolated from production traffic. This is a recommended security practice. The command 'switchport access vlan 999' places the port in VLAN 999, which should be an unused VLAN. Combined with 'shutdown', this secures the port. This is the second required command.

  • ✗

    switchport trunk allowed vlan none

    Why it's wrong here

    This command is used on trunk ports to remove all VLANs from the allowed list. It is not applicable to access ports, which are used for end devices. Unused ports should be configured as access ports and placed in an unused VLAN, not as trunks. Using this command on an access port would cause an error or have no effect. It does not disable the port or assign it to an unused VLAN.

  • ✗

    no switchport

    Why it's wrong here

    The 'no switchport' command converts a switch port into a routed port, which is used for Layer 3 functionality. This is not appropriate for unused ports; it would make the port a routed interface, potentially allowing IP configuration and traffic. It does not disable the port or place it in an unused VLAN. This command is used when you want to configure an interface as a Layer 3 port, which is not the goal here.

Visual reference

Switch VLAN 10 Sales (192.168.10.0/24) PC-A PC-B VLAN 20 HR (192.168.20.0/24) PC-C PC-D Router VLANs isolate traffic — inter-VLAN routing requires a Layer 3 device

About these practice questions

This 200-301 question is part of Courseiva's 1,450-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-301 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-301 exam.