CCNA Network Infrastructure and Connectivity Practice Question
A network technician is configuring a new Cisco switch and needs to secure unused switch ports to prevent unauthorized access. The technician decides to disable the ports and place them in an unused VLAN. Which two commands are required to accomplish this on each unused interface? (Choose two.)
⚠ Common exam trap
The trap here is thinking that setting the port to access mode or using trunk commands is sufficient to secure unused ports, when the key actions are disabling the port and placing it in an unused VLAN.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
shutdown
To secure unused ports, you should administratively disable them with the 'shutdown' command and assign them to an unused VLAN using 'switchport access vlan 999'. This prevents unauthorized devices from connecting and isolates any potential traffic. Setting the port to access mode is also good practice but not one of the two required commands in this scenario.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
shutdown
Why this is correct
The 'shutdown' command administratively disables the interface, preventing any traffic from being sent or received. This is a critical step to secure unused ports. When a port is shut down, it cannot be used for unauthorized access. This command is entered in interface configuration mode. It is one of the two required commands to disable the ports as specified in the scenario.
- ✗
switchport mode access
Why it's wrong here
Setting the port to access mode is a common step for access ports, but it does not disable the port or place it in an unused VLAN. While it is good practice to set access mode on unused ports, it alone does not secure them. The requirement is to disable the ports and assign them to an unused VLAN, so this command is not sufficient. It is often used in conjunction with other commands but is not one of the two required here.
- ✓
switchport access vlan 999
Why this is correct
Assigning the port to an unused VLAN (e.g., VLAN 999) ensures that even if the port is enabled, it is isolated from production traffic. This is a recommended security practice. The command 'switchport access vlan 999' places the port in VLAN 999, which should be an unused VLAN. Combined with 'shutdown', this secures the port. This is the second required command.
- ✗
switchport trunk allowed vlan none
Why it's wrong here
This command is used on trunk ports to remove all VLANs from the allowed list. It is not applicable to access ports, which are used for end devices. Unused ports should be configured as access ports and placed in an unused VLAN, not as trunks. Using this command on an access port would cause an error or have no effect. It does not disable the port or assign it to an unused VLAN.
- ✗
no switchport
Why it's wrong here
The 'no switchport' command converts a switch port into a routed port, which is used for Layer 3 functionality. This is not appropriate for unused ports; it would make the port a routed interface, potentially allowing IP configuration and traffic. It does not disable the port or place it in an unused VLAN. This command is used when you want to configure an interface as a Layer 3 port, which is not the goal here.
Visual reference
Go deeper
Related to this question
Learn chapter
IOS Debug Commands and Best Practices
Key term
VLAN
A VLAN logically segments a physical network into isolated broadcast domains without requiring separate physical switches.
Key term
VLAN
A VLAN (Virtual Local Area Network) is a logical grouping of network devices that behave as if they are on the same physical network segment, regardless of their actual physical location.
About these practice questions
This 200-301 question is part of Courseiva's 1,450-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-301 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-301 exam.