CCNA Switching and Network Access Practice Question
A network technician is connecting a new access switch to an existing distribution switch. The access switch will carry multiple VLANs, and the technician wants to ensure that the link is configured as a trunk and that only VLANs 10, 20, and 30 are allowed. Which command should be used on the access switch interface to restrict the allowed VLANs?
⚠ Common exam trap
Candidates often confuse the 'add' keyword with the base command; using 'add' would not remove the default all-VLANs allowance.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
switchport trunk allowed vlan 10,20,30
To restrict a trunk port to specific VLANs, the 'switchport trunk allowed vlan' command with a list of VLAN IDs is used. This replaces the default allowed list (all VLANs) with the specified ones. The 'add' keyword would append rather than replace, and other commands either set native VLAN or are for access ports. Thus, the correct command is the one that sets the allowed VLAN list directly.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
switchport access vlan 10,20,30
Why it's wrong here
This command is used to assign an access port to a single VLAN, not a trunk port, and it does not accept multiple VLANs. It would be invalid syntax for a list. The scenario requires a trunk port with multiple allowed VLANs, so this command is completely inappropriate. It would also change the port to access mode if not already, which is not desired.
- ✗
switchport trunk allowed vlan add 10,20,30
Why it's wrong here
The 'add' keyword appends the specified VLANs to the current allowed list rather than replacing it. If the trunk already allows all VLANs by default, using 'add' would not restrict the list; it would still allow all VLANs. The technician wants to restrict to only those three VLANs, so this command would not achieve the goal. It is used when you want to add VLANs to an existing allowed list without removing others.
- ✗
switchport trunk native vlan 10,20,30
Why it's wrong here
The native VLAN command specifies the VLAN for untagged traffic on a trunk, and it accepts only a single VLAN ID, not a list. This command is invalid syntax for multiple VLANs. Even if it were valid, it would not restrict allowed VLANs; it only sets the native VLAN. Therefore, it does not meet the requirement of allowing only VLANs 10, 20, and 30.
- ✓
switchport trunk allowed vlan 10,20,30
Why this is correct
This command explicitly sets the allowed VLAN list on a trunk port to only VLANs 10, 20, and 30. By default, all VLANs are allowed on a trunk, so this command is necessary to restrict traffic. It is the correct way to limit VLANs on a Cisco switch trunk interface. The other options either add to the existing list or are used for different purposes, making this the right choice.
Visual reference
Go deeper
Related to this question
Learn chapter
Copper and Fiber Cable Types, Distance Limits, and Interface Diagnostics
Key term
Trunk port
A trunk port is a switch port configured to carry traffic for multiple VLANs, using a tagging protocol to identify which VLAN each frame belongs to.
Key term
Interface
An interface is a point of connection or interaction between two systems, devices, or software components that allows them to exchange information or signals.
About these practice questions
Courseiva writes every 200-301 question from scratch — 1,450 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-301 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-301 exam.