CCNA Switching and Network Access Practice Question
A port connected to an end-user PC should not send or expect VLAN tags from the endpoint. Which interface type is appropriate on the switch?
⚠ Common exam trap
Don't confuse the need for VLANs with the need for VLAN tagging. Access ports handle untagged traffic for single VLANs.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Access port
The appropriate interface type is an access port. In plain language, a normal user PC is expected to connect to one VLAN and send ordinary untagged Ethernet frames. The switch associates that traffic with the configured access VLAN. This is different from a trunk, which is designed to carry multiple VLANs and commonly uses tagging to preserve VLAN identity across the link. Routed ports are Layer 3 interfaces used for routing between VLANs, not for attaching a single end-user PC. Port-channel interfaces aggregate multiple physical links for redundancy and bandwidth, but they do not determine whether VLAN tagging is used; the underlying port mode (access or trunk) still applies. Therefore, access port is the only correct choice for an untagged, single-VLAN end-device connection.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Access port
Why this is correct
An access port is correct because it carries traffic for exactly one VLAN and forwards untagged frames, which is exactly what a PC's NIC expects. PCs do not generate 802.1Q VLAN tags, so an access port's behavior of stripping and expecting untagged data aligns with the end-device's native Ethernet operation. Furthermore, access ports do not transmit DTP (Dynamic Trunking Protocol) frames, preventing any unwanted trunk negotiation toward the PC.
- ✗
Trunk port
Why it's wrong here
A trunk port is wrong because it is designed to carry multiple VLANs over a single link using 802.1Q encapsulation. By default, a trunk port sends and expects tagged frames on all but the native VLAN, while a PC NIC sends only untagged frames and lacks the capability to interpret or generate VLAN tags. Additionally, trunk ports often run DTP, which a PC cannot participate in, potentially causing misconfiguration or protocol errors on the link.
When this WOULD be correct
If the exam question specified a scenario where multiple VLANs need to be transmitted between switches or to a router, and the focus was on inter-switch communication rather than end-user devices, then a trunk port would be the correct answer.
- ✗
Routed port
Why it's wrong here
A routed port is wrong because it is a Layer 3 interface with an IP address, intended for routing between different subnets or connecting to routers and Layer 3 switches. It does not provide VLAN-based switching services, spanning-tree participation, or untagged access to a single broadcast domain, which are the normal requirements for a PC's connection. Using a routed port would force the PC to be configured as a routed endpoint, which is not the standard design for an end-user workstation.
When this WOULD be correct
In a scenario where the question asks for the appropriate interface type for connecting two routers or Layer 3 devices that need to communicate without VLAN tagging, a routed port would be the correct answer, as it allows for direct IP communication between devices.
- ✗
Port-channel interface
Why it's wrong here
A port-channel interface is wrong because it is an EtherChannel logical bundle that combines multiple physical links into a single logical link for aggregation and redundancy. This configuration is intended for inter-switch connections or server NICs that support LACP or PAgP negotiation, whereas a typical end-user PC has a single NIC and no hardware or software support for these bundling protocols. Even if a PC were connected, the port-channel would require negotiation that the PC cannot perform.
When this WOULD be correct
If the exam question asked about configuring a switch to connect multiple access ports for redundancy and load balancing, where VLAN tagging is not required, then a port-channel interface would be the correct answer. The question would need to focus on link aggregation rather than VLAN handling.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The 200-301 exam frequently reuses these exact scenarios with slightly different constraints.
✓Access portCorrect answer▾
Why this is correct
An access port is correct because it carries traffic for exactly one VLAN and forwards untagged frames, which is exactly what a PC's NIC expects. PCs do not generate 802.1Q VLAN tags, so an access port's behavior of stripping and expecting untagged data aligns with the end-device's native Ethernet operation. Furthermore, access ports do not transmit DTP (Dynamic Trunking Protocol) frames, preventing any unwanted trunk negotiation toward the PC.
✗Trunk portWrong answer — click to see why▾
Why this is wrong here
A trunk port is designed to carry traffic for multiple VLANs using 802.1Q tagging, which is not expected from a standard PC. Using a trunk port for a PC would cause the switch to expect tagged frames, leading to communication failures.
★ When this WOULD be the correct answer
If the exam question specified a scenario where multiple VLANs need to be transmitted between switches or to a router, and the focus was on inter-switch communication rather than end-user devices, then a trunk port would be the correct answer.
Why candidates choose this
Students might confuse trunk ports with the ability to carry multiple VLANs, but they forget that end devices typically do not send or understand VLAN tags.
✗Routed portWrong answer — click to see why▾
Why this is wrong here
A routed port is a Layer 3 interface used for routing between VLANs or connecting to routers, not for connecting end-user PCs. It does not operate as a Layer 2 switchport and would not handle VLAN tagging as required.
★ When this WOULD be the correct answer
In a scenario where the question asks for the appropriate interface type for connecting two routers or Layer 3 devices that need to communicate without VLAN tagging, a routed port would be the correct answer, as it allows for direct IP communication between devices.
Why candidates choose this
Some may think a routed port can be used for any connection, but it lacks the Layer 2 switching functionality needed for a PC access connection.
✗Port-channel interfaceWrong answer — click to see why▾
Why this is wrong here
A port-channel interface is a logical bundling of multiple physical links for increased bandwidth and redundancy, not a single connection to an end-user PC. It is used between switches or to servers, not for typical PC access.
★ When this WOULD be the correct answer
If the exam question asked about configuring a switch to connect multiple access ports for redundancy and load balancing, where VLAN tagging is not required, then a port-channel interface would be the correct answer. The question would need to focus on link aggregation rather than VLAN handling.
Why candidates choose this
Students might associate port-channels with any type of connection, but they are not appropriate for a simple PC connection where no link aggregation is needed.
Analysis generated from the official 200-301blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Visual reference
Go deeper
Related to this question
Learn chapter
Configuring Switch Ports for Desktops, VoIP Phones, APs, IoT, and Virtualized Hosts
Key term
VLAN
A VLAN logically segments a physical network into isolated broadcast domains without requiring separate physical switches.
Key term
Redundancy
Redundancy is the practice of adding extra components or systems so that if one fails, another can take over without interruption.
About these practice questions
Courseiva writes every 200-301 question from scratch — 1,389 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-301 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-301 exam.