CCNA Switching and Network Access Practice Question
A switch displays this output:
Port Name Status Vlan Fa0/1 connected 10 Fa0/2 connected 10 Fa0/24 connected trunk
Which port should be checked first if a user in VLAN 20 cannot reach the distribution switch over the uplink?
⚠ Common exam trap
Don't confuse access ports with trunk ports; only trunk ports can carry multiple VLANs.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Fa0/24
If users in VLAN 20 must cross the uplink, the trunk port is the first place to verify allowed VLANs and tagging.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Fa0/1
Why it's wrong here
Fa0/1 is configured as an access port assigned to VLAN 10, so it carries untagged frames for VLAN 10 only. A client in VLAN 20 would have frames tagged (or PVID-assigned) for VLAN 20, which Fa0/1 cannot forward upstream. Since Fa0/1 is not the uplink trunk, inspecting it does not help isolate why VLAN 20 lacks connectivity to the distribution switch.
When this WOULD be correct
In a different scenario where the question specifies that VLAN 10 is experiencing connectivity issues or misconfigurations affecting users on that VLAN, checking Fa0/1 would be appropriate to troubleshoot the problem.
- ✗
Fa0/2
Why it's wrong here
Fa0/2 also resides in VLAN 10 as an access port, making it redundant to Fa0/1 for this diagnosis. Even if Fa0/2's link were active, its PVID of 10 would cause it to drop or ignore any VLAN 20 traffic due to improper VLAN membership. The relevant path to the distribution switch is the trunk on Fa0/24, not another access port in an unrelated VLAN.
When this WOULD be correct
In a scenario where the question specifies that VLAN 20 is configured on Fa0/2 and the user is attempting to reach a device on VLAN 20, checking Fa0/2 would be the correct action to troubleshoot connectivity issues related to that specific VLAN.
- ✓
Fa0/24
Why this is correct
Fa0/24 is the only port configured as a trunk, which is necessary for carrying traffic from multiple VLANs, including VLAN 20, to the distribution switch over the uplink. When a user in VLAN 20 cannot reach the distribution switch, this trunk port represents the primary path for inter-VLAN communication upstream. Investigating its configuration for allowed VLANs or potential physical layer issues is the logical first step to diagnose the connectivity problem for VLAN 20.
- ✗
Any access port in VLAN 1
Why it's wrong here
Any access port in VLAN 1 belongs to the default VLAN and would only handle untagged frames for VLAN 1; it cannot forward VLAN 20 traffic because access ports do not tag frames for other VLANs. Moreover, VLAN 1 might carry management or native traffic on a trunk, but the user's VLAN 20 traffic must traverse the tagged trunk uplink. Therefore, checking a random/any access port in VLAN 1 is a misdirection; the first step should be verifying the trunk configuration on Fa0/24.
When this WOULD be correct
In a scenario where the question asks which access port in VLAN 1 should be checked for connectivity issues affecting users in VLAN 1, option D would be correct. This could involve a misconfiguration or a device connected to an access port in VLAN 1 that is not functioning properly.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The 200-301 exam frequently reuses these exact scenarios with slightly different constraints.
✓Fa0/24Correct answer▾
Why this is correct
Fa0/24 is the only port configured as a trunk, which is necessary for carrying traffic from multiple VLANs, including VLAN 20, to the distribution switch over the uplink. When a user in VLAN 20 cannot reach the distribution switch, this trunk port represents the primary path for inter-VLAN communication upstream. Investigating its configuration for allowed VLANs or potential physical layer issues is the logical first step to diagnose the connectivity problem for VLAN 20.
✗Fa0/1Wrong answer — click to see why▾
Why this is wrong here
Fa0/1 is connected to VLAN 10, and since the user in VLAN 20 cannot reach the distribution switch, checking this port would not address the issue, as it is not part of the user's VLAN.
★ When this WOULD be the correct answer
In a different scenario where the question specifies that VLAN 10 is experiencing connectivity issues or misconfigurations affecting users on that VLAN, checking Fa0/1 would be appropriate to troubleshoot the problem.
Why candidates choose this
Candidates may choose Fa0/1 due to its status as a connected port, mistakenly believing that any active port could be relevant to the user's connectivity issue without considering VLAN assignments.
✗Fa0/2Wrong answer — click to see why▾
Why this is wrong here
Fa0/2 is connected to VLAN 10, which means it cannot facilitate communication for a user in VLAN 20. The issue lies with the trunk port, which is responsible for carrying multiple VLANs, including VLAN 20.
★ When this WOULD be the correct answer
In a scenario where the question specifies that VLAN 20 is configured on Fa0/2 and the user is attempting to reach a device on VLAN 20, checking Fa0/2 would be the correct action to troubleshoot connectivity issues related to that specific VLAN.
Why candidates choose this
Candidates may choose Fa0/2 because it is an active port and they might assume that any connected port could potentially be involved in the issue, especially if they misunderstand VLAN configurations.
✗Any access port in VLAN 1Wrong answer — click to see why▾
Why this is wrong here
Option D is incorrect because it suggests checking any access port in VLAN 1, which is not relevant to the user's issue in VLAN 20. The problem lies with the trunk port not allowing VLAN 20 traffic, not with access ports in VLAN 1.
★ When this WOULD be the correct answer
In a scenario where the question asks which access port in VLAN 1 should be checked for connectivity issues affecting users in VLAN 1, option D would be correct. This could involve a misconfiguration or a device connected to an access port in VLAN 1 that is not functioning properly.
Why candidates choose this
Candidates may choose this option due to a misunderstanding of VLANs, thinking that any access port might be relevant for troubleshooting connectivity issues, regardless of the specific VLAN in question.
Analysis generated from the official 200-301blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Visual reference
Go deeper
Related to this question
Learn chapter
Configuring Switch Ports for Desktops, VoIP Phones, APs, IoT, and Virtualized Hosts
Key term
Allowed VLANs
Allowed VLANs are the specific VLANs whose traffic is permitted to pass over a specific trunk link between switches, acting as an access control filter for VLAN traffic on a port.
Key term
VLAN
A VLAN (Virtual Local Area Network) is a logical grouping of network devices that behave as if they are on the same physical network segment, regardless of their actual physical location.
About these practice questions
This 200-301 question is part of Courseiva's 1,389-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-301 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-301 exam.