Courseiva
Switching and Network AccessmediumMultiple ChoiceObjective-mapped

CCNA Switching and Network Access Practice Question

A switch displays this output:

Port Name Status Vlan Fa0/1 connected 10 Fa0/2 connected 10 Fa0/24 connected trunk

Which port should be checked first if a user in VLAN 20 cannot reach the distribution switch over the uplink?

⚠ Common exam trap

Don't confuse access ports with trunk ports; only trunk ports can carry multiple VLANs.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Fa0/24

If users in VLAN 20 must cross the uplink, the trunk port is the first place to verify allowed VLANs and tagging.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Fa0/1

    Why it's wrong here

    Fa0/1 is configured as an access port assigned to VLAN 10, so it carries untagged frames for VLAN 10 only. A client in VLAN 20 would have frames tagged (or PVID-assigned) for VLAN 20, which Fa0/1 cannot forward upstream. Since Fa0/1 is not the uplink trunk, inspecting it does not help isolate why VLAN 20 lacks connectivity to the distribution switch.

    When this WOULD be correct

    In a different scenario where the question specifies that VLAN 10 is experiencing connectivity issues or misconfigurations affecting users on that VLAN, checking Fa0/1 would be appropriate to troubleshoot the problem.

  • Fa0/2

    Why it's wrong here

    Fa0/2 also resides in VLAN 10 as an access port, making it redundant to Fa0/1 for this diagnosis. Even if Fa0/2's link were active, its PVID of 10 would cause it to drop or ignore any VLAN 20 traffic due to improper VLAN membership. The relevant path to the distribution switch is the trunk on Fa0/24, not another access port in an unrelated VLAN.

    When this WOULD be correct

    In a scenario where the question specifies that VLAN 20 is configured on Fa0/2 and the user is attempting to reach a device on VLAN 20, checking Fa0/2 would be the correct action to troubleshoot connectivity issues related to that specific VLAN.

  • Fa0/24

    Why this is correct

    Fa0/24 is the only port configured as a trunk, which is necessary for carrying traffic from multiple VLANs, including VLAN 20, to the distribution switch over the uplink. When a user in VLAN 20 cannot reach the distribution switch, this trunk port represents the primary path for inter-VLAN communication upstream. Investigating its configuration for allowed VLANs or potential physical layer issues is the logical first step to diagnose the connectivity problem for VLAN 20.

  • Any access port in VLAN 1

    Why it's wrong here

    Any access port in VLAN 1 belongs to the default VLAN and would only handle untagged frames for VLAN 1; it cannot forward VLAN 20 traffic because access ports do not tag frames for other VLANs. Moreover, VLAN 1 might carry management or native traffic on a trunk, but the user's VLAN 20 traffic must traverse the tagged trunk uplink. Therefore, checking a random/any access port in VLAN 1 is a misdirection; the first step should be verifying the trunk configuration on Fa0/24.

    When this WOULD be correct

    In a scenario where the question asks which access port in VLAN 1 should be checked for connectivity issues affecting users in VLAN 1, option D would be correct. This could involve a misconfiguration or a device connected to an access port in VLAN 1 that is not functioning properly.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The 200-301 exam frequently reuses these exact scenarios with slightly different constraints.

Fa0/24Correct answer

Why this is correct

Fa0/24 is the only port configured as a trunk, which is necessary for carrying traffic from multiple VLANs, including VLAN 20, to the distribution switch over the uplink. When a user in VLAN 20 cannot reach the distribution switch, this trunk port represents the primary path for inter-VLAN communication upstream. Investigating its configuration for allowed VLANs or potential physical layer issues is the logical first step to diagnose the connectivity problem for VLAN 20.

Fa0/1Wrong answer — click to see why

Why this is wrong here

Fa0/1 is connected to VLAN 10, and since the user in VLAN 20 cannot reach the distribution switch, checking this port would not address the issue, as it is not part of the user's VLAN.

★ When this WOULD be the correct answer

In a different scenario where the question specifies that VLAN 10 is experiencing connectivity issues or misconfigurations affecting users on that VLAN, checking Fa0/1 would be appropriate to troubleshoot the problem.

Why candidates choose this

Candidates may choose Fa0/1 due to its status as a connected port, mistakenly believing that any active port could be relevant to the user's connectivity issue without considering VLAN assignments.

Fa0/2Wrong answer — click to see why

Why this is wrong here

Fa0/2 is connected to VLAN 10, which means it cannot facilitate communication for a user in VLAN 20. The issue lies with the trunk port, which is responsible for carrying multiple VLANs, including VLAN 20.

★ When this WOULD be the correct answer

In a scenario where the question specifies that VLAN 20 is configured on Fa0/2 and the user is attempting to reach a device on VLAN 20, checking Fa0/2 would be the correct action to troubleshoot connectivity issues related to that specific VLAN.

Why candidates choose this

Candidates may choose Fa0/2 because it is an active port and they might assume that any connected port could potentially be involved in the issue, especially if they misunderstand VLAN configurations.

Any access port in VLAN 1Wrong answer — click to see why

Why this is wrong here

Option D is incorrect because it suggests checking any access port in VLAN 1, which is not relevant to the user's issue in VLAN 20. The problem lies with the trunk port not allowing VLAN 20 traffic, not with access ports in VLAN 1.

★ When this WOULD be the correct answer

In a scenario where the question asks which access port in VLAN 1 should be checked for connectivity issues affecting users in VLAN 1, option D would be correct. This could involve a misconfiguration or a device connected to an access port in VLAN 1 that is not functioning properly.

Why candidates choose this

Candidates may choose this option due to a misunderstanding of VLANs, thinking that any access port might be relevant for troubleshooting connectivity issues, regardless of the specific VLAN in question.

Analysis generated from the official 200-301blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

Visual reference

Switch VLAN 10 Sales (192.168.10.0/24) PC-A PC-B VLAN 20 HR (192.168.20.0/24) PC-C PC-D Router VLANs isolate traffic — inter-VLAN routing requires a Layer 3 device

Go deeper

Related to this question

About these practice questions

This 200-301 question is part of Courseiva's 1,389-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-301 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-301 exam.