Courseiva

CCNA Switching and Network Access Practice Question

Which TWO statements are true regarding switch port configuration for access, voice, and trunk ports?

⚠ Common exam trap

Cisco often tests the distinction between 'dynamic auto' and 'dynamic desirable' DTP modes, where candidates mistakenly think 'auto' actively initiates trunk negotiation, when in fact it only responds to incoming DTP messages.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A switch port configured as a trunk port can simultaneously carry untagged traffic for the native VLAN and tagged traffic for multiple other VLANs.

Option A is correct because an 802.1Q trunk port transmits frames for the native VLAN untagged while tagging frames for all other allowed VLANs, allowing one link to carry both native and multiple tagged VLANs simultaneously. Option D is correct because when a voice VLAN is configured on an access port, the switch uses CDP (or LLDP-MED) to advertise the voice VLAN ID to the attached IP phone, which then tags its voice traffic with that VLAN. Option B is wrong because a port with both an access VLAN and a voice VLAN is configured as an access port with the 'switchport voice vlan' command, not as a trunk. Option C is wrong because 'switchport mode dynamic auto' only passively waits for the neighbor to initiate trunking; it is 'dynamic desirable' that actively attempts to form a trunk. Option E is wrong because the native VLAN is not automatically added to the allowed VLAN list by 'switchport trunk allowed vlan'; it must be explicitly included if it is to be permitted on the trunk.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    A switch port configured as a trunk port can simultaneously carry untagged traffic for the native VLAN and tagged traffic for multiple other VLANs.

    Why this is correct

    A trunk port uses IEEE 802.1Q tagging to carry frames from multiple VLANs simultaneously, but it handles the native VLAN uniquely by leaving those frames untagged as they traverse the trunk. All other VLANs in the allowed list are transmitted with 802.1Q tags, allowing a single physical link to carry many logical networks. The native VLAN is designated with 'switchport trunk native vlan' and is subject to the allowed VLAN list, so if that list is pruned, the native VLAN may also be excluded unless explicitly left in.

  • ✗

    When a port is configured with both an access VLAN and a voice VLAN, the switchport must be set to trunk mode.

    Why it's wrong here

    An access port with a voice VLAN does not require trunk mode because it uses a separate mechanism: the data VLAN remains untagged, while the voice VLAN is tagged using 802.1Q. The command 'switchport voice vlan' simply tells the switch to accept tagged frames from the IP phone for that specific voice VLAN, while the port stays in access mode for all other traffic. Trunk mode is only necessary when you need to carry multiple VLANs in both directions between switches, not for the single additional voice VLAN on an edge access port.

  • ✗

    The switchport mode dynamic auto command sets the port to actively attempt to form a trunk if the neighbor initiates negotiation.

    Why it's wrong here

    Dynamic auto is a passive DTP mode: the switchport waits for a DTP frame from the neighbor before it will negotiate trunking, and it never sends its own DTP frames to initiate negotiation. In contrast, dynamic desirable or trunk modes actively send DTP frames to try to form a trunk. Therefore, if two switches are both in dynamic auto mode, the link will remain an access port indefinitely because neither side starts the negotiation process.

  • ✓

    An access port with a voice VLAN configured sends CDP or LLDP information to the IP phone to identify the voice VLAN.

    Why this is correct

    When a Cisco IP phone boots on an access port configured with a voice VLAN, the switch sends CDP (or LLDP if configured) advertisements that include the voice VLAN ID, allowing the phone to tag its voice traffic with that VLAN. The phone then keeps PC data traffic untagged on the access VLAN while tagging voice traffic, enabling both to share the same physical link without needing trunk mode. This mechanism works only when the phone trusts the switch's CDP/LLDP information, which is why the voice VLAN must be configured explicitly on the access port.

  • ✗

    Issuing the switchport trunk allowed vlan command automatically includes the native VLAN in the allowed list, so it never needs to be explicitly added.

    Why it's wrong here

    The 'switchport trunk allowed vlan' command defines an explicit list of VLANs that may traverse the trunk, and that list is independent of the native VLAN. If the native VLAN is not included in the allowed list, native VLAN frames will be dropped, just like frames from any other excluded VLAN. The default allowed list includes all VLANs, but once you manually configure a restricted list, you are responsible for adding the native VLAN if you want its traffic to pass.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The 200-301 exam frequently reuses these exact scenarios with slightly different constraints.

✓A switch port configured as a trunk port can simultaneously carry untagged traffic for the native VLAN and tagged traffic for multiple other VLANs.Correct answer▾

Why this is correct

A trunk port uses IEEE 802.1Q tagging to carry frames from multiple VLANs simultaneously, but it handles the native VLAN uniquely by leaving those frames untagged as they traverse the trunk. All other VLANs in the allowed list are transmitted with 802.1Q tags, allowing a single physical link to carry many logical networks. The native VLAN is designated with 'switchport trunk native vlan' and is subject to the allowed VLAN list, so if that list is pruned, the native VLAN may also be excluded unless explicitly left in.

✗When a port is configured with both an access VLAN and a voice VLAN, the switchport must be set to trunk mode.Wrong answer — click to see why▾

Why this is wrong here

Multi-VLAN access ports (access + voice) stay in access mode; trunk mode is not required and would incorrectly pass all VLANs.

✗The switchport mode dynamic auto command sets the port to actively attempt to form a trunk if the neighbor initiates negotiation.Wrong answer — click to see why▾

Why this is wrong here

Dynamic desirable actively initiates, but dynamic auto is passive.

✗Issuing the switchport trunk allowed vlan command automatically includes the native VLAN in the allowed list, so it never needs to be explicitly added.Wrong answer — click to see why▾

Why this is wrong here

When you prune the allowed VLANs, any omitted VLANs (including the native VLAN) are blocked unless added back.

Analysis generated from the official 200-301blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

Visual reference

Switch VLAN 10 Sales (192.168.10.0/24) PC-A PC-B VLAN 20 HR (192.168.20.0/24) PC-C PC-D Router VLANs isolate traffic — inter-VLAN routing requires a Layer 3 device

About these practice questions

This 200-301 question is part of Courseiva's 1,450-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-301 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-301 exam.