CCNA Switching and Network Access Practice Question
Which TWO statements accurately describe 802.1Q trunking and inter-VLAN routing on Cisco switches?
⚠ Common exam trap
Cisco often tests the misconception that the native VLAN is always VLAN 1 and that it is tagged, when in fact the native VLAN is untagged and can be changed to any VLAN number.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
802.1Q trunking adds a 4-byte tag that includes a 12-bit VLAN ID field, increasing the maximum frame size.
Option B is correct because 802.1Q inserts a 4-byte tag into the Ethernet frame, and that tag contains a 12-bit VLAN Identifier (VID) field supporting VLAN IDs 1-4094, which increases the frame size beyond the standard 1518 bytes (up to 1522 bytes). Option C is correct because router-on-a-stick uses one physical router interface divided into logical subinterfaces, and each subinterface is configured with encapsulation dot1q <vlan-id> plus an IP address in a distinct subnet to route between VLANs. Option A is incorrect because the native VLAN is the one VLAN whose frames are sent untagged on an 802.1Q trunk, not tagged with VLAN ID 1. Option D is incorrect because a trunk port carries traffic for multiple VLANs simultaneously, tagging frames to keep them separated. Option E is incorrect because the native VLAN is configurable per trunk port with the switchport trunk native vlan command and is not locked to VLAN 1.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The native VLAN on a trunk port sends frames with an 802.1Q tag containing VLAN ID 1.
Why it's wrong here
On an 802.1Q trunk, frames belonging to the native VLAN are transmitted untagged, not with an 802.1Q tag containing VLAN ID 1. The default native VLAN is indeed VLAN 1, but the native VLAN is defined by the absence of a tag; only non-native VLAN traffic gets tagged. Sending native VLAN frames with a tag would violate the 802.1Q standard and cause interoperability issues.
- ✓
802.1Q trunking adds a 4-byte tag that includes a 12-bit VLAN ID field, increasing the maximum frame size.
Why this is correct
802.1Q trunking inserts a 4-byte tag field between the source MAC address and the EtherType/length field. This tag comprises a 16-bit TPID (0x8100) and a 16-bit TCI, which contains a 3-bit priority, a 1-bit Drop Eligible Indicator (DEI), and a 12-bit VLAN ID supporting up to 4094 usable VLANs. Adding this 4-byte field increases the maximum Ethernet frame size from 1518 to 1522 bytes for tagged frames.
- ✓
A router-on-a-stick configuration uses subinterfaces, each mapped to a VLAN with 802.1Q encapsulation and an IP address in a unique subnet.
Why this is correct
Router-on-a-stick (ROAS) uses a single physical router interface divided into multiple logical subinterfaces, one per VLAN. Each subinterface is configured with 802.1Q encapsulation matching a specific VLAN ID and an IP address in a unique subnet for that VLAN. The router performs inter-VLAN routing by receiving tagged frames on the physical trunk link and forwarding them between subinterfaces based on the frame's VLAN tag and destination IP.
- ✗
A trunk port can only forward traffic for one VLAN at a time.
Why it's wrong here
A trunk port is specifically designed to carry traffic for multiple VLANs simultaneously. It maintains the VLAN membership of each frame by inserting an 802.1Q tag into non-native VLAN frames, allowing the receiving switch to distinguish which VLAN each frame belongs to. Trunks support all active VLANs at once, and the native VLAN (untagged) plus tagged VLANs all traverse the same link concurrently.
- ✗
The native VLAN on a trunk cannot be changed from VLAN 1.
Why it's wrong here
The native VLAN on a trunk is fully configurable and not permanently fixed to VLAN 1. Using the 'switchport trunk native vlan <vlan-id>' command, a network administrator can change the native VLAN to any existing VLAN number, such as 99. This is often done as a security best practice to avoid using VLAN 1, but the native VLAN must match on both ends of the trunk to prevent misconfiguration.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The 200-301 exam frequently reuses these exact scenarios with slightly different constraints.
✓802.1Q trunking adds a 4-byte tag that includes a 12-bit VLAN ID field, increasing the maximum frame size.Correct answer▾
Why this is correct
802.1Q trunking inserts a 4-byte tag field between the source MAC address and the EtherType/length field. This tag comprises a 16-bit TPID (0x8100) and a 16-bit TCI, which contains a 3-bit priority, a 1-bit Drop Eligible Indicator (DEI), and a 12-bit VLAN ID supporting up to 4094 usable VLANs. Adding this 4-byte field increases the maximum Ethernet frame size from 1518 to 1522 bytes for tagged frames.
✗The native VLAN on a trunk port sends frames with an 802.1Q tag containing VLAN ID 1.Wrong answer — click to see why▾
Why this is wrong here
By default, frames belonging to the native VLAN (VLAN 1) traverse a trunk link without an 802.1Q tag.
✗A trunk port can only forward traffic for one VLAN at a time.Wrong answer — click to see why▾
Why this is wrong here
Trunk ports differentiate frames from multiple VLANs using VLAN tags, permitting concurrent forwarding for all allowed VLANs.
✗The native VLAN on a trunk cannot be changed from VLAN 1.Wrong answer — click to see why▾
Why this is wrong here
Cisco switches allow administrators to assign any active VLAN as the native VLAN for a trunk port.
Analysis generated from the official 200-301blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Visual reference
Go deeper
Related to this question
Learn chapter
Troubleshoot: Route Missing from Routing Table
Key term
Route
A route is a path that data takes through a network from one device or network to another, determined by routing protocols and configured rules.
Key term
Router-on-a-stick
A router-on-a-stick is a network configuration where a single router interface is used to route traffic between multiple VLANs by connecting to a switch through a trunk link.
About these practice questions
One of 1,450 original 200-301 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-301 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-301 exam.