Courseiva

CCNA Switching Network Access Questions

20 of 320 questions · Page 5/5 · Switching Network Access topic · Answers revealed

301
MCQhard

Refer to the exhibit. An engineer configured PortFast on interface GigabitEthernet0/1, which connects to a server that does not participate in spanning tree. However, the port remains in the listening state for the full forward delay period before transitioning to forwarding. The engineer issues the show spanning-tree vlan 10 detail command. Based on the output, what is the most likely cause?

A.The port is configured as a trunk, so PortFast is not active.
B.BPDU Guard is enabled on the port, causing it to block.
C.The forward delay timer is set too high, and PortFast cannot override it.
D.The server is sending BPDUs, causing the port to lose its PortFast state.
AnswerA

PortFast is only effective on access ports. The exhibit shows ‘Edge port: no (default) portfast: no (default)’ despite the engineer enabling PortFast, indicating the port is operating as a trunk (or not an access port). Therefore, PortFast has no effect and the normal STP listening/learning states apply.

Why this answer

PortFast is designed to immediately transition a port to the forwarding state, bypassing the listening and learning states. However, PortFast is only effective on access ports; if the interface is configured as a trunk port, PortFast is automatically disabled by the switch. The output of 'show spanning-tree vlan 10 detail' would confirm the port is a trunk, explaining why it still goes through the full forward delay.

Exam trap

Cisco often tests the misconception that PortFast works on any port type, but the trap here is that PortFast is only effective on access ports, and trunk ports automatically disable PortFast regardless of configuration.

Why the other options are wrong

B

The port is not in an err-disabled state; BPDU Guard causes the port to be shut down, not to stay in listening.

C

Misunderstanding that PortFast bypasses timers completely on access ports; the high forward delay is irrelevant if PortFast were active.

D

The assumption that the server is sending BPDUs is contradicted by the output showing zero BPDUs received.

302
Drag & Dropmedium

Drag and drop the following steps into the correct order to configure and recover from a BPDU guard violation on a PortFast-enabled access port in RSTP.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Configure PortFast and BPDU guard on the access port. Then trigger a violation by connecting an unauthorized switch, which causes the port to error-disable. Diagnose by checking the error-disabled status.

To recover, first remove the offending device, then cycle the port with shutdown and no shutdown; otherwise the port will immediately go error-disabled again.

Exam trap

Do not confuse the order: configuration must precede the violation. Also, recovery requires removing the rogue switch before bouncing the interface; failing to do so will cause the port to trip again.

303
PBQhard

You are connected to R1, a multilayer switch acting as the STP root for VLAN 10. Configure Root Guard on port GigabitEthernet0/1 (designated port) to protect against superior BPDUs from an unauthorized switch, Loop Guard on uplink GigabitEthernet0/2 to prevent loops, and BPDU Guard on PortFast-enabled GigabitEthernet0/3. After configuration, a superior BPDU arrives on G0/1, blocking the port; verify the Root Guard state and ensure BPDU Guard triggers err-disable on G0/3.

Network Topology
G0/1: designated portG0/2: uplinkG0/3: PortFastR1Access SwitchCore SwitchEnd Device

Hints

  • •Root Guard is applied on ports that should never become root; use 'spanning-tree guard root'.
  • •Loop Guard prevents alternate or root ports from becoming designated when BPDUs stop; use 'spanning-tree guard loop' on uplinks.
  • •BPDU Guard combined with PortFast err-disables a port upon BPDU reception; enable with 'spanning-tree bpduguard enable' under the interface.
A.G0/1 is in root-inconsistent state; G0/3 is in err-disabled state.
B.G0/1 is in blocking state; G0/3 is in err-disabled state.
C.G0/1 is in root-inconsistent state; G0/3 is in blocking state.
D.G0/1 is in err-disabled state; G0/3 is in root-inconsistent state.
AnswerA
solution
! R1
interface GigabitEthernet0/1
spanning-tree guard root
interface GigabitEthernet0/2
spanning-tree guard loop
interface GigabitEthernet0/3
spanning-tree bpduguard enable

Why this answer

Root Guard is needed on the designated port (G0/1) to prevent an unauthorized switch from becoming root by sending superior BPDUs. Loop Guard on the uplink (G0/2) prevents loops if BPDUs stop arriving. BPDU Guard on PortFast ports (G0/3) immediately err-disables them upon BPDU reception.

The configuration uses 'spanning-tree guard root' on G0/1, 'spanning-tree guard loop' on G0/2, and 'spanning-tree bpduguard enable' on G0/3. Verification shows G0/1 blocked by root-inconsistent state and G0/3 in err-disabled state.

Exam trap

Do not confuse the states caused by Root Guard (root-inconsistent) and BPDU Guard (err-disable). Also, remember that Root Guard is applied to designated ports, not root or alternate ports.

Why the other options are wrong

B

Root Guard uses a specific 'root-inconsistent' state, not the generic 'blocking' state.

C

BPDU Guard triggers err-disable, not blocking. Blocking is an STP state, not an error state.

D

Root Guard and BPDU Guard have different effects: root-inconsistent vs. err-disable. Mixing them up is a common error.

304
MCQhard

A user connects a Cisco IP Phone with a PC attached to the phone's PC port to switch interface GigabitEthernet0/5. The PC obtains an IP address and can reach the network, but the phone displays "Configuring IP" and never registers. Based on the exhibit outputs, what is the most likely cause?

A.The switchport must be configured as a trunk to support voice VLANs.
B.VLAN 20 has not been created in the switch's VLAN database.
C.The native VLAN on the trunk ports between the switch and the DHCP server is incorrectly set to VLAN 10.
D.The phone is manually configured to use VLAN 10 for voice traffic instead of VLAN 20.
AnswerB

The 'show vlan brief' output lists only VLANs 1 and 10. VLAN 20 does not exist, so the switch discards any tagged frames arriving on the port with VLAN ID 20, causing the phone's DHCP/TFTP communication to fail.

Why this answer

The PC obtains an IP address and can reach the network, indicating that the access VLAN (likely VLAN 1 or the native VLAN) is functioning. However, the phone displays 'Configuring IP' and never registers, which means it cannot obtain an IP address on its voice VLAN. The most likely cause is that VLAN 20, which is configured as the voice VLAN on the switchport, has not been created in the switch's VLAN database.

Without the VLAN existing, the switch cannot forward traffic or DHCP requests for that VLAN, leaving the phone stuck in the IP configuration phase.

Exam trap

Cisco often tests the distinction between configuring a voice VLAN on an interface and actually creating that VLAN in the global VLAN database; candidates mistakenly assume that referencing a VLAN in interface configuration automatically creates it.

Why the other options are wrong

A

Voice VLANs operate on access ports by tagging voice traffic while keeping PC traffic untagged in the data VLAN. A trunk is not required.

C

Native VLAN mismatches on trunks would affect both data and voice VLANs if both were allowed. The PC works, ruling out a general trunk issue.

D

The phone would work if it was sending voice traffic on the data VLAN (10), because VLAN 10 exists. The phone failing indicates a missing voice VLAN, not a misconfiguration on the phone.

305
MCQmedium

Exhibit: Users complain of slow wireless performance in a dense office even though signal strength is strong. Multiple APs are using channels 1, 2, and 3 on 2.4 GHz. Which change is most appropriate?

A.Reduce all AP transmit power to zero
B.Move to non-overlapping channels such as 1, 6, and 11
C.Change every AP to the same channel for consistency
D.Disable WPA2 security
AnswerB

In the 2.4 GHz ISM band, adjacent channel interference is unavoidable if channels are spaced closer than 25 MHz, so planning APs on the three non-overlapping channels 1, 6, and 11 ensures that overlapping coverage cells do not transmit on the same or partially overlapping frequencies. This eliminates co-channel and adjacent-channel contention, allowing the CSMA/CA medium access protocol to work efficiently and restoring throughput for users.

Why this answer

In 2.4 GHz, overlapping channels cause co-channel and adjacent-channel interference. The common non-overlapping choices are 1, 6, and 11. Moving away from overlapping channels usually improves performance in a dense deployment.

Exam trap

Avoid assuming that increasing power or adding more APs will solve interference issues without considering channel overlap.

Why the other options are wrong

A

Reducing all AP transmit power to zero would completely disable the wireless network, making it impossible for users to connect or experience any performance, which does not address the issue of slow performance in a dense office environment.

C

Changing every AP to the same channel would lead to co-channel interference, exacerbating the slow wireless performance issue rather than resolving it. In a dense office environment, this configuration would reduce overall throughput and increase contention among devices.

D

Disabling WPA2 security would not address the issue of slow wireless performance in a dense office environment; instead, it would compromise network security and potentially allow unauthorized access, worsening the situation.

306
MCQhard

A Layer 2 switch port connected to an end host should move to forwarding quickly but also shut down if a BPDU is received. Which pair of features best supports that design?

AnswerA

PortFast immediately transitions an access port to the forwarding state, bypassing the listening and learning STP states so the end host can start sending traffic without delay. BPDU Guard protects the STP topology by disabling any PortFast port that receives a BPDU, which indicates an unauthorized switch or bridge has been connected. Together they are the required configuration for a trusted edge port attached to a single end host.

Why this answer

PortFast and BPDU Guard are the right pair. In plain language, PortFast makes an edge port usable quickly for a real end device, while BPDU Guard protects that same port by shutting it down if spanning-tree control traffic appears unexpectedly.

This is a classic access-layer design. PortFast improves usability, and BPDU Guard improves safety. The best answer combines both functions.

Exam trap

Be careful not to confuse BPDU Guard with Root Guard or Loop Guard, as they serve different purposes in spanning tree protection.

Why the other options are wrong

B

Root Guard and UDLD do not directly address the requirement for a port to quickly transition to forwarding while shutting down upon receiving a BPDU. Root Guard is used to prevent a port from becoming a root port, while UDLD is for detecting unidirectional links.

C

Loop Guard and native VLAN do not directly address the requirement for a port to quickly transition to forwarding while shutting down upon receiving a BPDU. Loop Guard is designed to prevent loops by keeping a port in a loop-inconsistent state, and native VLAN is related to VLAN tagging, not port state management.

D

Port security and EtherChannel do not directly address the need for a switch port to quickly transition to forwarding mode while also shutting down upon receiving a BPDU. Port security focuses on limiting MAC addresses and EtherChannel is used for link aggregation, neither of which fulfill the specific requirements of this question.

307
MCQhard

A network administrator has configured a switch port to support a VoIP phone and a desktop PC. Users report that the desktop PC cannot obtain an IP address via DHCP, while the VoIP phone registers successfully. The switch port is up/up, and the desktop is connected to the phone's PC port. What is the most likely cause of the issue?

A.The switchport mode access should be changed to switchport mode trunk to allow both vlans.
B.The switchport access vlan should be changed to the data VLAN to match the subnet expected by the desktop.
C.The switchport voice vlan should be removed because the desktop cannot use it.
D.The spanning-tree portfast should be disabled to prevent DHCP delays.
AnswerB

In a typical IP phone daisy-chain topology, the desktop connects to the phone's PC port, and the switch sends all untagged desktop frames into the port's configured access VLAN. If that access VLAN is incorrectly set to, say, the native VLAN or a different number, the desktop's DHCP DISCOVER will not arrive at the DHCP server for its expected data subnet, leaving it without an IP address. Correctly changing the switchport access vlan to the data VLAN ensures the desktop's untagged traffic is placed in the proper L2 domain, allowing the DHCP server to respond with an appropriate address.

Why this answer

The desktop PC obtains its IP address from the data VLAN, but the switch port's access VLAN is likely misconfigured to the voice VLAN. Changing the access VLAN to the correct data VLAN places the PC in the proper subnet and allows DHCP to function. Option A is unnecessary because a voice-access port does not need to be a trunk.

Option C would break the VoIP phone without fixing the PC's VLAN assignment. Option D is irrelevant; PortFast speeds up STP convergence and does not block DHCP.

Exam trap

Cisco often tests the misconception that the PC uses the voice VLAN or that the port must be a trunk, when in reality the phone handles the VLAN separation internally and the switch port remains an access port with a separate voice VLAN.

Why the other options are wrong

A

The current configuration uses access mode with voice vlan, which is correct for a phone+PC setup. Trunk mode is unnecessary and could break the phone's untagged traffic expectations.

C

The voice vlan is correctly configured for the phone; the problem is with the data vlan assignment for the desktop.

D

Portfast is beneficial for host ports; disabling it would worsen the issue by introducing STP convergence delays.

308
MCQhard

A network engineer is troubleshooting a switch stack where a newly added member switch is not passing traffic. The engineer runs the command 'show switch' and sees that the new switch is in 'Provisioned' state. What is the most likely cause of this issue?

A.The stack priority of the new switch is set lower than the existing switches.
B.The new switch has a different model number than the provisioned configuration.
C.The new switch is running an incompatible IOS version compared to the stack master.
D.The new switch has not been physically connected to the stack or has not been powered on.
AnswerD

A switch in 'Provisioned' state means it has been pre-configured in the stack but is not currently detected. This occurs when the switch is not physically connected via stacking cables or is powered off. Once the switch is connected and powered on, it should transition to 'Ready' or 'Member' state and begin passing traffic.

Why this answer

The 'Provisioned' state in a switch stack indicates that the switch is expected based on configuration but is not currently detected. This usually means the switch is not physically connected to the stack or is not powered on. Once the switch is connected and powered, it should join the stack and become active.

Exam trap

The trap here is confusing the 'Provisioned' state with other stack member states like 'Ready' or 'Member', which indicate different conditions.

309
MCQhard

Based on the exhibit, which action is most likely required to allow AP-22 to join the controller successfully?

A.Correct the AP's default gateway so it matches the AP's actual subnet and reachability needs.
B.Change the AP from Ethernet to PPP encapsulation.
C.Remove the AP IP address so it can obtain an IP address automatically via DHCP.
D.Disable DHCP on the controller for all APs.
AnswerA

The AP's IP address and its default gateway must reside in the same Layer 3 subnet; the exhibit shows a mismatch, so the AP cannot route CAPWAP discovery or join messages toward the wireless LAN controller. With an incorrect gateway, the AP's forwarding table sends management traffic to a non-existent or unreachable next hop, effectively isolating the AP from the controller. Correcting the gateway to match the actual subnet and reachability path restores proper IP routing and allows the AP to complete the join process.

Why this answer

The correct action is to fix the AP's default gateway so it can reach the controller's subnet. Option B is wrong because APs use Ethernet, not PPP encapsulation, which is used for serial WAN links. Option C is wrong because CAPWAP does not assign IP addresses; DHCP does, but the AP already has a static IP, and removing it would cause it to fall back to DHCP, which may not fix the gateway issue.

Option D is wrong because disabling DHCP on the controller would affect all APs and prevent new APs from obtaining addresses, which is not a targeted fix.

Exam trap

Avoid assuming resets or updates fix network configuration issues; focus on Layer 3 settings like gateways.

Why the other options are wrong

B

APs use Ethernet frames, not PPP encapsulation; PPP is used for serial links.

C

CAPWAP does not assign IP addresses; DHCP handles that, but removing the AP's IP does not correct the gateway mismatch.

D

Disabling DHCP on the controller would break all APs, not just AP-22, and does not address the gateway issue.

310
MCQhard

Exhibit: An access switch shows Gi1/0/10 as err-disabled shortly after an IP phone and a workstation are connected through the same wall jack. What is the most likely cause?

A.The native VLAN is missing
B.The port security maximum is too low for the connected devices
C.BPDU Guard blocked the port because a workstation was attached
AnswerB

With a Cisco IP phone and a PC behind it, the switchport must learn two MAC addresses (phone and PC) on the same port. If the port-security maximum is set to 1, the second MAC address triggers a violation and the default violation mode (shutdown) places the interface into err-disabled state. The fix is to raise the maximum to at least 2 and optionally use sticky MAC addresses.

Why this answer

With a phone and a PC on the same access port, the switch may legitimately see two MAC addresses. Port security set to a maximum of 1 causes a violation and can place the interface into err-disabled state.

Exam trap

Be cautious of assuming all err-disabled states are due to STP or VLAN issues; port security is a frequent cause.

Why the other options are wrong

A

The native VLAN being missing would not directly cause a port to go err-disabled when connecting an IP phone and workstation; it typically results in VLAN mismatches or communication issues rather than disabling the port.

C

BPDU Guard is designed to protect against loops by disabling ports that receive Bridge Protocol Data Units (BPDUs). In this scenario, the port is err-disabled due to port security violations, not because of BPDU Guard activation.

D

DHCP snooping denying the voice VLAN would typically result in the IP phone failing to receive an IP address, rather than causing the port to go err-disabled. The err-disabled state is more likely due to port security violations when multiple devices are connected.

311
MCQeasy

A network technician is connecting a new access switch to an existing distribution switch. The access switch will carry multiple VLANs, and the technician wants to ensure that the link is configured as a trunk and that only VLANs 10, 20, and 30 are allowed. Which command should be used on the access switch interface to restrict the allowed VLANs?

A.switchport access vlan 10,20,30
B.switchport trunk allowed vlan add 10,20,30
C.switchport trunk native vlan 10,20,30
D.switchport trunk allowed vlan 10,20,30
AnswerD

This command explicitly sets the allowed VLAN list on a trunk port to only VLANs 10, 20, and 30. By default, all VLANs are allowed on a trunk, so this command is necessary to restrict traffic. It is the correct way to limit VLANs on a Cisco switch trunk interface. The other options either add to the existing list or are used for different purposes, making this the right choice.

Why this answer

To restrict a trunk port to specific VLANs, the 'switchport trunk allowed vlan' command with a list of VLAN IDs is used. This replaces the default allowed list (all VLANs) with the specified ones. The 'add' keyword would append rather than replace, and other commands either set native VLAN or are for access ports.

Thus, the correct command is the one that sets the allowed VLAN list directly.

Exam trap

The trap here is confusing the 'add' keyword with the base command; using 'add' would not remove the default all-VLANs allowance.

312
MCQmedium

Exhibit: A user reports intermittent connectivity after a new switch was connected to an access port. Which feature would have prevented this by immediately disabling the port when a BPDU was received?

AnswerC

BPDU Guard is the correct protection mechanism because it is designed specifically for PortFast-enabled access ports. When a legitimate BPDU is received on such a port, BPDU Guard immediately err-disables the interface to prevent a potential bridging loop, which explains the intermittent connectivity: the new device is sending BPDUs and triggering the shutdown each time.

Why this answer

BPDU Guard is the correct answer because it protects PortFast-enabled edge ports by immediately disabling the port upon receiving a BPDU, preventing accidental loops. Root Guard prevents the port from becoming a root port, not from BPDU reception. Loop Guard prevents alternate or root ports from becoming designated due to BPDU loss, unrelated to BPDU reception disabling.

UDLD detects unidirectional links but does not disable ports upon BPDU reception.

Exam trap

Be cautious not to confuse BPDU Guard with other guard features like Root Guard or Loop Guard, which serve different purposes.

Why the other options are wrong

A

Root Guard prevents a port from being elected as root port, not from receiving BPDUs on an access port.

B

Loop Guard prevents loops caused by BPDU loss on blocked ports, not from BPDU reception on access ports.

D

UDLD detects unidirectional links but does not disable a port when a BPDU is received.

313
MCQhard

Refer to the exhibit. A network engineer configured an EtherChannel between SW1 and SW2 using LACP. After the configuration is applied, the Port-channel 1 interface remains in a down state and does not pass traffic. The engineer runs the show etherchannel detail command on SW1. Based on the output, what is the most likely cause of the problem?

A.The native VLAN is mismatched on member interface Gi0/2.
B.The load-balancing method on the port-channel is set incorrectly to src-dst-ip.
C.The interface Gi0/1 is administratively down.
D.Spanning Tree Protocol has placed the port-channel in a blocking state due to a loop.
AnswerC

The exhibit shows Gi0/1 with state 'Up Cntrl-fwd/bndl In-bndl Mstr', meaning it is up, forwarding, bundled, and acting as the master port. An administratively down interface would show 'Down' with 'admin down' status, which is not the case.

Why this answer

An EtherChannel requires all member ports to have consistent VLAN configurations. However, if one port (Gi0/2) has a native VLAN mismatch, only that port is suspended/excluded from the channel. The port-channel can still become active using other valid members.

In this scenario, the port-channel remains down because Gi0/1 is administratively down, leaving no valid member ports to form the channel. The show etherchannel detail output would indicate Gi0/1 in an administratively down state and Gi0/2 in a suspended state due to the native VLAN mismatch.

Exam trap

Candidates often assume that any VLAN mismatch on a member port will bring down the entire port-channel. In reality, only the mismatched port is affected; the port-channel may still operate if other ports are properly configured.

Why the other options are wrong

B

Load-balancing configuration does not influence the bundle state of a port-channel; it only affects frame distribution. The output shows a physical/logical inconsistency, not a hashing algorithm problem.

D

A common misconception is that any down or suspended link indicates an STP loop. However, 'show etherchannel detail' presents the explicit reason, and the native VLAN mismatch line directly contradicts this option.

314
PBQhard

You are connected to a single switch, SW1, which is a Cisco Catalyst 2960 running Cisco IOS. Configure port GigabitEthernet0/1 as an access port for a Cisco IP phone and a PC on the same VLAN (Voice VLAN 20, Data VLAN 10). The switch must provide PoE to the phone. Additionally, configure GigabitEthernet0/2 as an access port for a wireless access point (AP) that requires PoE. Verify both configurations using the appropriate show commands. The current running-config is incomplete; you must add the necessary commands.

Hints

  • •Voice VLAN is configured with a separate command on the interface.
  • •PoE may be disabled; use 'power inline auto' to enable it.
  • •Use 'show interfaces switchport' to confirm voice VLAN assignment.
A.interface GigabitEthernet0/1 switchport mode access switchport access vlan 10 switchport voice vlan 20 power inline auto interface GigabitEthernet0/2 switchport mode access switchport access vlan 10 power inline auto
B.interface GigabitEthernet0/1 switchport mode trunk switchport trunk allowed vlan 10,20 power inline auto interface GigabitEthernet0/2 switchport mode access switchport access vlan 10 power inline auto
C.interface GigabitEthernet0/1 switchport mode access switchport access vlan 10 switchport voice vlan 20 power inline never interface GigabitEthernet0/2 switchport mode access switchport access vlan 10 power inline auto
D.interface GigabitEthernet0/1 switchport mode access switchport access vlan 20 switchport voice vlan 10 power inline auto interface GigabitEthernet0/2 switchport mode access switchport access vlan 10 power inline auto
AnswerA
solution
! SW1
configure terminal
interface gigabitEthernet 0/1
switchport voice vlan 20
power inline auto
exit
interface gigabitEthernet 0/2
power inline auto
end
write memory

Why this answer

The configuration was missing the voice VLAN assignment on Gi0/1 and PoE settings on both ports. For Gi0/1, the command 'switchport voice vlan 20' is required to separate voice traffic from data traffic. For both Gi0/1 and Gi0/2, PoE must be enabled; by default 'power inline auto' is set, but since the ports show 'off', they may have been disabled.

The solution ensures PoE is enabled with 'power inline auto' and sets the voice VLAN correctly. Verification with 'show interfaces switchport' should show 'Voice VLAN: 20' and 'show power inline' should show 'auto' for both ports.

Exam trap

Candidates often confuse the need for a trunk port when multiple VLANs are involved, but the voice VLAN feature allows an access port to carry both data and voice traffic. Also, remember that 'power inline auto' is the default but may need to be explicitly configured if disabled. Always verify with 'show interfaces switchport' to see the voice VLAN and 'show power inline' to see PoE status.

Why the other options are wrong

B

The specific factual error is that trunk ports are used to carry multiple VLANs between switches, not for connecting end devices like phones and PCs. The correct method is to use an access port with a voice VLAN.

C

The specific factual error is that 'power inline never' explicitly disables PoE, which would prevent the phone from powering on. The correct command is 'power inline auto' to enable PoE detection and delivery.

D

The specific factual error is that the VLAN numbers are reversed. The access VLAN should be the data VLAN (10), and the voice VLAN should be 20. Swapping them would place data traffic in VLAN 20 and voice in VLAN 10, which is not the intended configuration.

315
MCQmedium

A switchport connected to an IP phone and a PC must carry user traffic and voice traffic separately. Which feature is designed for that purpose on a Cisco access port?

AnswerA

A voice VLAN is the correct feature because it lets a single access switchport carry both an IP phone's 802.1Q-tagged voice frames and the PC's untagged data frames in the native/configured access VLAN. The phone is configured to tag its media with the Voice VLAN ID while leaving PC traffic untagged, enabling logical separation of voice and data on one physical port.

Why this answer

The correct feature is a voice VLAN. In plain language, a voice VLAN lets the switch treat the IP phone’s traffic differently from the user PC’s traffic even though both devices may be connected through the same physical access port. The phone can tag voice traffic for the voice VLAN while the PC remains in the normal data access VLAN. This is a practical design because it keeps voice traffic logically separate, which helps with policy, QoS, and management.

This is a classic CCNA switching concept because it shows that one physical edge port can still support more than one logical traffic type in a controlled way. A standard access VLAN by itself would not provide the same voice/data separation. EtherChannel, SPAN, and native VLAN concepts solve different problems. The best answer is the feature specifically built to support phones and workstations together on one access connection while keeping their traffic logically distinct.

Exam trap

Be cautious not to confuse VLAN-related terms. Understand that voice VLAN is specifically designed for separating voice and data traffic on access ports.

Why the other options are wrong

B

EtherChannel is a technology used to combine multiple physical links into a single logical link for increased bandwidth and redundancy, but it does not separate user and voice traffic on a switchport. Therefore, it does not fulfill the requirement of carrying voice and user traffic separately.

C

SPAN (Switched Port Analyzer) is used for monitoring and capturing traffic on a switch port, not for separating user and voice traffic. It does not provide the necessary functionality to handle VLANs for voice and data traffic on a single port.

D

The Native VLAN is used for untagged traffic on a trunk port and does not separate voice and user traffic on an access port. It is not designed to handle the specific requirements of carrying both voice and data traffic separately.

316
Drag & Dropmedium

Drag and drop the following steps into the correct order to configure a Cisco switch access port with a data VLAN and a voice VLAN.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

First, enter global configuration mode with 'configure terminal'. Next, select the interface using 'interface GigabitEthernet0/1'. Then, set the port to access mode with 'switchport mode access' to prevent trunk negotiation.

After that, assign the data VLAN with 'switchport access vlan 10'. Finally, assign the voice VLAN with 'switchport voice vlan 20'. This order ensures the interface is properly configured before VLAN assignment and prevents DTP from creating a trunk.

317
Multi-Selectmedium

A switch should learn one MAC address on an access port and shut the port down if a second unauthorized device appears. Which two port-security settings support that requirement?

Select 2 answers
A.switchport port-security maximum 1
B.switchport port-security violation shutdown
C.switchport protected
D.switchport nonegotiate
AnswersA, B

The 'switchport port-security maximum 1' command under interface configuration enables port security and caps the number of learned secure MAC addresses to exactly one. Once a single device's MAC address is dynamically learned and stored in the secure MAC table, any additional source MAC address seen on the port is treated as a violation, triggering the configured violation action. This is the precise command needed to satisfy the requirement of learning only one MAC address, as it directly enforces the numerical limit on secure MAC entries.

Why this answer

Port security enforces how many MAC addresses may be learned on a port and what happens when a violation occurs. 'switchport port-security maximum 1' limits the port to one MAC address, and 'switchport port-security violation shutdown' disables the port if a violation occurs, matching the requirement. 'switchport protected' isolates ports within a switch but does not limit MAC addresses or cause a shutdown. 'switchport nonegotiate' disables DTP negotiation, which is unrelated to port security.

Exam trap

Be careful not to confuse the different port security violation modes. Only the shutdown mode will disable the port.

Why the other options are wrong

C

The 'switchport protected' command is used to isolate ports within a VLAN (private VLAN edge), preventing communication between protected ports. It does not limit MAC addresses or trigger port shutdown upon violation.

D

The 'switchport nonegotiate' command disables Dynamic Trunking Protocol (DTP) negotiation, preventing the port from becoming a trunk. It does not limit MAC addresses or enforce violation actions, so it cannot meet the requirement to learn one MAC and shut down on a second unauthorized device.

318
MCQhard

A user reports that a laptop can connect to the correct SSID but repeatedly fails authentication when joining the WLAN. Which category of issue is most strongly indicated?

A.A security or authentication mismatch related to WLAN access
B.A missing OSPF router ID on the access point
C.A routed-port mismatch on the switch uplink
D.A DHCP relay problem on the client
AnswerA

The client can see and associate with the SSID, but the authentication exchange fails because of mismatched security parameters—such as an incorrect pre-shared key, incompatible WPA version, or an EAP/RADIUS misconfiguration on the WLAN profile. In 802.1X or WPA2/WPA3 PSK, the four-way handshake must complete before the client is granted access; when authentication credentials or cipher suites differ between client and AP, the handshake aborts, causing repeated association attempts and a visible SSID but no successful connection.

Why this answer

The strongest indication is a wireless security or authentication mismatch rather than a pure RF coverage problem. In practical terms, the laptop can already see and attempt to join the correct SSID, which means discovery is working. Repeated authentication failure points more directly to credentials, security settings, or authentication-policy alignment than to channel or signal absence.

This question is about recognizing the stage of failure. The client is finding the WLAN, but it is not being accepted onto it.

Exam trap

A common exam trap is selecting options related to routing protocols or DHCP relay issues when a client fails to authenticate on a WLAN. Candidates may incorrectly assume that IP configuration problems or routing mismatches cause authentication failures. However, authentication occurs before IP assignment, so DHCP or OSPF issues cannot cause repeated authentication failures.

This trap distracts from the correct focus on wireless security settings and credentials, which are the root cause when a client sees the SSID but cannot authenticate.

Why the other options are wrong

B

Incorrect. OSPF router IDs are relevant to routing protocols and do not affect wireless client authentication or SSID association processes.

C

Incorrect. Routed-port mismatches on switch uplinks affect wired network traffic forwarding but do not cause wireless authentication failures at the client level.

D

Incorrect. DHCP relay problems affect IP address assignment after authentication; since the client fails authentication repeatedly, DHCP issues are not the cause.

319
PBQmedium

You are connected to SW1 via the console. SW1 is a Layer 2 switch with two VLANs (10 - Sales, 20 - Engineering). Port G0/1 is connected to a PC in VLAN 10, and port G0/2 is connected to a PC in VLAN 20. The switch needs to be configured to allow inter-VLAN communication using an external router connected to port G0/3. Currently, the PCs cannot communicate across VLANs. Configure the switch to support Router-on-a-Stick with VLAN 10 as the native VLAN on the trunk.

Network Topology
G0/1G0/1G0/3G0/3G0/0G0/0PC1SW1R1PC2

Hints

  • •Remember to set the trunk port encapsulation if needed (though modern switches default to dot1q).
  • •The native VLAN on the trunk must match what the router expects.
  • •Use switchport mode access for ports connecting to end devices.
A.Configure G0/1 as access VLAN 10, G0/2 as access VLAN 20, G0/3 as trunk with native VLAN 10, and allow VLANs 10 and 20 on the trunk.
B.Configure G0/1 as access VLAN 10, G0/2 as access VLAN 20, G0/3 as trunk with native VLAN 1, and allow VLANs 10 and 20 on the trunk.
C.Configure G0/1 as access VLAN 10, G0/2 as access VLAN 20, G0/3 as trunk with native VLAN 10, but do not allow VLAN 10 on the trunk.
D.Configure G0/1 as trunk with native VLAN 10, G0/2 as trunk with native VLAN 20, G0/3 as trunk with native VLAN 10, and allow VLANs 10 and 20 on all trunks.
AnswerA
solution
! SW1
vlan 10
name Sales
vlan 20
name Engineering
interface GigabitEthernet0/1
switchport mode access
switchport access vlan 10
interface GigabitEthernet0/2
switchport mode access
switchport access vlan 20
interface GigabitEthernet0/3
switchport mode trunk
switchport trunk native vlan 10

Why this answer

Router-on-a-Stick requires the switch port facing the router (G0/3) to be a trunk carrying both VLANs, with the native VLAN matching the router's subinterface configuration. Setting native VLAN 10 and allowing VLANs 10 and 20 on the trunk ensures both VLANs can reach the router's subinterfaces for inter-VLAN routing. The access ports G0/1 and G0/2 must remain access ports in their respective VLANs.

Exam trap

200-301 often tests the misconception that the native VLAN is optional or can be left at default — candidates pick native VLAN 1, missing that the question explicitly requires VLAN 10 as the native VLAN and that a mismatch breaks untagged traffic.

Why the other options are wrong

B

The native VLAN must match the VLAN that the router's subinterface handles as untagged. Setting it to VLAN 1 violates the requirement.

C

The trunk must carry all VLANs that need inter-VLAN communication. Excluding VLAN 10 prevents its traffic from reaching the router.

D

PCs are end devices that expect untagged frames; they should be connected to access ports, not trunk ports.

320
MCQhard

Refer to the exhibit. A network engineer is troubleshooting an EtherChannel on R1 that is not passing traffic. The output of the show etherchannel summary command is displayed. What is the most likely cause?

A.The local switch is configured with LACP passive while the remote switch is set to LACP active.
B.One side is configured with LACP active and the other side is configured with mode 'on' (static).
C.The remote switch is configured with PAgP desirable while the local switch uses LACP.
D.The port-channel member interfaces are configured as access ports, preventing LACP from negotiating.
AnswerB

With LACP active on one side and mode 'on' on the fabric peer, the 'on' port forces an EtherChannel statically and never transmits LACP PDUs, so the active LACP port never receives a response and cannot move the member port to a bundled state. The port-channel interface may still be administratively up and declared up (SU) because it exists in configuration, but the physical member ports remain in a down (D) state because no LACP negotiation completed. This exact combination produces the (D) flags on member ports while the port-channel itself remains up, making it the correct cause.

Why this answer

The 'show etherchannel summary' output shows the port-channel is down (flags indicate 'D' for down), and the most common cause when one side is configured with LACP active and the other with mode 'on' (static) is a protocol mismatch. LACP active expects to negotiate with another LACP-enabled port, but static mode 'on' forces the link up without negotiation, causing the EtherChannel to fail to form. This mismatch prevents the exchange of LACP frames, leaving the bundle in an error-disabled or non-functional state.

Exam trap

Cisco often tests the misconception that LACP passive/active is incompatible, but the real trap is confusing static mode 'on' (which disables negotiation) with LACP modes, leading candidates to overlook the protocol mismatch between LACP and static configuration.

Why the other options are wrong

A

LACP passive is not incompatible with LACP active.

C

PAgP/LACP mismatch leads to suspended state, not down; the exhibit's (D) indicates the link is not up, which points to LACP negotiation failure rather than protocol mismatch.

D

LACP negotiation is independent of the access/trunk configuration.

← PreviousPage 5 of 5 · 320 questions total

Ready to test yourself?

Try a timed practice session using only Switching Network Access questions.

CCNA Switching Network Access Questions — Page 5 of 5 | Courseiva