Courseiva
Architecture →mediumMultiple Choice

CCNP Architecture Practice Question

A network administrator is deploying QoS in a converged network. Which approach correctly implements trust boundaries and marking?

⚠ Common exam trap

Cisco often tests the misconception that trust boundaries should be placed at the distribution or core layer for simplicity, but the trap is that marking must happen at the access layer to prevent untrusted endpoints from injecting high-priority traffic into the network.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Set trust boundary at the access layer switch and re-mark packets based on source.

In a converged network, trust boundaries should be established at the access layer to ensure that marking decisions are made as close to the source as possible. By setting the trust boundary at the access layer switch and re-marking packets based on source (e.g., trusting only IP phones while re-marking workstation traffic), the network can enforce policy before traffic enters the core, preventing unauthorized or misconfigured endpoints from influencing QoS markings. This aligns with Cisco's best practice of trusting only known devices and re-marking all other traffic to a default or lower priority.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Set trust boundary at the access layer switch and re-mark packets based on source.

    Why this is correct

    The access layer is the optimal trust boundary because it is the first device in the path that can inspect source identities (e.g., IP phone vs. workstation) with port-level granularity. Re-marking DSCP here ensures that packets enter the network with a consistent QoS class, allowing all downstream switches to rely on these markings for queuing and policing. This prevents untrusted end devices from dictating their own priority, which is essential for converged networks carrying voice, video, and data.

  • ✗

    Configure marking only at the core layer to simplify policy.

    Why it's wrong here

    Configuring marking only at the core layer is ineffective because by the time packets reach the core, they have already traversed lower layers where congestion and queuing decisions have occurred. The core's primary role is high-speed forwarding, not deep packet inspection, and any marking applied there cannot influence how access and distribution switches handled the traffic. This approach fails to provide end-to-end QoS, as upstream prioritization must be set at the edge to benefit all subsequent hops.

  • ✗

    Trust only the distribution layer switches to mark traffic.

    Why it's wrong here

    Trusting distribution layer switches to mark traffic is flawed because packets have already passed through access switches where oversubscription and queuing on access links may cause drops before any marking is applied. Additionally, distribution switches aggregate traffic from many sources, making source-based re-marking coarse and operationally complex, while also shifting the trust boundary away from the actual endpoint. QoS policies should be enforced as close to the source as possible, not after the traffic has already been subjected to network conditions.

  • ✗

    Trust the DSCP values set by IP phones and workstations.

    Why it's wrong here

    Trusting DSCP values set by IP phones and workstations is risky because these end devices are not under administrative control and can be misconfigured, compromised, or intentionally spoofed to gain unwanted priority. End-user applications may also set arbitrary DSCP values that conflict with network policy, leading to bandwidth abuse or ineffective queuing. The network must re-mark at the access switch to establish a trusted boundary and enforce a consistent classification based on the device and application type, not on potentially untrustworthy labels.

About these practice questions

This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.