Courseiva
Network Assurance →easyMultiple Choice

CCNP Network Assurance Practice Question

A network administrator is troubleshooting a performance issue in a large enterprise campus network. The network consists of Cisco Catalyst 9300 switches acting as access switches and Cisco Catalyst 9500 switches as distribution. Users on VLAN 10 report intermittent slow file transfers to a server on VLAN 20. The administrator has verified that there are no errors on the links, CPU utilization is normal, and STP topology is stable. The administrator suspects a possible QoS issue. Upon checking the QoS configuration on the access switch, the administrator finds that the default QoS configuration is in place, which trusts the CoS value at the port level. The connected devices are IP phones and PCs; the IP phones mark voice traffic with CoS 5. The server on VLAN 20 is connected to a distribution switch. Which action should the administrator take to most likely resolve the issue?

⚠ Common exam trap

Cisco often tests the misconception that simply trusting CoS or DSCP values is sufficient to prioritize traffic, when in fact trust alone does not configure the egress queuing and scheduling policies needed to prevent congestion and ensure bandwidth allocation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure auto QoS for VoIP on the access ports to ensure proper classification and queuing.

Auto QoS for VoIP automatically configures the necessary class maps, policy maps, and trust settings to properly classify and queue voice traffic (CoS 5) while ensuring data traffic is not starved. The default QoS configuration trusts CoS at the port level, but without proper queuing and scheduling, voice and data may compete for buffers, causing intermittent slow file transfers. Auto QoS sets up strict priority queuing for voice and allocates bandwidth for data, resolving the performance issue without manual misconfiguration.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Apply a policy map that polices voice traffic to 128 kbps to free bandwidth for data.

    Why it's wrong here

    Policing voice traffic to a fixed 128 kbps rate is inherently counterproductive for QoS. Voice streams, such as G.711 or G.729, require guaranteed bandwidth and are highly sensitive to packet drops; a policer will drop any excess traffic, causing jitter and audible glitches during congestion. Moreover, this approach treats voice as something to be constrained rather than protected, and the freed bandwidth does not compensate for the compromised call quality.

  • ✗

    Disable QoS entirely on all switches to eliminate any potential QoS-related drops.

    Why it's wrong here

    Disabling QoS on all switches removes the classification, marking, and queuing mechanisms that protect time-sensitive voice traffic. Without QoS, voice packets compete equally with bulk data in the same best-effort queue, leading to unnecessary delay, jitter, and packet loss under normal network contention. This will likely worsen the very performance issue being diagnosed, as modern LANs depend on QoS to ensure that voice is prioritized over less critical traffic.

  • ✓

    Configure auto QoS for VoIP on the access ports to ensure proper classification and queuing.

    Why this is correct

    Auto QoS for VoIP on access ports dynamically configures the necessary trust boundaries, classification, and egress queuing to properly handle voice traffic. It typically sets the ingress port to trust CoS for the connected IP phone, marks voice traffic appropriately, and places it in the priority queue to minimize latency and drop risk. This is the correct remediation because it matches the network behavior to the requirements of voice—ensuring priority without manual, error-prone configuration.

  • ✗

    Configure trust DSCP on the access ports to prioritize all traffic based on DSCP values.

    Why it's wrong here

    Configuring trust DSCP on access ports indiscriminately accepts the DSCP values set by any attached endpoint, but many devices do not mark traffic correctly (or at all). Without sourcing classification, untrusted traffic could be prioritized as 'expedited forwarding' and preempt voice, while legitimate voice may be dropped if the endpoint marks it identically to bulk data. Auto QoS avoids this by only trusting markings from known IP phones and using port-based identification, so trusting DSCP network-wide is not an appropriate solution.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.