Courseiva
Security →easyMultiple Choice

CCNP Security Practice Question

A network engineer is configuring a Cisco Catalyst switch to mitigate VLAN hopping attacks. The switch has multiple access ports assigned to VLAN 10 and trunk ports connecting to other switches. The engineer wants to ensure that an attacker cannot send double-tagged frames to hop into another VLAN. Which action should the engineer take on all access ports?

⚠ Common exam trap

The trap here is thinking that BPDU Guard or native VLAN changes on access ports prevent VLAN hopping, when the primary mitigation is disabling DTP and forcing access mode.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure the access ports with the switchport mode access command and disable Dynamic Trunking Protocol (DTP) on them.

To mitigate VLAN hopping, access ports should be explicitly configured as access ports and DTP should be disabled to prevent trunk negotiation. Attackers can use DTP to negotiate a trunk and then send tagged frames to access other VLANs. Disabling DTP with 'switchport nonegotiate' on access ports prevents this. The other options either do not address the attack or are misconfigurations.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure the access ports with the switchport mode access command and enable BPDU Guard.

    Why it's wrong here

    BPDU Guard is used to protect against spanning-tree attacks by disabling ports that receive BPDUs, typically on PortFast-enabled access ports. It does not prevent VLAN hopping. While it is a good security practice, it does not address the double-tagging or DTP-based VLAN hopping attack. The primary mitigation for VLAN hopping is to disable DTP and set ports to access mode.

  • ✗

    Configure the access ports with the switchport mode trunk command and set the native VLAN to an unused VLAN.

    Why it's wrong here

    Configuring access ports as trunk ports is incorrect; access ports should not be trunks. While setting the native VLAN to an unused VLAN is a good practice on trunk ports, applying it to access ports is not applicable. This configuration would actually increase the attack surface by allowing trunking on ports connected to end devices.

  • ✓

    Configure the access ports with the switchport mode access command and disable Dynamic Trunking Protocol (DTP) on them.

    Why this is correct

    Setting access ports to access mode and disabling DTP prevents the port from negotiating a trunk, which is a primary vector for VLAN hopping attacks. Attackers can exploit DTP to form a trunk and gain access to all VLANs. By explicitly configuring the port as access and disabling DTP with 'switchport nonegotiate', the port will not trunk. This is a recommended best practice.

  • ✗

    Configure the access ports with the switchport mode access command and assign them to the native VLAN.

    Why it's wrong here

    Assigning access ports to the native VLAN does not prevent VLAN hopping. In fact, if the native VLAN is not changed from the default VLAN 1, it could increase the risk. The key mitigation is to change the native VLAN on trunk ports and to ensure access ports are not trunking. Simply assigning access ports to the native VLAN is not a valid mitigation.

Visual reference

Switch VLAN 10 Sales (192.168.10.0/24) PC-A PC-B VLAN 20 HR (192.168.20.0/24) PC-C PC-D Router VLANs isolate traffic — inter-VLAN routing requires a Layer 3 device

About these practice questions

Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.