Courseiva
Architecture →easyMultiple Choice

CCNP Architecture Practice Question

A small business has a single router connected to the internet and a switch for the LAN. They want to implement VLANs to separate guest and corporate traffic. The router has only one physical interface to the switch. The network engineer proposes using subinterfaces with 802.1Q trunking on the router interface. Which configuration step is required on the switch port connected to the router?

⚠ Common exam trap

Cisco often tests the misconception that a switch port connecting to a router can remain as an access port or use DTP, but the key is that the router's subinterface requires 802.1Q-tagged frames, which only a statically configured trunk port can provide.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure the port as a trunk port.

The router uses subinterfaces with 802.1Q trunking to carry multiple VLANs over a single physical link. For this to work, the switch port connected to the router must be configured as a trunk port, which tags frames with VLAN IDs as they traverse the link. This allows the router to route between VLANs using its subinterfaces, each associated with a specific VLAN.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure the port as a routed port.

    Why it's wrong here

    A routed port is a Layer 3 interface created with the no switchport command and is designed for point-to-point routed links, not for carrying multiple VLANs. Because it operates at Layer 3, it strips any 802.1Q VLAN tags and cannot deliver tagged frames to router subinterfaces. As a result, subinterfaces configured for VLANs would receive no tagged traffic, and inter-VLAN routing over that link would fail.

  • ✗

    Configure the port as an access port in VLAN 1.

    Why it's wrong here

    An access port in VLAN 1 assigns all inbound and outbound frames to a single untagged VLAN, removing any VLAN tag before sending frames to the router. Router subinterfaces using encapsulation dot1Q rely on receiving 802.1Q-tagged frames to identify which VLAN each frame belongs to; with only untagged VLAN 1 traffic, all other VLAN subinterfaces remain silent. This confines routing to one VLAN, defeating the purpose of supporting multiple VLANs on the single router link.

  • ✓

    Configure the port as a trunk port.

    Why this is correct

    A trunk port carries frames from multiple VLANs and tags each frame with its 802.1Q VLAN ID, except for the native VLAN which remains untagged. Router subinterfaces configured with encapsulation dot1Q can accept these tagged frames, allowing the router to route between VLANs over one physical link. This is the required configuration for router-on-a-stick inter-VLAN routing when a single router interface must handle traffic for many VLANs.

  • ✗

    Configure the port as a dynamic desirable port.

    Why it's wrong here

    Dynamic desirable mode uses DTP (Dynamic Trunking Protocol) to actively offer and negotiate trunking with the neighboring device, but it is a negotiation mechanism rather than an operational interface state. A Cisco router does not run DTP, so the negotiation will not succeed unless the router is manually configured to trunk, and the link may remain an access port. Even when negotiation works, relying on DTP is not deterministic; the switch port should be explicitly configured as a trunk to guarantee 802.1Q tagging.

Visual reference

Switch VLAN 10 Sales (192.168.10.0/24) PC-A PC-B VLAN 20 HR (192.168.20.0/24) PC-C PC-D Router VLANs isolate traffic — inter-VLAN routing requires a Layer 3 device

About these practice questions

One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.