Courseiva
easyMultiple Choice

CCNP Practice Question: The default trust state of a Cisco IOS switch…

What is the default trust state of a Cisco IOS switch port when no 'mls qos trust' command is configured?

⚠ Common exam trap

Cisco often tests the misconception that a switch port will trust existing markings by default, but the correct default behavior is to treat all ports as untrusted and apply CoS 0.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The port is untrusted and marks all incoming packets with CoS 0.

By default, Cisco IOS switch ports are untrusted for QoS. Without the 'mls qos trust' command, the port does not trust any Layer 2 CoS or Layer 3 DSCP markings. Instead, it applies a default CoS value of 0 to all incoming packets, effectively re-marking them to the lowest priority. This ensures that traffic from untrusted sources (e.g., end hosts) does not retain potentially high-priority markings.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The port trusts the CoS value of incoming packets.

    Why it's wrong here

    Trusting CoS would require explicit interface configuration such as "mls qos trust cos" to preserve the 802.1p priority carried in the Ethernet header. The default switchport state is untrusted, meaning the switch does not honor any incoming CoS markings and instead forces all packets to a best-effort CoS value of 0, so this option is false.

  • ✗

    The port trusts the DSCP value of incoming packets.

    Why it's wrong here

    DSCP trust is an IP-layer behavior configured with "mls qos trust dscp" and can only apply to IP packets that already contain a DSCP field. In the default configuration, the switchport is untrusted and does not inspect the DSCP value for ingress classification; all traffic is re-marked with CoS 0, which is not the same as trusting DSCP, making this option incorrect.

  • ✓

    The port is untrusted and marks all incoming packets with CoS 0.

    Why this is correct

    When QoS is globally enabled, all switchports default to an untrusted state, meaning they do not preserve any priority information carried in incoming frames. Every packet received on such a port is marked with CoS 0 (and correspondingly DSCP 0) before entering the switch fabric, so saying the port is untrusted and marks all packets with CoS 0 accurately describes the default behavior.

  • ✗

    The port trusts both CoS and DSCP values.

    Why it's wrong here

    The default state of a switchport is untrusted, not a dual-trust mode for both Layer 2 CoS and Layer 3 DSCP values. Trusting both fields would require intentional configuration of trust policies, and even then the switch would only honor those fields according to its mapping tables; an unconfigured port overwrites both CoS and DSCP to 0, so this option is incorrect.

About these practice questions

One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.