mediumMultiple Choice
CCNP Practice Question: Consider this VLAN configuration on a Cisco…
Consider this VLAN configuration on a Cisco switch:
vlan 10
name Sales
vlan 20
name Engineering
interface GigabitEthernet0/1 switchport mode trunk switchport trunk allowed vlan 10,20
What is missing if the switch needs to carry VLAN 30 traffic on this trunk?
⚠ Common exam trap
Cisco often tests the misconception that simply creating a VLAN on the switch is enough for trunk traffic, but the allowed VLAN list must also be explicitly updated, or the trunk will drop frames for that VLAN.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
VLAN 30 must be created and added to the allowed VLAN list on the trunk.
A trunk port only forwards traffic for VLANs that exist in the switch's VLAN database and are explicitly permitted in the allowed VLAN list. VLAN 30 is neither created (no 'vlan 30' command) nor added to the trunk's allowed list (missing 'switchport trunk allowed vlan add 30'), so the switch will drop any frames tagged with VLAN 30. Creating the VLAN and updating the allowed list ensures the trunk can forward VLAN 30 traffic.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
VLAN 30 must be created and added to the allowed VLAN list on the trunk.
Why this is correct
On an 802.1Q trunk, each VLAN must first exist in the switch's local VLAN database and then be explicitly included in the allowed VLAN list on the trunk interface. Without both steps, the switch filters frames for VLAN 30, even if the VLAN is defined elsewhere in the SD-Access fabric. The edge node must have a consistent local VLAN-to-SGT mapping, and traffic will be dropped in hardware if the VLAN is not present and permitted.
- ✗
The trunk must be configured as an access port for VLAN 30.
Why it's wrong here
Configuring the interface as an access port forces it to carry exactly one untagged VLAN, typically the native VLAN, and it strips 802.1Q tags from all frames. That would break the fabric's need to transport multiple VLANs with tags intact, so VLAN 30 could not be forwarded across the link alongside other VLANs. An access port cannot serve as a multi-VLAN trunk in SD-Access, and it would also disrupt the VXLAN/VLAN mapping at the edge.
- ✗
The native VLAN must be changed to VLAN 30.
Why it's wrong here
Changing the native VLAN to VLAN 30 only alters which VLAN is carried untagged on the trunk; it does not add VLAN 30 to the allowed list nor make it available for tagged traffic. Additionally, native VLAN mismatch can trigger CDP errors and spanning-tree inconsistences, but even a perfectly matched native VLAN does not permit other VLANs to traverse the link. The correct fix is to create VLAN 30 and add it to the allowed list, not to shift the native VLAN.
- ✗
The switchport mode must be changed to dynamic desirable.
Why it's wrong here
Switching the trunk mode to dynamic desirable invokes DTP to negotiate the link mode, but DTP does not influence which VLANs are permitted on the trunk or what exists in the VLAN database. The interface is already operating as a trunk, so the problem is not negotiation but the absence of VLAN 30 from the allowed list and local VLAN database. In fact, dynamic desirable can cause the link to become an access port if the peer is set to dynamic auto or does not respond, making the issue worse.
Visual reference
About these practice questions
This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.