Courseiva
mediumMultiple Choice

CCNP Practice Question: Runs the following command on Switch SW1: SW1#…

A network engineer runs the following command on Switch SW1:

SW1# show interfaces gi0/1 trunk

Port Mode Encapsulation Status Native vlan Gi0/1 desirable n-802.1q trunking 1

Port Vlans allowed on trunk Gi0/1 1-1005

Port Vlans allowed and active in management domain Gi0/1 1,10,20

Port Vlans in spanning tree forwarding state and not pruned Gi0/1 1,10,20

Based on this output, what can be concluded?

⚠ Common exam trap

Test-takers frequently confuse 'allowed on trunk' with 'active in management domain', leading them to assume all allowed VLANs are actually forwarding traffic, when in fact only those listed in the second line are active.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

VLANs 2-9 are allowed but not active.

The output shows that VLANs 1-1005 are allowed on the trunk, but only VLANs 1, 10, and 20 are active in the management domain. This means VLANs 2-9 and 11-19, 21-1005 are allowed but not active (i.e., not created or not present on the switch). Option C correctly identifies that VLANs 2-9 are among those allowed but not active.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The interface is configured as an access port.

    Why it's wrong here

    The interface is not an access port because the output shows 'Mode: desirable' (or 'Administrative Mode: dynamic desirable') and an operational trunking mode. In dynamic desirable mode, the interface actively sends DTP frames to negotiate trunking with the neighbor, and if the neighbor is set to trunk or desirable, the link becomes an 802.1Q trunk. An access port would instead show 'Mode: access' and would not have an allowed VLAN list or native VLAN configuration.

  • ✗

    The trunk is using ISL encapsulation.

    Why it's wrong here

    The output clearly lists 'Encapsulation: n-802.1q', which means the trunking protocol was negotiated as IEEE 802.1Q, not Cisco's proprietary Inter-Switch Link (ISL). ISL, if used, would appear as 'isl' and is a deprecated, frame-tagging encapsulation that adds a 26-byte header and 4-byte trailer, whereas 802.1Q inserts a 4-byte tag and is the industry standard. Since the encapsulation is negotiated 802.1Q, the ISL statement is false.

  • ✓

    VLANs 2-9 are allowed but not active.

    Why this is correct

    This is correct because the trunk's allowed VLAN list permits VLANs 1-1005, but the VLAN database only has VLANs 1, 10, and 20 in an active/up state (for instance, 'Status: active'). VLANs 2-9 are therefore permitted on the trunk but are not active, so they will not carry traffic until they are created and brought up, or until ports are assigned to them. Being allowed on a trunk does not make a VLAN operationally active; the VLAN must exist and have an active administrative state.

  • ✗

    The native VLAN is 10.

    Why it's wrong here

    The native VLAN shown in the output is the default of 1, not 10. In 802.1Q trunking, the native VLAN is the one VLAN whose frames are transmitted untagged, and it must match on both ends of the trunk to avoid native VLAN mismatch problems (which can cause spanning-tree loops or unexpected traffic). If the native VLAN had been changed to 10, the output would explicitly show 'Native VLAN: 10' and the command 'switchport trunk native vlan 10' would have been present in the configuration.

Visual reference

SW1 Root Bridge SW2 SW3 BLK DP DP RP RP STP blocks one link to prevent loops DP = Designated Port RP = Root Port BLK = Blocked

About these practice questions

This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.