Courseiva
mediumMultiple Choice

CCNP Practice Question: Given the following snippet from a Cisco 9800…

Given the following snippet from a Cisco 9800 WLC:

ap ethernet-port default-ethernet-port

description "Default Ethernet Port"

mode trunk allowed vlan 10,20,30 native vlan 10

What is the effect of this configuration on the AP?

⚠ Common exam trap

Cisco often tests the misconception that the native VLAN is always tagged or that the AP's trunk port behaves like a switch trunk, when in fact the native VLAN carries untagged management traffic and the allowed VLANs carry tagged client traffic.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The AP will use VLAN 10 for management traffic and VLANs 20 and 30 for client traffic.

The configuration sets the AP's Ethernet port as a trunk port with VLAN 10 as the native VLAN and allowed VLANs 10, 20, and 30. In Cisco wireless architectures, the AP uses the native VLAN (VLAN 10) for management traffic (e.g., CAPWAP control) and the other allowed VLANs (20 and 30) for client data traffic, which is tunneled via CAPWAP to the WLC. This matches option B.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The AP's Ethernet port will tag all traffic with VLAN 10.

    Why it's wrong here

    On a trunk port, the native VLAN is transmitted without an 802.1Q tag, while all other allowed VLANs are explicitly tagged. Since the configuration sets VLAN 10 as the native VLAN for AP management traffic, those frames remain untagged. Thus, the claim that all traffic is tagged with VLAN 10 is false; only client VLANs 20 and 30 are tagged.

  • ✓

    The AP will use VLAN 10 for management traffic and VLANs 20 and 30 for client traffic.

    Why this is correct

    This is correct because the switchport trunk native vlan 10 command makes VLAN 10 the untagged, management VLAN for the AP, while the switchport trunk allowed vlan 20,30 command permits tagged client traffic on those VLANs. The AP's management IP resides in VLAN 10, and SSIDs are mapped to VLAN 20 and 30 for client data, maintaining separation between management and user traffic.

  • ✗

    The AP will only allow VLAN 10 traffic.

    Why it's wrong here

    The configuration explicitly includes VLANs 20 and 30 in the allowed list, so the AP trunk carries far more than just VLAN 10. Only if the allowed vlan command had specified a single VLAN would this statement hold. Since multiple VLANs are permitted, the claim that only VLAN 10 traffic is allowed is incorrect.

  • ✗

    The AP's Ethernet port is configured as an access port.

    Why it's wrong here

    A port configured with switchport mode trunk is by definition not an access port; it uses 802.1Q tagging to transport multiple VLANs and negotiates trunking via DTP if not set to nonegotiate. An access port would carry only one untagged VLAN and would not support the multiple client VLANs described. Therefore, this statement misidentifies the port mode.

Visual reference

Switch VLAN 10 Sales (192.168.10.0/24) PC-A PC-B VLAN 20 HR (192.168.20.0/24) PC-C PC-D Router VLANs isolate traffic — inter-VLAN routing requires a Layer 3 device

About these practice questions

One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.