Courseiva
Back to Cisco DCCOR / CCNP Data Center Core 350-601 questions

Scenario-based practice

VLAN and Inter-VLAN Routing Scenarios

Practise 350-601 VLAN and trunking questions covering access ports, trunk ports, allowed VLAN lists, native VLAN, inter-VLAN routing, and command-output troubleshooting.

15
scenario questions
350-601
exam code
Cisco
vendor

Scenario guide

How to approach vlan and inter-vlan routing scenarios

VLAN misconfiguration is one of the top sources of connectivity failures in real networks and one of the most tested areas on the CCNA. These questions cover VLAN access ports, 802.1Q trunks, native VLANs, and router-on-a-stick or layer-3 switch inter-VLAN routing.

Quick answer

Routing questions usually test route selection (administrative distance, metric), how static routes are configured and when they are preferred over dynamic routing.

Administrative distance comparing routing sources.

Static route configuration: next-hop vs exit interface.

Default route propagation and the gateway of last resort.

Recursive routing table lookups.

Related practice questions

Related 350-601 topic practice pages

Scenario questions usually connect to one or more exam topics. Use these links to review the underlying concepts behind the scenario.

Practice set

Practice scenarios

Question 1hardmultiple choice
Open the full VLAN trunking answer →

During an FCoE deployment, the server team reports that hosts can reach the storage array but performance is intermittent with periodic timeouts. The network team sees no errors on the FCoE VLAN. The DCB configuration on the upstream switch shows that PFC is enabled for CoS 3. What should the engineer check next?

Question 2easymultiple choice
Full question →

A network engineer is implementing port security on a Cisco Nexus 9000 switch to limit the number of MAC addresses learned on a single access port. The switchport is configured as follows:

interface Ethernet 1/2
  switchport mode access
  switchport port-security
  switchport port-security maximum 2
  switchport port-security violation shutdown
  switchport port-security mac-address sticky

After connecting two authorized devices, a third unauthorized device is connected, causing the port to enter the err-disabled state. The engineer needs to restore connectivity for the two authorized devices as quickly as possible, while maintaining the security posture. What is the best practice to recover the port automatically in the future?

Question 3mediummultiple choice
Open the full VLAN trunking answer →

An engineer needs to extend a Layer 2 VLAN across a VXLAN EVPN fabric. Which construct maps the VLAN to the overlay network?

Question 4easymultiple choice
Open the full VLAN trunking answer →

A network engineer wants to automate the deployment of VLANs across 50 Nexus switches in a data center. Which approach provides the most consistent and repeatable results with minimal manual effort?

Question 5hardmultiple choice
Open the full VLAN trunking answer →

A data center engineer is designing a UCS Manager solution that requires VLAN segmentation across multiple fabric interconnects. The network team requires that each VLAN is assigned a unique native VLAN ID per fabric. Which pool configuration supports this requirement?

Question 6hardmultiple choice
Open the full VLAN trunking answer →

An engineer is troubleshooting a DHCP issue in a data center VLAN. Clients are unable to obtain IP addresses from the DHCP server. The switch has DHCP snooping enabled on the VLAN, and the DHCP server is connected to a trusted port. The clients are on untrusted ports. Which additional security feature is most likely causing the problem if the DHCP server is on a different subnet and the switch is not configured as a DHCP relay?

Question 7mediummultiple choice
Full question →

A server team reports that after connecting a new server to a switchport, the server can receive traffic but cannot send traffic. The port is configured with port security. What is the most likely cause?

Question 8mediummultiple choice
Open the full VLAN trunking answer →

A company uses Cisco TrustSec in its data center to enforce segmentation. Servers in VLAN 10 (Finance) should only communicate with servers in VLAN 20 (ERP) via an application gateway. Which TrustSec component is used to assign a Security Group Tag (SGT) to traffic from the Finance servers?

Question 9mediummultiple choice
Open the full VLAN trunking answer →

An engineer is deploying FCoE on a Cisco Nexus 9000v switch in a converged network. The storage array is connected via native Fibre Channel to an MDS switch, and the MDS is connected to the Nexus using an FCoE link. The engineer creates a virtual Fibre Channel (VFC) interface on the Nexus, binds it to an Ethernet interface, and maps VSAN 200 to VLAN 200. The MDS side has an FCoE port configured and enabled. Servers connected to the Nexus with FCoE initiators can successfully log into the storage targets, but performance is very poor and intermittent. The engineer checks for drops on all interfaces and finds none. The engineer also verifies that the FCoE VLAN is not blocked by spanning tree. What is the most likely cause of the performance issue?

Question 10easymultiple choice
Open the full VLAN trunking answer →

Which VLAN range is reserved by default on Cisco Nexus switches?

Question 11easymultiple choice
Open the full VLAN trunking answer →

A startup company is deploying a new web application on UCS B-Series blades. They want to use PXE boot for rapid provisioning. The network team has configured a DHCP server and a PXE server on the same VLAN as the UCS service profiles. The system administrator creates a service profile for a blade and sets the boot policy to 'PXE' as the first boot device, and local disk as second. However, when the blade powers on, it boots from the local disk instead of PXE. The PXE server logs show no request from the blade's MAC address. The DHCP server logs show no activity. The fabric interconnect is configured with a default VLAN. What is the most likely cause?

Question 12mediummultiple choice
Open the full VLAN trunking answer →

A data center engineer is troubleshooting connectivity issues between two EPGs in the same tenant on a Cisco ACI fabric. The first EPG 'web_epg' is in VLAN 100 and the second EPG 'db_epg' is in VLAN 200. The contract 'web_to_db' allows TCP port 3306 from web_epg to db_epg. The EPGs are in the same VRF. The engineer has verified that the physical connectivity is correct and the endpoints are learning their IP addresses. However, traffic from web_epg to db_epg is not reaching the destination. The engineer checks the contract and sees that the subject 'mysql_access' has filter 'mysql' with direction 'both'. The provider is db_epg and consumer is web_epg. The engineer also notices that the default action in the contract is 'deny'. What is the most likely cause of the issue?

Question 13hardmultiple choice
Open the full VLAN trunking answer →

An engineer is configuring PXE boot for a UCS B-series blade. The blade's vNIC is associated with a VLAN that has no IP helper address configured. What is required to allow the blade to obtain an IP address from a DHCP server on a different subnet?

Question 14mediummultiple choice
Open the full VLAN trunking answer →

A data center network uses MST with multiple instances. Different VLANs are mapped to different MST instances to utilize multiple spanning tree paths. Which MST parameter must be identical on all switches in the same region to ensure proper operation?

Question 15hardmulti select
Open the full VLAN trunking answer →

A Cisco MDS switch is configured with an ISL trunk between two switches. The administrator wants to enable multiple VSANs over the same physical link. Which two actions must be taken? (Choose two.)

These 350-601 practice questions are part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style 350-601 questions with detailed explanations, topic-based practice, mock exams, readiness tracking, and study analytics.