easyMultiple Choice
200-901 Practice Question: Is configuring a new switch and needs to ensure…
A network engineer is configuring a new switch and needs to ensure that frames from VLAN 10 and VLAN 20 are isolated on the same trunk link to another switch. Which IEEE standard should be configured on the trunk interfaces?
⚠ Common exam trap
Cisco often tests the distinction between 802.1Q (VLAN tagging) and 802.1X (authentication), so the trap here is confusing a trunking protocol with a security protocol, leading candidates to pick 802.1X when the question is about VLAN isolation on a trunk.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
802.1Q
C is correct because 802.1Q is the IEEE standard that defines VLAN tagging, allowing multiple VLANs (such as VLAN 10 and VLAN 20) to be carried over a single trunk link while maintaining isolation between them. By inserting a 4-byte VLAN tag into the Ethernet frame, 802.1Q enables the receiving switch to identify which VLAN a frame belongs to, ensuring traffic from different VLANs remains separate.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
802.3
Why it's wrong here
802.3 defines Ethernet framing and CSMA/CD at the MAC layer, carrying no VLAN tag information, so it cannot isolate VLAN 10 from VLAN 20 across a trunk. It is tempting because 802.3 is the foundational Ethernet standard underlying all switch ports, but VLAN tagging requires 802.1Q.
- ✗
802.11
Why it's wrong here
802.11 defines wireless LAN MAC and PHY layers for Wi-Fi, not wired trunk encapsulation, so it cannot isolate VLANs on a switch trunk link. It is tempting because 802.11 is a widely recognised IEEE networking standard, but VLAN tagging across trunks is governed by 802.1Q.
- ✓
802.1Q
Why this is correct
802.1Q defines VLAN tagging on trunk links, inserting a tag into each frame to identify its VLAN. This lets VLAN 10 and VLAN 20 traffic traverse the same trunk while remaining logically isolated, exactly as the scenario requires.
- ✗
802.1X
Why it's wrong here
802.1X provides port-based network access control, authenticating devices before granting switch port access; it does not tag or separate VLAN traffic on a trunk. It is tempting because 802.1X is configured on switch ports and relates to VLAN assignment after authentication, but trunk isolation needs 802.1Q tagging.
Visual reference
About these practice questions
Courseiva writes every 200-901 question from scratch — 975 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.