Courseiva
Infrastructure →mediumMultiple Choice

350-401 Infrastructure Practice Question

A network engineer is configuring a new Cisco IOS switch that will be deployed in a data center. The switch must forward traffic for VLAN 10 while ensuring that the native VLAN for all trunk ports is not susceptible to VLAN hopping attacks. The engineer decides to change the native VLAN from the default to an unused VLAN 999. Which command sequence correctly configures the native VLAN on a trunk port?

⚠ Common exam trap

Many exam-takers confuse the native VLAN with an allowed VLAN or an access VLAN, and forgetting to set the port to trunk mode first.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

interface GigabitEthernet0/1 switchport mode trunk switchport trunk native vlan 999

The correct configuration requires entering interface configuration mode, setting the port to trunk mode, and then specifying the native VLAN with 'switchport trunk native vlan 999'. This ensures that untagged traffic is associated with an unused VLAN, reducing VLAN hopping risk. The other options either misconfigure the port mode or do not properly set the native VLAN.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    vlan 999 name NATIVE interface GigabitEthernet0/1 switchport mode trunk switchport trunk allowed vlan 999

    Why it's wrong here

    This creates VLAN 999 and allows it on the trunk, but does not set it as the native VLAN. Allowing VLAN 999 does not change the native VLAN, which remains VLAN 1 by default. This does not mitigate VLAN hopping and fails to meet the requirement.

  • ✗

    interface GigabitEthernet0/1 switchport trunk encapsulation dot1q switchport trunk native vlan 999 switchport mode trunk

    Why it's wrong here

    While this sequence includes the native VLAN command, it also includes 'switchport trunk encapsulation dot1q'. On modern Cisco switches, this command may not be available or necessary, and the order of commands is not critical. However, this option is not the best because it adds an extra command that may cause errors on some platforms.

  • ✓

    interface GigabitEthernet0/1 switchport mode trunk switchport trunk native vlan 999

    Why this is correct

    This sequence enters interface configuration mode, sets the port to trunk mode, and assigns VLAN 999 as the native VLAN. This is the correct Cisco IOS syntax to change the native VLAN on a trunk port, mitigating VLAN hopping by using an unused VLAN.

  • ✗

    interface GigabitEthernet0/1 switchport mode access switchport access vlan 999

    Why it's wrong here

    This configures the port as an access port in VLAN 999, not a trunk. It would not carry multiple VLANs, and the native VLAN concept applies only to trunk ports. This does not meet the requirement to forward VLAN 10 traffic and change native VLAN on trunk.

Visual reference

Switch VLAN 10 Sales (192.168.10.0/24) PC-A PC-B VLAN 20 HR (192.168.20.0/24) PC-C PC-D Router VLANs isolate traffic — inter-VLAN routing requires a Layer 3 device

About these practice questions

Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.