Courseiva
Infrastructure →mediumMultiple Choice

350-401 Infrastructure Practice Question

A network engineer is configuring QoS on a Cisco IOS switch. The engineer needs to mark packets coming from a specific server with DSCP EF (46) and ensure that this marking is trusted throughout the network. Which command should be used to trust the DSCP markings on the interface connected to the server?

⚠ Common exam trap

Test-takers frequently confuse trust boundaries and assuming that trusting CoS is equivalent to trusting DSCP, even when the server sends untagged frames.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

mls qos trust dscp

To trust DSCP markings on an interface, the correct command is 'mls qos trust dscp'. This tells the switch to accept the DSCP value in incoming packets and use it for QoS processing. Since the server is already marking its traffic with DSCP EF, this command ensures that the marking is preserved and honored throughout the network, preventing the switch from re-marking the packets.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    mls qos trust dscp

    Why this is correct

    The 'mls qos trust dscp' command configures the interface to trust the DSCP value in incoming packets. This means the switch will use the existing DSCP marking for classification and queuing, rather than overwriting it. This is appropriate when the server is already marking its traffic with DSCP EF, as it preserves the marking and ensures proper treatment across the network.

  • ✗

    mls qos trust cos

    Why it's wrong here

    The 'mls qos trust cos' command trusts the CoS value in the Layer 2 header. CoS is only present on trunk links or 802.1Q tagged frames. If the server is not sending tagged frames, the CoS will be 0, and the DSCP marking will be lost. Therefore, this command does not meet the requirement to trust DSCP markings from the server.

  • ✗

    mls qos trust ip-precedence

    Why it's wrong here

    The 'mls qos trust ip-precedence' command trusts the IP precedence field (the top 3 bits of the ToS byte). DSCP uses the top 6 bits, so trusting IP precedence would only consider the first 3 bits and ignore the rest. This would not correctly preserve the DSCP EF marking, which is 46 (binary 101110). Therefore, this command is not suitable for trusting DSCP.

  • ✗

    mls qos map cos-dscp 0 8 16 24 32 40 48 56

    Why it's wrong here

    The 'mls qos map cos-dscp' command defines the mapping between CoS and DSCP values for internal use, but it does not configure the interface to trust incoming DSCP markings. This command is used when the switch needs to derive DSCP from CoS, typically on ingress from non-IP traffic. It does not satisfy the requirement to trust DSCP on the server-facing interface.

About these practice questions

One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.