350-401 Infrastructure Practice Question
An engineer needs to configure a switchport to carry traffic for multiple VLANs to a router using a single physical link. Which configuration should be applied on the switchport?
⚠ Common exam trap
It's easy for candidates to confuse Dynamic Desirable (a DTP negotiation mode) with a trunk port configuration, thinking negotiation automatically results in trunking, but the question asks for the configuration that directly enables multi-VLAN traffic, not a negotiation protocol.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure the port as a trunk port.
A trunk port is specifically designed to carry traffic for multiple VLANs over a single physical link using IEEE 802.1Q encapsulation. This allows the switch to tag frames with VLAN IDs, enabling the router (often configured as a router-on-a-stick) to route between VLANs.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure the port as a dynamic desirable port.
Why it's wrong here
Dynamic desirable negotiates a trunk via DTP, which is deprecated and disabled on many platforms; it does not guarantee a trunk forms. Carrying multiple VLANs requires an explicit 802.1Q trunk with encapsulation dot1q and allowed VLANs. Dynamic desirable would suit legacy DTP environments, not deterministic trunk configuration.
- ✓
Configure the port as a trunk port.
Why this is correct
A trunk port tags frames with 802.1Q VLAN identifiers, allowing multiple VLANs to traverse one physical link to the router. Access ports carry only a single untagged VLAN, so they cannot satisfy the multi-VLAN requirement.
- ✗
Configure the port as a routed port.
Why it's wrong here
A routed port has no VLAN encapsulation and carries one Layer 3 subnet, so it cannot multiplex multiple VLANs. It is tempting because routed ports are correct for a point-to-point Layer 3 link between a switch and router without VLAN tagging.
- ✗
Configure the port as an access port.
Why it's wrong here
An access port carries untagged traffic for a single VLAN, so it cannot separate multiple VLANs over one link. It is tempting because access ports are the standard choice when connecting a single host or a router subinterface that terminates one VLAN only.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.