mediumMultiple Choice
350-401 Practice Question: Deploying a new campus network with a…
A company is deploying a new campus network with a hierarchical design (core, distribution, access). The QoS design must ensure that voice traffic is prioritized end-to-end, and that marking is trusted only on access ports connected to IP phones. Which architectural approach should the architect take for classification and marking?
⚠ Common exam trap
Cisco often tests the concept that the trust boundary must be set at the access layer, not at the distribution or core, and that trusting DSCP from IP phones is the correct method, while remarking all traffic to a single value or ignoring markings entirely are common misconceptions that break end-to-end QoS.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure the access switches to trust DSCP on ports connected to IP phones, and apply queuing policies on distribution and core switches that match the trusted markings.
It aligns with the Cisco QoS trust boundary model for campus networks. IP phones are trusted endpoints that mark voice traffic with the correct DSCP values (e.g., EF for voice, AF41 for video). By configuring the access switch port to trust DSCP from the IP phone, the marking is preserved end-to-end. Distribution and core switches then apply queuing policies (e.g., LLQ) based on these trusted markings, ensuring voice traffic receives priority treatment across the entire network.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Configure the access switches to trust DSCP on ports connected to IP phones, and apply queuing policies on distribution and core switches that match the trusted markings.
Why this is correct
Trusting DSCP on IP phone ports is the correct trust boundary because Cisco IP phones set Expedited Forwarding (EF, DSCP 46) for voice RTP; access switches should preserve this marking via 'mls qos trust dscp' rather than re-marking. With those markings intact, distribution and core switches can apply consistent queuing policies—strict priority for EF voice, class-based queuing for call signaling (CS3/AF31) and data—so voice quality is maintained end to end and the trust boundary stays at the access layer.
- ✗
Remark all traffic to a single DSCP value at the access layer and apply priority queuing at the core.
Why it's wrong here
Re-marking all traffic to a single DSCP value, such as DSCP 0, at the access layer removes the very differentiation QoS depends on. The core's priority queue would then contain every class of traffic, so voice packets no longer receive the strict priority treatment they need; either the queue overflows and drops voice, or you would have to also discard the EF markings that identify voice RTP. This breaks Cisco's end-to-end QoS model, which requires distinct DSCP per class to support per-hop behavior.
- ✗
Apply QoS policies only at the core layer, ignoring markings from the access layer.
Why it's wrong here
Applying QoS only at the core while ignoring access-layer markings is flawed because classification must happen as close to the source as possible, and the access switch is the trust boundary for IP phone DSCP. If the access switch is not configured to trust DSCP, it will reset packets to the default DSCP (often 0) on egress, so the core receives no meaningful markings to act on—it would need to reclassify every flow from raw packet inspection. Even if the core can infer QoS, the access layer still needs to police/trust at the edge, otherwise the markings are nonexistent when they arrive.
- ✗
Use the distribution layer to reclassify traffic based on source MAC addresses of IP phones.
Why it's wrong here
Reclassifying traffic at the distribution layer by source MAC address of IP phones is impractical and fragile because it relies on static L2 bindings that break when phones are moved, replaced, or when MAC spoofing occurs, and it requires the distribution switch to know every phone MAC. DSCP trust is the industry-standard approach because it uses L3 markings already set by phones—like EF for voice—making the policy protocol-independent and scalable to large campuses, whereas MAC-based classification is CPU-intensive, non-standard, and does not align with Cisco's recommended trust boundary at the access port.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.