mediumMultiple Select
350-401 Practice Question: Which two statements about the Cisco QoS trust…
Which two statements about the Cisco QoS trust boundary are true? (Choose two.)
⚠ Common exam trap
The trap here is the assumption that Cisco switches trust QoS markings out of the box — many candidates pick option C because they confuse 'QoS is enabled' with 'QoS trust is configured', when in fact trust is disabled by default on all access ports.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The trust boundary can be set at the access layer switch port connected to an IP phone.
Option A is correct because the trust boundary is typically established at the access layer switch port where an IP phone connects, since the phone can mark voice traffic with CoS/DSCP and the switch can be configured to trust those markings from the phone while untrusting traffic from an attached PC. Option B is correct because the interface-level command 'mls qos trust cos' explicitly configures the port to trust the incoming Layer 2 CoS field, allowing the switch to honor the CoS value for QoS classification and queuing. Option C is incorrect because Cisco switch interfaces do not trust incoming CoS or DSCP by default; they typically trust nothing (or default to a best-effort/CoS 0 behavior) until trust is explicitly configured. Option D is incorrect because the trust boundary is not always at the distribution layer; it is commonly placed at the access layer, though it can be extended to other points depending on design. Option E is incorrect because a switch does not automatically trust DSCP markings from an attached PC; trust must be explicitly configured, and PC traffic is generally untrusted by default.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The trust boundary can be set at the access layer switch port connected to an IP phone.
Why this is correct
Extending the trust boundary to the access switch port facing an IP phone is valid because the phone marks CoS or DSCP for attached devices, letting the switch trust those markings rather than reclassify. This satisfies the stem's requirement for a true trust boundary location, since classification occurs at the network edge.
- ✓
The 'mls qos trust cos' command configures the interface to trust the Layer 2 CoS value.
Why this is correct
Configuring `mls qos trust cos` on a switch port makes the interface accept the incoming Layer 2 CoS field as the basis for classification, extending the trust boundary to that port. This satisfies the stem's requirement for statements about where CoS marking is honoured rather than rewritten at ingress.
- ✗
By default, all Cisco switch interfaces trust the incoming CoS or DSCP marking.
Why it's wrong here
Cisco switch interfaces do not trust incoming CoS or DSCP by default; untrusted ports reset or remark those values at ingress. Trust must be configured explicitly at the boundary. It is tempting because trust is the goal at the boundary, but the default state is untrusted, so this statement is false.
- ✗
The trust boundary is always located at the distribution layer switch.
Why it's wrong here
The trust boundary sits wherever trusted devices connect, typically the access layer where IP phones or endpoints attach, not fixed at distribution. Placement depends on topology and device capability. It is tempting because distribution switches often aggregate traffic, but the boundary is defined by where marking is trusted, not by layer.
- ✗
When a PC is connected to a switch port, the switch automatically trusts the DSCP value from the PC.
Why it's wrong here
A switch port does not automatically trust DSCP from an attached PC; by default the port is untrusted and will remark or clear incoming markings. Trust requires explicit configuration. It is tempting because PCs can mark DSCP, but the switch ignores that marking unless the port is configured to trust it.
Go deeper
Related to this question
About these practice questions
This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.