mediumMultiple SelectObjective-mapped
350-401 Practice Question: Which two statements about the Cisco QoS trust…
Which two statements about the Cisco QoS trust boundary are true? (Choose two.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The trust boundary can be set at the access layer switch port connected to an IP phone.
The trust boundary defines where the device accepts or overwrites Layer 2 CoS or Layer 3 DSCP markings. By default, Cisco switches trust the CoS value on trunk ports and set DSCP to 0 on access ports. The 'mls qos trust cos' command forces the switch to trust CoS, and 'mls qos trust dscp' forces trust of DSCP. The trust boundary can be extended to an IP phone, which then re-marks traffic from the PC. Option C is incorrect because trust is not automatically applied to all interfaces; it must be configured. Option D is incorrect because the trust boundary is at the access layer, not the core. Option E is incorrect because the switch does not automatically trust DSCP from a PC; it typically sets it to 0 unless configured otherwise.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The trust boundary can be set at the access layer switch port connected to an IP phone.
Why this is correct
Correct because the trust boundary is typically configured at the access layer, and can be extended to the IP phone to mark traffic from the PC.
- ✓
The 'mls qos trust cos' command configures the interface to trust the Layer 2 CoS value.
Why this is correct
Correct because this command sets the trust state to use the CoS value for QoS classification.
- ✗
By default, all Cisco switch interfaces trust the incoming CoS or DSCP marking.
Why it's wrong here
Incorrect because by default, Cisco switches do not trust markings; they set DSCP to 0 on access ports and trust CoS on trunk ports only after QoS is enabled globally.
- ✗
The trust boundary is always located at the distribution layer switch.
Why it's wrong here
Incorrect because the trust boundary is typically at the access layer, closest to the endpoint, to prevent unauthorized marking changes.
- ✗
When a PC is connected to a switch port, the switch automatically trusts the DSCP value from the PC.
Why it's wrong here
Incorrect because the switch does not automatically trust DSCP from a PC; it sets DSCP to 0 unless trust is explicitly configured.
Visual reference
Go deeper
Related to this question
About these practice questions
This 350-401 question is part of Courseiva's 1,175-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.