hardMultiple Select
350-401 Practice Question: Which three statements about the classification…
Which three statements about the classification and marking tools in Cisco IOS are true? (Choose three.)
⚠ Common exam trap
The trap here is assuming that 'set dscp' only works on egress or that MPLS EXP is automatically derived from DSCP without configuration; candidates often overlook that marking can occur on ingress and that MPLS QoS requires explicit mapping.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The trust boundary can be configured using the 'mls qos trust' command on a switch port to trust the CoS or DSCP value received from an attached device.
Option A is correct because the 'mls qos trust' interface command (e.g., 'mls qos trust cos' or 'mls qos trust dscp') establishes the trust boundary on a switch port, instructing the switch to accept and honor the CoS or DSCP values already present in frames received from an attached device rather than re-marking them. Option B is correct because NBAR is a Cisco IOS classification engine that inspects packet payloads and matches application signatures, including HTTP URL strings and SSL/TLS certificate fields, allowing granular application-aware classification beyond simple Layer 3/Layer 4 criteria. Option C is correct because the 802.1Q tag carries a 3-bit Priority Code Point (CoS) field yielding 8 values (0-7), while the IP header's DSCP field is 6 bits yielding 64 values (0-63), which is the fundamental difference in granularity between Layer 2 and Layer 3 marking. Option D is incorrect because 'set dscp' in a policy map can be applied on ingress or egress, not exclusively egress. Option E is incorrect because MPLS EXP bits are not automatically mapped from IP DSCP; mapping between DSCP and EXP requires explicit configuration (e.g., via table-map or policy), so the 'always directly mapped' claim is false.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The trust boundary can be configured using the 'mls qos trust' command on a switch port to trust the CoS or DSCP value received from an attached device.
Why this is correct
The mls qos trust command on a switch port establishes the trust boundary, instructing the switch to accept and preserve the CoS or DSCP markings already applied by the attached device instead of reclassifying the traffic.
- ✓
NBAR (Network-Based Application Recognition) can classify traffic based on application signatures, including HTTP URLs and SSL certificate fields.
Why this is correct
NBAR performs deep packet inspection against protocol signatures, so it recognises applications by payload characteristics such as HTTP URL strings and SSL certificate fields, rather than relying solely on port numbers or Layer 3 addresses.
- ✓
Layer 2 CoS marking uses a 3-bit field in the 802.1Q tag, providing 8 possible values, while DSCP uses 6 bits for 64 values.
Why this is correct
CoS occupies the 3-bit Priority Code Point field inside the 802.1Q tag, giving eight values, whereas DSCP occupies six bits of the IP header ToS byte, giving sixty-four values, so the two marking schemes differ in width.
- ✗
The 'set dscp' command in a policy map can be used to mark packets with a DSCP value, but only on egress interfaces.
Why it's wrong here
The 'set dscp' command in a policy map marks packets on ingress as well as egress; classification and marking are typically applied inbound at the trust boundary. It is tempting because egress marking is common, but ingress marking is equally supported.
- ✗
MPLS EXP bits are a 3-bit field used for QoS in MPLS networks and are always directly mapped from the IP DSCP value without any configuration.
Why it's wrong here
MPLS EXP bits are not automatically mapped from IP DSCP; mapping requires explicit configuration, and EXP is a separate 3-bit field. It is tempting because EXP does carry QoS marking in MPLS, but the claim of automatic direct mapping without configuration is false.
Go deeper
Related to this question
Learn chapter
SDN Controllers and Cisco ACI
Key term
VLAN Trunking
VLAN Trunking is a method to carry traffic for multiple VLANs over a single network link between switches or between a switch and a router.
Key term
QoS Classification and Marking
QoS Classification and Marking is the process of identifying network traffic by type and assigning a priority label to ensure important data gets handled first.
About these practice questions
Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.