easyMultiple Choice
350-401 Practice Question: Is configuring a new Cisco Catalyst switch to…
A network engineer is configuring a new Cisco Catalyst switch to connect to an existing network. The uplink to the distribution switch is configured as a trunk. The engineer wants to ensure that the trunk uses 802.1Q encapsulation and that the native VLAN is set to VLAN 100. The distribution switch is a Cisco Catalyst 3850. Which configuration should the engineer apply on the uplink interface?
⚠ Common exam trap
Cisco often tests the fact that on modern switches (like the 3850), the 'switchport trunk encapsulation dot1q' command is not available because 802.1Q is the only supported encapsulation, leading candidates to incorrectly include it.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
switchport mode trunk; switchport trunk native vlan 100
On modern Cisco Catalyst switches that run LAN Base or IP Base software, the default trunk encapsulation is 802.1Q, so the 'switchport trunk encapsulation dot1q' command is not required. The 'switchport mode trunk' forces the interface into trunking mode, and 'switchport trunk native vlan 100' sets the native VLAN to 100, which matches the requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
switchport mode trunk; switchport trunk native vlan 100
Why this is correct
This is the correct configuration. The command 'switchport mode trunk' forces the interface into permanent 802.1Q trunking mode, independent of DTP negotiation. Adding 'switchport trunk native vlan 100' correctly changes the native VLAN assignment from the default VLAN 1 to VLAN 100, so untagged traffic on this trunk is interpreted as belonging to VLAN 100. This combination reliably establishes a trunk with the desired native VLAN.
- ✗
switchport trunk encapsulation dot1q; switchport mode trunk; switchport trunk native vlan 100
Why it's wrong here
This configuration is incorrect because 'switchport trunk encapsulation dot1q' is unnecessary and often unsupported on modern Cisco switches. On Catalyst switches that only support 802.1Q, the encapsulation is hard-coded and the command is rejected; on switches that support both ISL and 802.1Q, the command may be required, but it is not a universal or safe addition. Moreover, the problem context expects a minimal configuration, and including this command can cause the interface configuration to fail if the platform does not recognize it.
- ✗
switchport mode dynamic desirable; switchport trunk native vlan 100
Why it's wrong here
This configuration is incorrect because 'switchport mode dynamic desirable' does not guarantee that the interface becomes a trunk. Instead, it relies on DTP (Dynamic Trunking Protocol) to negotiate trunking with the remote peer; if the remote interface is set to 'dynamic auto' or 'access', the negotiation can fail or result in an access port. Furthermore, while 'switchport trunk native vlan 100' is valid, it only takes effect if the interface actually ends up as a trunk, which makes this configuration inherently unreliable for ensuring trunking.
- ✗
switchport mode trunk; switchport trunk allowed vlan 100
Why it's wrong here
This configuration is incorrect because 'switchport trunk allowed vlan 100' does not set the native VLAN; it restricts the trunk to carrying only VLAN 100 as an allowed VLAN. With this command, VLAN 100 traffic would still be tagged on the trunk (unless the native VLAN were separately changed), and the native VLAN would remain at its default of VLAN 1. The result is that untagged traffic is mapped to VLAN 1, and VLAN 100 is the sole allowed tagged VLAN, which does not fulfill the requirement to change the native VLAN to 100.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.