mediumMultiple Choice
350-401 Practice Question: An engineer is configuring a new access switch…
An engineer is configuring a new access switch for a branch office. The switch must support multiple VLANs for different departments: VLAN 10 (Engineering), VLAN 20 (Sales), and VLAN 30 (Management). The uplink to the distribution switch is a trunk. The engineer wants to ensure that only the required VLANs are allowed on the trunk and that the native VLAN is changed from the default to VLAN 99 for security reasons. Which configuration commands should the engineer apply on the access switch's uplink interface?
⚠ Common exam trap
Cisco often tests the distinction between 'allowed vlan' and 'allowed vlan except' — candidates may confuse the syntax and select the option that excludes the required VLANs instead of permitting them.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
switchport mode trunk; switchport trunk native vlan 99; switchport trunk allowed vlan 10,20,30
It explicitly sets the interface to trunk mode, changes the native VLAN from the default VLAN 1 to VLAN 99 for security, and uses the 'allowed vlan' command to permit only VLANs 10, 20, and 30 on the trunk. This ensures that only the required department VLANs are carried, reducing unnecessary broadcast traffic and preventing VLAN hopping attacks by changing the native VLAN.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
switchport mode trunk; switchport trunk native vlan 99; switchport trunk allowed vlan 10,20,30
Why this is correct
This configuration statically enables trunking with `switchport mode trunk`, sets the native VLAN to 99 so that untagged frames are mapped to that VLAN, and uses the allowed VLAN list to permit only VLANs 10, 20, and 30 across the trunk. The combination restricts the trunk to the explicitly required VLANs while still allowing the native VLAN to be untagged, which matches the requirement exactly. Without the allowed list, the trunk would carry all active VLANs, so this command is the critical part that scopes the trunk.
- ✗
switchport mode trunk; switchport trunk native vlan 99; switchport trunk allowed vlan except 10,20,30
Why it's wrong here
The `except` keyword in `switchport trunk allowed vlan` inverts the list: it means 'allow every VLAN except VLANs 10, 20, and 30.' As a result, this trunk would carry all other active VLANs and block exactly the three VLANs that are supposed to be transported, the opposite of the requirement. This syntax is useful when you want to disallow only a few VLANs from a large default-allowed set, but it cannot be used to specify a positive allow list of VLANs.
- ✗
switchport mode dynamic desirable; switchport trunk native vlan 99; switchport trunk allowed vlan 10,20,30
Why it's wrong here
The `switchport mode dynamic desirable` command enables DTP negotiation, which may cause the trunk to fail if the distribution switch does not respond with trunking, leaving the interface in an access mode and blocking all VLAN traffic. The stem requires a static trunk configuration to guarantee the uplink operates as a trunk, which `dynamic desirable` does not ensure. This option is tempting because it correctly sets the native VLAN and allowed VLAN list, and in a scenario where both switches use DTP and the distribution switch is set to `dynamic desirable` or `trunk`, it would successfully negotiate a trunk.
- ✗
switchport trunk encapsulation dot1q; switchport mode trunk; switchport trunk native vlan 99
Why it's wrong here
This configuration is missing the `switchport trunk allowed vlan 10,20,30` statement; without it, the trunk defaults to allowing all VLANs, so traffic for every active VLAN could traverse the link, not just VLANs 10, 20, and 30. Additionally, `switchport trunk encapsulation dot1q` is not necessary on modern Catalyst switches that only support 802.1Q — the command may not even be recognized on some platforms. The main failure is the lack of an allowed VLAN restriction, which leaves the trunk open to unwanted VLANs.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.