mediumMultiple Choice
350-401 Practice Question: Given the following configuration on a Cisco IOS…
Given the following configuration on a Cisco IOS switch:
interface GigabitEthernet0/4 switchport mode trunk switchport trunk allowed vlan except 100-200
What is the effect of this configuration?
⚠ Common exam trap
Cisco often tests the 'except' keyword to trap candidates who confuse it with 'add' or 'remove', leading them to think the trunk only forwards the specified range or that the allowed list becomes empty.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The trunk will forward traffic for all VLANs except VLANs 100 through 200.
The 'switchport trunk allowed vlan except 100-200' command explicitly removes VLANs 100 through 200 from the allowed VLAN list on the trunk. All other VLANs (1-99 and 201-4094) remain permitted. This is the standard behavior of the 'except' keyword in Cisco IOS trunk configuration.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The trunk will forward traffic for all VLANs except VLANs 100 through 200.
Why this is correct
The command `switchport trunk allowed vlan except 100-200` starts from the default allowed list, which includes all VLANs (1-4094), and subtracts VLANs 100 through 200 from that set. As a result, the trunk forwards traffic for every VLAN outside this range, including the native VLAN and any user-configured VLANs beyond the excluded block. This is the standard behavior of the `except` keyword: it creates a deny list rather than an allow list.
- ✗
The trunk will only forward traffic for VLANs 100 through 200.
Why it's wrong here
If the configuration were `switchport trunk allowed vlan 100-200`, the switch would replace the allowed list with exactly that range, and only those VLANs would be forwarded. The word `except` fundamentally alters the meaning: it removes the specified VLANs from the currently allowed set instead of defining the permitted set. Therefore, claiming the trunk forwards only VLANs 100-200 inverts the actual logic and is incorrect.
- ✗
The trunk will forward traffic for all VLANs.
Why it's wrong here
The `except` clause explicitly denies VLANs 100-200 from the trunk's allowed list, so traffic carrying those VLAN IDs will be dropped at the trunk port. Since the allowed list is configured as 'all except this range,' the statement 'forward traffic for all VLANs' is false because the excluded range is not forwarded. Only VLANs outside the specified range—and VLANs 1-99 and 201+—are eligible for forwarding.
- ✗
The trunk will not forward any traffic because the allowed list is empty.
Why it's wrong here
The allowed list is far from empty; it still contains every VLAN number that is not between 100 and 200, which for the standard 1-4094 range is 3993 VLANs. A truly empty allowed list would be configured with `switchport trunk allowed vlan none`, which would block all trunk traffic. The `except` option preserves the bulk of the VLAN set, so the trunk remains operational for the majority of VLANs.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.