mediumMultiple Choice
350-401 Practice Question: Given the following configuration on a Cisco…
Given the following configuration on a Cisco IOS-XE switch:
interface GigabitEthernet0/1 switchport mode trunk switchport trunk native vlan 999 switchport trunk allowed vlan 10,20,30
What is the effect of this configuration?
⚠ Common exam trap
Cisco often tests the distinction between the native VLAN being untagged by default and the 'switchport trunk native vlan tag' command that forces tagging, leading candidates to incorrectly assume that all VLANs on a trunk are always tagged.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The interface will forward traffic for VLANs 10, 20, and 30, and all untagged frames will be placed into VLAN 999.
The configuration sets the interface as a trunk port, explicitly allows only VLANs 10, 20, and 30 to traverse it, and designates VLAN 999 as the native VLAN. On a trunk, the native VLAN is used for untagged frames (e.g., DTP, CDP, or any traffic sent without an 802.1Q header), so all untagged frames received or sent on this interface will be associated with VLAN 999.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The interface will forward traffic for VLANs 10, 20, and 30, and all untagged frames will be placed into VLAN 999.
Why this is correct
This is correct because the command 'switchport trunk allowed vlan 10,20,30' explicitly restricts the trunk to carry only those three VLANs. Additionally, 'switchport trunk native vlan 999' changes the default native VLAN from 1 to 999, so any untagged frames received on this trunk are assigned to VLAN 999 and forwarded accordingly. Tagged frames for VLANs 10, 20, and 30 are forwarded normally, while untagged frames are handled as part of VLAN 999, which is the expected behavior for a configured native VLAN.
- ✗
The interface will forward traffic for all VLANs except 10, 20, and 30, and the native VLAN is 1.
Why it's wrong here
This is incorrect because the 'switchport trunk allowed vlan' command is a permit list, not a deny list. It configures the trunk to forward traffic for exactly the VLANs listed (10, 20, and 30) and drop or ignore traffic from any other VLAN. Additionally, the native VLAN was explicitly changed to 999 with 'switchport trunk native vlan 999', so it is not 1. Therefore, the statement gets both the allowed VLAN behavior and the native VLAN value wrong.
- ✗
The interface will operate as an access port in VLAN 999.
Why it's wrong here
This is incorrect because 'switchport mode trunk' explicitly configures the interface as a trunk port, not an access port. An access port carries traffic for a single VLAN and sends all frames untagged, whereas a trunk port carries multiple VLANs and uses 802.1Q tagging for all VLANs except the native VLAN. Setting the native VLAN to 999 does not change the port's operational mode; it remains a trunk that carries the allowed VLANs, with untagged frames mapped to VLAN 999.
- ✗
The interface will forward traffic for VLANs 10, 20, and 30, and all frames will be tagged including the native VLAN.
Why it's wrong here
This is incorrect because frames belonging to the native VLAN are always sent untagged on a traditional 802.1Q trunk. Even though the native VLAN has been changed to 999 using 'switchport trunk native vlan 999', frames in VLAN 999 will still be transmitted without a VLAN tag, while frames for VLANs 10, 20, and 30 will be tagged. Therefore, saying 'all frames will be tagged including the native VLAN' contradicts the fundamental purpose of the native VLAN, which is to handle untagged traffic on a trunk.
Visual reference
Go deeper
Related to this question
About these practice questions
This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.