mediumMultiple Choice
350-401 Practice Question: Given the following snippet from a Cisco 9800…
Given the following snippet from a Cisco 9800 WLC:
ap ethernet-port default-ethernet-port
description "Default Ethernet Port"
mode trunk allowed vlan 10,20,30 native vlan 10
What is the effect of this configuration on the AP?
⚠ Common exam trap
Cisco often tests the misconception that the native VLAN is always tagged or that the AP's trunk port behaves like a switch trunk, when in fact the native VLAN carries untagged management traffic and the allowed VLANs carry tagged client traffic.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The AP will use VLAN 10 for management traffic and VLANs 20 and 30 for client traffic.
The configuration sets the AP's Ethernet port as a trunk port with VLAN 10 as the native VLAN and allowed VLANs 10, 20, and 30. In Cisco wireless architectures, the AP uses the native VLAN (VLAN 10) for management traffic (e.g., CAPWAP control) and the other allowed VLANs (20 and 30) for client data traffic, which is tunneled via CAPWAP to the WLC. This matches option B.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The AP's Ethernet port will tag all traffic with VLAN 10.
Why it's wrong here
On a trunk port, the native VLAN is transmitted without an 802.1Q tag, while all other allowed VLANs are explicitly tagged. Since the configuration sets VLAN 10 as the native VLAN for AP management traffic, those frames remain untagged. Thus, the claim that all traffic is tagged with VLAN 10 is false; only client VLANs 20 and 30 are tagged.
- ✓
The AP will use VLAN 10 for management traffic and VLANs 20 and 30 for client traffic.
Why this is correct
This is correct because the switchport trunk native vlan 10 command makes VLAN 10 the untagged, management VLAN for the AP, while the switchport trunk allowed vlan 20,30 command permits tagged client traffic on those VLANs. The AP's management IP resides in VLAN 10, and SSIDs are mapped to VLAN 20 and 30 for client data, maintaining separation between management and user traffic.
- ✗
The AP will only allow VLAN 10 traffic.
Why it's wrong here
The configuration explicitly includes VLANs 20 and 30 in the allowed list, so the AP trunk carries far more than just VLAN 10. Only if the allowed vlan command had specified a single VLAN would this statement hold. Since multiple VLANs are permitted, the claim that only VLAN 10 traffic is allowed is incorrect.
- ✗
The AP's Ethernet port is configured as an access port.
Why it's wrong here
A port configured with switchport mode trunk is by definition not an access port; it uses 802.1Q tagging to transport multiple VLANs and negotiates trunking via DTP if not set to nonegotiate. An access port would carry only one untagged VLAN and would not support the multiple client VLANs described. Therefore, this statement misidentifies the port mode.
Visual reference
Go deeper
Related to this question
Learn chapter
QoS and Network Performance Management
Key term
Cisco AP Modes
Cisco AP Modes are different operational states a wireless access point can use, determining how it handles traffic, management, and security in a network.
Key term
VLAN Trunking
VLAN Trunking is a method to carry traffic for multiple VLANs over a single network link between switches or between a switch and a router.
About these practice questions
One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.