Missing Encapsulation dot1Q on Router Subinterface
A network technician is configuring a router-on-a-stick for inter-VLAN routing. The router has one physical interface (G0/0) connected to a managed switch. The technician creates subinterfaces G0/0.10 for VLAN 10 (192.168.10.1/24) and G0/0.20 for VLAN 20 (192.168.20.1/24). The switch port connected to the router is configured as a trunk allowing VLANs 10 and 20. On a workstation in VLAN 10, the technician can ping the gateway 192.168.10.1 but cannot ping the gateway 192.168.20.1. Which of the following is the MOST likely cause?
Quick Answer
This scenario tests whether you understand that a router subinterface needs two things to route VLAN traffic correctly: an IP address and a way to identify which VLAN tag belongs to it. The workstation can reach its own gateway (192.168.10.1) because that subinterface is fully functional, but it cannot reach the VLAN 20 gateway, which tells you the problem is isolated to the VLAN 20 subinterface rather than the trunk link, the switch configuration, or the workstation itself, since VLAN 10 traffic clearly makes it across the trunk. The encapsulation dot1Q command is what tells the router to expect and process 802.1Q tagged frames for a specific VLAN ID on that subinterface; without it, the router has an IP address configured but no instruction for handling incoming tagged traffic, so it silently drops anything arriving for VLAN 20. This is different from a trunk misconfiguration, which would typically break both VLANs rather than just one. Whenever a router-on-a-stick setup works for one VLAN but not another, and the trunk itself is confirmed to be carrying both VLANs, check the specific subinterface's encapsulation command first, since a working sibling subinterface strongly suggests the problem is isolated to configuration on the one that fails, not the shared trunk.
⚠ Common exam trap
CompTIA often tests the misconception that simply creating a subinterface and assigning an IP address is enough for inter-VLAN routing, when in fact the `encapsulation dot1Q` command is mandatory to bind the subinterface to a specific VLAN.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The subinterface G0/0.20 is missing the encapsulation dot1Q 20 command
The workstation in VLAN 10 can ping its own gateway (192.168.10.1) but not the gateway in VLAN 20 (192.168.20.1). This indicates that the router's subinterface for VLAN 20 is not properly configured to accept and forward traffic from VLAN 20. The most likely cause is that the subinterface G0/0.20 is missing the `encapsulation dot1Q 20` command, which is required to tag frames with VLAN 20 ID when they traverse the trunk link. Without this command, the router will not process traffic for VLAN 20, and the gateway remains unreachable.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The switch trunk port is set to the wrong native VLAN
Why it's wrong here
A mismatch in native VLAN could cause connectivity issues, but both VLANs would likely be affected, not just VLAN 20. Also, the workstation can ping its own gateway, indicating the trunk passes VLAN 10 traffic correctly.
- ✓
The subinterface G0/0.20 is missing the encapsulation dot1Q 20 command
Why this is correct
Without the encapsulation dot1Q command on G0/0.20, the subinterface will not associate incoming frames with VLAN 20. The router may still have the IP address configured, but it will not process tagged frames from VLAN 20, so workstations in VLAN 10 cannot reach the VLAN 20 gateway.
- ✗
The workstation in VLAN 10 has an incorrect subnet mask
Why it's wrong here
An incorrect subnet mask might prevent the workstation from reaching other networks, but it can still ping its own gateway (192.168.10.1). The issue is specifically with reaching the VLAN 20 gateway, which is a routing problem, not a host configuration issue.
- ✗
The router interface G0/0 is in a VLAN that is not allowed on the trunk
Why it's wrong here
The trunk allows both VLANs 10 and 20, and VLAN 10 works. If VLAN 20 were not allowed on the trunk, no traffic from VLAN 20 would reach the router, which could cause the symptom, but the configuration shows the trunk allows both. The absence of encapsulation is a more precise and common cause.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 896 original 220-1101 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on 220-1101
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A technician is configuring a small office network with a managed switch and a router that supports inter-VLAN routing. A workstation on VLAN 10 (192.168.10.0/24) can ping other workstations on VLAN 10 but cannot ping a server on VLAN 20 (192.168.20.0/24). The switch has a trunk port connecting to the router, and the trunk is configured to allow VLANs 10 and 20. The workstation's default gateway is set to 192.168.10.1. The server's default gateway is set to 192.168.20.1. Which of the following is the MOST likely cause of the problem?
medium- ✓ A.A. The router's subinterface for VLAN 20 is not configured or is incorrectly configured.
- B.B. The workstation's firewall is blocking ICMP echo requests.
- C.C. The switch port connecting the router is configured as an access port on VLAN 1.
- D.D. The server's default gateway is set to 192.168.20.254.
Why A: The workstation can communicate within VLAN 10 but cannot reach VLAN 20, indicating that inter-VLAN routing is failing. Since the trunk is correctly allowing VLANs 10 and 20, the most likely cause is that the router's subinterface for VLAN 20 (e.g., GigabitEthernet0/0.20) is missing, has an incorrect encapsulation dot1Q 20 command, or lacks an IP address in the 192.168.20.0/24 subnet. Without a properly configured subinterface, the router cannot route traffic to or from VLAN 20.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1101 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1101 exam.