Courseiva
Networking →mediumMultiple Choice

Trunk Port Requirement for Inter-VLAN Routing

A technician is configuring a small office network with a managed switch. The network has two VLANs: VLAN 10 for workstations (192.168.10.0/24) and VLAN 20 for servers (192.168.20.0/24). The switch ports for workstations are set to access mode and assigned to VLAN 10. The server ports are also set to access mode and assigned to VLAN 20. The router is connected to one of the switch ports and is configured with subinterfaces (192.168.10.1 on VLAN 10 and 192.168.20.1 on VLAN 20) to route between VLANs. A workstation on VLAN 10 cannot ping a server on VLAN 20. The workstation can ping other workstations on VLAN 10. The technician has verified the router subinterfaces are configured correctly. Which of the following is the MOST likely cause of the problem?

Quick Answer

This scenario is a close variation of the router-on-a-stick trunk problem, testing whether you can apply the same reasoning to a slightly different symptom description. The workstation can reach other devices within its own VLAN 10, which confirms Layer 2 switching within that VLAN works correctly and that the workstation's own configuration is fine, and the router's subinterfaces for both VLANs are already confirmed correct, which rules out routing configuration as the cause. What's left is the path between the switch and the router itself: for the router to route between VLAN 10 and VLAN 20 using subinterfaces, the switch port connecting to the router must be configured as a trunk so it can carry tagged traffic for both VLANs simultaneously. If that port is left in its default access mode instead, it can only carry a single VLAN's untagged traffic to the router, meaning the router only ever receives frames from one VLAN and effectively cannot perform inter-VLAN routing at all, exactly matching the described failure between workstations and servers on different VLANs. Whenever inter-VLAN routing fails despite correctly configured subinterfaces and confirmed intra-VLAN connectivity, the switch port connecting to the router is the next place to check, since it must be a trunk, not an access port, to carry multiple VLANs to the router.

⚠ Common exam trap

Many candidates assume the router subinterface configuration is the only requirement for inter-VLAN routing, overlooking the need for the switch port to be configured as a trunk to carry multiple VLANs to the router.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

B

The workstation can ping other workstations on VLAN 10, confirming Layer 2 connectivity within the VLAN. The router subinterfaces are correctly configured, so the issue is likely that the switch port connecting to the router is not configured as a trunk port. Without a trunk, the switch cannot carry both VLAN 10 and VLAN 20 traffic to the router, preventing inter-VLAN routing.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    A

    Why it's wrong here

    Access mode is the correct configuration for workstation and server ports that belong to a single VLAN. This is not the problem.

  • ✓

    B

    Why this is correct

    The switch port connecting to the router must be configured as a trunk to carry both VLAN 10 and VLAN 20 traffic. If it is left in default access mode (usually VLAN 1), only that single VLAN traffic will reach the router, breaking inter-VLAN routing.

  • ✗

    C

    Why it's wrong here

    If the server's default gateway were set incorrectly, the server would not be able to respond to the workstation's ping, but the workstation would still send the initial request. However, since the workstation cannot even reach the router for routing, this is not the primary cause.

  • ✗

    D

    Why it's wrong here

    The workstation's subnet mask (255.255.255.0) is correct for its /24 subnet. An incorrect subnet mask would cause issues communicating even within VLAN 10, which is not the case.

Visual reference

Switch VLAN 10 Sales (192.168.10.0/24) PC-A PC-B VLAN 20 HR (192.168.20.0/24) PC-C PC-D Router VLANs isolate traffic — inter-VLAN routing requires a Layer 3 device

About these practice questions

One of 896 original 220-1101 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

2 more ways this is tested on 220-1101

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A network technician is configuring a small office network with one router and one managed switch. The network has two VLANs: VLAN 10 (Sales) and VLAN 20 (Engineering). Both VLANs need internet access, and inter-VLAN routing is not required. The technician configures the router's single physical interface with IP 192.168.1.1/24 and creates subinterfaces for VLAN 10 (192.168.10.1/24) and VLAN 20 (192.168.20.1/24). The switch port connecting to the router is configured as an access port in VLAN 10. Which of the following is the MOST likely result?

medium
  • A.Only VLAN 10 can access the internet; VLAN 20 cannot.
  • B.Both VLANs can access the internet.
  • C.Only VLAN 20 can access the internet; VLAN 10 cannot.
  • ✓ D.Neither VLAN can access the internet.

Why D: The router's subinterfaces are configured for VLAN 10 and VLAN 20, but the switch port connecting to the router is an access port in VLAN 10. Access ports carry only untagged traffic and drop tagged frames. Therefore, frames sent by the router's subinterfaces (which are tagged with VLAN 10 or 20) will be dropped by the switch. Conversely, frames sent by hosts in either VLAN arrive at the router untagged, so they are associated with the physical interface (192.168.1.1/24), not the subinterfaces (192.168.10.1 or 192.168.20.1). Consequently, neither VLAN can communicate with the router's subinterface IPs, and neither VLAN can access the internet.

Variation 2. A network technician is configuring a small office network with one router and one managed switch. The switch has two VLANs: VLAN 10 for Sales and VLAN 20 for Engineering. Both VLANs need internet access. The technician configures the router's single physical interface (G0/0) with subinterfaces G0/0.10 for VLAN 10 (192.168.10.1/24) and G0/0.20 for VLAN 20 (192.168.20.1/24). The switch port connected to the router is configured as an access port in VLAN 10. Which of the following is the MOST likely result of this configuration?

medium
  • ✓ A.Only devices in VLAN 10 can access the internet.
  • B.Both VLAN 10 and VLAN 20 can access the internet.
  • C.Only devices in VLAN 20 can access the internet.
  • D.Neither VLAN can access the internet.

Why A: The switch port connected to the router is configured as an access port in VLAN 10. This means it only carries traffic for VLAN 10, stripping any VLAN tags. The router's subinterface G0/0.20 for VLAN 20 never receives or sends traffic because the access port does not allow VLAN 20 frames. Therefore, only devices in VLAN 10 can reach the router's default gateway (192.168.10.1) and access the internet.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1101 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1101 exam.