Cisco CCNA (200-301) — All Questions
The figures these questions turn on, pooled by value and printable, with a side to write them from memory: the cram packet, $6.99 →
101 questions
On a Cisco switch trunk link using IEEE 802.1Q, how are frames belonging to the native VLAN handled by default?
- a.They are sent untagged✓
- b.They are tagged with the highest VLAN ID
- c.They are tagged with VLAN ID 1
- d.They are dropped for security
With 802.1Q, frames on the native VLAN traverse the trunk untagged by default, while all other VLANs are tagged with a 4-byte VLAN identifier. The native VLAN must match on both ends of the trunk to avoid a mismatch. For security, administrators often change the native VLAN away from the default VLAN 1.
In a Spanning Tree Protocol topology, which switch becomes the root bridge?
- a.The switch with the most ports
- b.The switch configured last
- c.The switch with the lowest bridge ID✓
- d.The switch with the highest MAC address
STP elects the root bridge as the switch with the lowest bridge ID, which is the combination of bridge priority and MAC address. If priorities are equal (default 32768), the lowest MAC address breaks the tie. Administrators lower the priority on the desired switch to control root placement.
Which EtherChannel negotiation protocol is an IEEE open standard (802.3ad) rather than Cisco-proprietary?
- a.VTP
- b.PAgP
- c.LACP✓
- d.CDP
LACP (Link Aggregation Control Protocol) is the IEEE 802.3ad open standard for dynamically bundling multiple physical links into one logical channel. PAgP is Cisco's proprietary equivalent. Bundling links increases bandwidth and provides redundancy while STP treats the channel as a single logical interface.
In a wireless network, what is the primary role of a Wireless LAN Controller (WLC) in a split-MAC architecture?
- a.It centrally manages configuration and RF for lightweight APs✓
- b.It broadcasts the SSID directly to clients
- c.It acts only as a DHCP server
- d.It replaces all access points
In split-MAC (controller-based) deployments, lightweight access points handle real-time RF functions while the WLC centrally manages configuration, security policies, roaming, and RF resource management via CAPWAP tunnels. This centralizes control of many APs. Autonomous APs, by contrast, operate independently without a controller.
Which interface command assigns a switch access port to VLAN 10?
- a.vlan 10 access
- b.switchport trunk vlan 10
- c.switchport access vlan 10✓
- d.switchport mode vlan 10
The command 'switchport access vlan 10' assigns the port to VLAN 10 for untagged end-device traffic. You typically pair it with 'switchport mode access' to force the port into access mode. Trunk commands carry multiple VLANs and are used between switches, not for a single end device.
A switch receives a frame whose destination MAC address is not in its MAC address table. What does the switch do?
- a.Sends it only to the default gateway
- b.Drops the frame immediately
- c.Floods it out all ports in the VLAN except the port it arrived on✓
- d.Forwards it to every VLAN
When the destination MAC is unknown (unknown unicast), the switch floods the frame out all ports in the same VLAN except the ingress port, hoping the destination replies so its MAC can be learned. Flooding stays within the VLAN because a VLAN is a single broadcast domain. Once a reply is seen, the table is updated.
What is a consequence of a native VLAN mismatch on the two ends of an 802.1Q trunk?
- a.Only VLAN 1 will pass traffic
- b.Nothing; it is purely cosmetic
- c.The trunk negotiates a slower speed
- d.Traffic from the two native VLANs is bridged together, risking security and loop issues✓
If the native VLANs differ, untagged frames sent from one side's native VLAN are received into a different VLAN on the other side, effectively merging two VLANs. This can leak traffic between segments and create spanning-tree inconsistencies. CDP often flags the mismatch, and both trunk ends should use the same native VLAN.
In classic Spanning Tree Protocol, which port state populates the MAC address table but does not yet forward user frames?
- a.Learning✓
- b.Listening
- c.Forwarding
- d.Blocking
In the Learning state, the switch begins recording source MAC addresses to build its table but still does not forward user data, preventing loops during convergence. Listening processes BPDUs without learning MACs, Blocking discards data frames, and only Forwarding passes user traffic. RSTP streamlines these transitions for faster convergence.
What is the primary advantage of Rapid PVST+ (RSTP) over the original 802.1D Spanning Tree Protocol?
- a.It doubles the link bandwidth
- b.It removes the need for a root bridge
- c.Much faster convergence after a topology change✓
- d.It permanently disables all redundant links
RSTP (802.1w), used by Rapid PVST+, converges in seconds rather than the 30-50 seconds classic STP can take, by using proposal/agreement handshakes and defined port roles. It still elects a root bridge and blocks loops but reacts to changes far more quickly. This reduces downtime when links fail or recover.
What does the PortFast feature do when enabled on a switch access port?
- a.Blocks all incoming BPDUs
- b.Bundles the port into an EtherChannel
- c.Elects the port as the root port
- d.Transitions the port straight to forwarding, skipping listening and learning✓
PortFast lets an edge/access port that connects to a single host move immediately to the forwarding state, avoiding the usual STP delay so devices get connectivity (and DHCP) quickly. It should be used only on ports facing end devices, not other switches. Pairing it with BPDU Guard protects against accidental loops.
Want these explained in order? Cisco CCNA 200-301 — Complete Study Guide (2026) — PDF + EPUB, $14.99 · 14-day refund →
With BPDU Guard enabled on a PortFast port, what happens if that port receives a BPDU?
- a.The port automatically becomes a trunk
- b.The BPDU is forwarded to the root bridge
- c.The port is placed in the err-disabled state✓
- d.The BPDU is silently ignored
BPDU Guard assumes a PortFast port should never see BPDUs (since it faces an end device), so receiving one indicates a rogue switch or a loop risk. It immediately err-disables the port to protect the topology. Recovery requires manual intervention or errdisable recovery, alerting the administrator to the unexpected connection.
Which LACP mode combination will successfully form an EtherChannel between two switches?
- a.passive / passive
- b.on / passive
- c.auto / auto
- d.active / passive✓
LACP forms a channel when at least one side actively initiates negotiation, so active/active or active/passive both work. Passive/passive fails because neither side starts negotiation. The 'on' mode is static (no negotiation) and must be 'on' on both ends; mixing 'on' with a dynamic mode fails. 'auto/auto' are PAgP terms, not LACP.
In the 2.4 GHz Wi-Fi band (North America), which set of channels is non-overlapping and recommended to avoid interference?
- a.1, 6, 11✓
- b.1, 6, 12
- c.2, 7, 12
- d.1, 5, 9
The 2.4 GHz band has only three non-overlapping 20 MHz channels in North America: 1, 6, and 11. Using these on adjacent access points minimizes co-channel and adjacent-channel interference. The 5 GHz band offers many more non-overlapping channels, which is one reason it is preferred for dense deployments.
Which protocol tunnels both control and data traffic between a lightweight access point and a Wireless LAN Controller?
- a.CDP
- b.802.1Q
- c.CAPWAP✓
- d.LACP
CAPWAP (Control And Provisioning of Wireless Access Points) builds the tunnels that carry management/control messages and, when configured, client data between a lightweight AP and its WLC. This split-MAC design centralizes configuration and RF management. CDP is a discovery protocol, LACP bundles links, and 802.1Q tags VLANs.
Which statement accurately describes collision and broadcast domains on a Layer 2 switch?
- a.Each port is its own collision domain, and each VLAN is a broadcast domain✓
- b.Each port is a separate broadcast domain
- c.A switch has no MAC address table
- d.All ports share a single collision domain
Every port on a switch is a separate collision domain because full-duplex microsegmentation eliminates contention on each link. Broadcast domains are defined per VLAN, so by default all ports in the same VLAN share one broadcast domain. Routers or SVIs are needed to separate broadcast domains between VLANs.
How does IEEE 802.1Q identify which VLAN a frame belongs to on a trunk link?
- a.It sends the VLAN ID in a separate packet
- b.It appends an 8-byte trailer after the FCS
- c.It inserts a 4-byte tag into the Ethernet frame header✓
- d.It stores the VLAN ID in the IP header
802.1Q inserts a 4-byte tag between the source MAC and EtherType fields of the Ethernet frame; the tag contains a 12-bit VLAN ID (supporting VLANs 1-4094) plus priority bits. Native VLAN frames are left untagged by default. Because the frame is modified, the FCS is recalculated after tagging.
Which VLAN is the default VLAN on a Cisco Catalyst switch, to which all ports initially belong?
- a.VLAN 4094
- b.VLAN 0
- c.VLAN 1005
- d.VLAN 1✓
By default all switch ports are members of VLAN 1, which also carries control traffic like CDP and STP. Because VLAN 1 cannot be deleted, best practice is to move user and management traffic to other VLANs for security.
Which range represents the normal-range VLAN IDs on a Cisco switch?
- a.0-1023
- b.1-1005✓
- c.1-4094
- d.1006-4094, which are reserved for normal everyday use
Normal-range VLANs are 1-1005 and are stored in the vlan.dat file and can be advertised by VTP. Extended-range VLANs 1006-4094 require VTP transparent mode (or later versions) and are stored in the running configuration.
In VLAN configuration mode, which command assigns the name SALES to a VLAN?
- a.switchport vlan name SALES
- b.vlan name SALES
- c.name SALES✓
- d.description SALES
After entering 'vlan 20', the command 'name SALES' labels the VLAN for readability. The 'description' command is used on interfaces, not VLAN definitions, and naming a VLAN is optional but helpful for documentation.
Which interface command statically configures a port as a trunk?
- a.switchport mode trunk✓
- b.switchport trunk enable
- c.switchport access trunk
- d.switchport mode dynamic
'switchport mode trunk' forces the port into permanent trunking mode so it carries multiple tagged VLANs. Pairing it with 'switchport nonegotiate' disables DTP. Access mode, by contrast, carries a single untagged VLAN for an end device.
Which DTP mode actively attempts to form a trunk with a neighboring switch?
- a.access
- b.nonegotiate, which forces a permanent trunk without DTP
- c.dynamic auto
- d.dynamic desirable✓
'dynamic desirable' actively sends DTP frames trying to negotiate a trunk, forming one with a neighbor set to trunk, desirable, or auto. 'dynamic auto' only responds passively, so two auto ports stay in access mode.
Which command disables Dynamic Trunking Protocol negotiation on an interface?
- a.no dtp enable
- b.switchport nonegotiate✓
- c.no switchport
- d.switchport mode access
'switchport nonegotiate' stops the port from sending DTP frames, which is recommended on manually configured trunks and on access ports to prevent trunk negotiation attacks. The mode must be set statically since negotiation is turned off.
Which command restricts a trunk to carry only VLANs 10 and 20?
- a.switchport trunk allowed vlan 10,20✓
- b.switchport block vlan 30
- c.switchport filter vlan 10,20 permit only inbound
- d.switchport access vlan 10
'switchport trunk allowed vlan 10,20' limits the trunk to those VLANs, pruning all others to reduce unnecessary flooding and improve security. Using 'add' or 'remove' keywords lets you modify the list without overwriting it entirely.
Which command changes the native VLAN on an 802.1Q trunk to VLAN 99?
- a.native vlan 99
- b.switchport trunk native vlan 99✓
- c.switchport trunk allowed native 99
- d.switchport native vlan 99
'switchport trunk native vlan 99' sets the untagged native VLAN and must match on both ends of the trunk. Moving the native VLAN off the default VLAN 1 is a common hardening step against VLAN hopping.
Which method routes between VLANs using a single physical router interface divided into subinterfaces?
- a.Layer 2 switching
- b.A dedicated physical router interface for every single VLAN
- c.Router-on-a-stick✓
- d.Proxy ARP
Router-on-a-stick uses one trunk link to a router whose subinterfaces each carry a VLAN with 802.1Q tagging, letting the router route between them. It is simple but the single link can become a bottleneck compared with a Layer 3 switch.
On a router subinterface for router-on-a-stick, which command associates it with VLAN 10 tagging?
- a.switchport trunk encapsulation dot1q
- b.encapsulation dot1q 10✓
- c.encapsulation dot1q 10 native tagged always
- d.encapsulation isl
'encapsulation dot1q 10' tells the subinterface to tag and expect 802.1Q frames for VLAN 10. The IP address configured on that subinterface becomes the default gateway for VLAN 10's hosts. ISL is a legacy Cisco alternative rarely used today.
On a multilayer (Layer 3) switch, which feature performs inter-VLAN routing?
- a.Switched Virtual Interfaces (SVIs) with ip routing enabled✓
- b.Router-on-a-stick with one tagged subinterface configured per VLAN
- c.A crossover cable between two access ports
- d.A trunk to an external router only
A Layer 3 switch routes between VLANs using SVIs (interface vlan X) once 'ip routing' is enabled, keeping traffic on the high-speed switch backplane. This scales better than router-on-a-stick because it avoids a single external trunk bottleneck.
What does the acronym SVI stand for?
- a.System Virtual Instance
- b.Secure VLAN Interface
- c.Switched Virtual Interface✓
- d.Static VLAN Identifier
SVI stands for Switched Virtual Interface, a logical Layer 3 interface (interface vlan X) representing a VLAN on a multilayer switch. Assigning it an IP address provides a gateway and enables inter-VLAN routing when routing is turned on.
Which global command enables IPv4 routing between SVIs on a Layer 3 switch?
- a.ip route enable
- b.router ospf 1
- c.enable routing
- d.ip routing✓
The global command 'ip routing' activates the switch's Layer 3 forwarding so it can route between SVIs. Without it, the SVIs exist but the switch will not forward packets between VLANs even though addresses are configured.
What is the purpose of a voice VLAN on an access port?
- a.It carries IP phone traffic separately from data on the same port✓
- b.It replaces the native VLAN on trunks
- c.It provides guest wireless isolation
- d.It is a trunk-only VLAN for inter-switch management traffic
A voice VLAN lets an IP phone tag its voice traffic into a separate VLAN while a PC daisy-chained through the phone uses the data VLAN, all on one access port. Separating voice enables consistent QoS and simpler policy for real-time traffic.
By default, which VLANs does an 802.1Q trunk carry?
- a.Only VLAN 1
- b.All VLANs (1-4094) unless the allowed list is pruned✓
- c.Only VLANs explicitly listed under switchport access
- d.Only the native VLAN
By default a trunk allows all VLANs (1-4094), tagging every VLAN except the native one. Administrators typically prune the allowed VLAN list to only needed VLANs to limit broadcast flooding and reduce the attack surface.
What is the primary purpose of VTP (VLAN Trunking Protocol)?
- a.To bundle several links into one logical channel for redundancy
- b.To elect the spanning-tree root bridge
- c.To encrypt all traffic crossing a trunk link
- d.To synchronize the VLAN database across switches in a domain✓
VTP propagates VLAN creation, deletion, and naming from a server switch to other switches in the same VTP domain, reducing manual configuration. It carries some risk: a switch with a higher revision number can overwrite the domain's VLAN database.
Which VTP mode receives and synchronizes VLAN information but cannot create or delete VLANs?
- a.Server
- b.Dynamic desirable negotiation mode
- c.Transparent
- d.Client✓
A VTP client cannot add, change, or delete VLANs; it only synchronizes its database from a server and forwards advertisements. Servers can modify VLANs, and transparent switches keep their own local VLANs while merely passing advertisements along.
How does a switch in VTP transparent mode handle VLANs?
- a.It synchronizes and overwrites its VLANs from the VTP server
- b.It keeps its own local VLANs but forwards VTP advertisements✓
- c.It deletes all locally configured VLANs when a new server appears
- d.It automatically becomes the spanning-tree root bridge
A transparent switch maintains its VLAN database independently and does not sync with the domain, but it still forwards VTP advertisements to downstream switches. This is required to configure extended-range VLANs in older VTP versions.
How does an EtherChannel distribute traffic across its member links?
- a.It sends each individual packet round-robin across every link
- b.It uses only the first link and keeps the others idle as backups
- c.It duplicates all traffic on every member link at once
- d.It hashes addresses so each flow consistently uses one link✓
EtherChannel applies a hashing algorithm (based on source/destination MAC or IP, for example) to assign each conversation to one link, keeping a flow's packets in order. It balances per-flow, not per-packet, so a single flow does not exceed one link's speed.
What is the maximum number of active physical links in a single EtherChannel bundle?
- a.16
- b.8✓
- c.2
- d.4
An EtherChannel supports up to 8 active links bundled into one logical interface (some platforms allow additional standby links with LACP). All member ports must share matching speed, duplex, and VLAN settings to bundle successfully.
Which two modes belong to PAgP, the Cisco-proprietary EtherChannel negotiation protocol?
- a.trunk and access
- b.auto and desirable✓
- c.on and on
- d.active and passive
PAgP uses 'auto' and 'desirable' modes; a channel forms when at least one side is desirable. 'active' and 'passive' are LACP terms, and 'on' is a static mode with no negotiation. Mixing PAgP and LACP modes prevents the bundle from forming.
How does EtherChannel interact with Spanning Tree Protocol?
- a.It disables spanning tree entirely across the whole switched network
- b.It causes a second root bridge to be elected for redundancy
- c.STP treats the bundle as one logical link, so no member is blocked✓
- d.It automatically raises the STP bridge priority to become root
STP sees an EtherChannel as a single logical link, so it does not block any of the bundled physical ports, letting all of them forward and add bandwidth. Without bundling, STP would block the redundant links to prevent a loop.
What happens if the member interfaces of an EtherChannel have mismatched settings (such as different VLANs)?
- a.The channel forms and ignores the mismatch
- b.All traffic on the channel is automatically encrypted
- c.The ports are placed in the err-disabled state✓
- d.The switch automatically reboots to recover the bundle
EtherChannel requires consistent speed, duplex, and VLAN/trunk settings on all members; a mismatch triggers a misconfiguration guard that err-disables the ports. You must fix the inconsistency and re-enable the interfaces to restore the channel.
Which interface command adds a port to EtherChannel 1 using LACP active mode?
- a.channel-group 1 mode active✓
- b.channel-protocol lacp only
- c.interface port-channel 1 mode active enable
- d.etherchannel 1 on
'channel-group 1 mode active' places the interface into port-channel 1 and enables LACP active negotiation. The matching logical interface Port-channel1 is created automatically, and the neighbor must use active or passive for the bundle to form.
Showing 40 of 101