N10-009 exam dumps

N10-009 practice question 155 of 329

Network+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

N10-009 Question 155

Single answerVirtual Local Area Network (VLAN), VLAN database, Switch virtual interface (SVI)

A network administrator is deploying a new VLAN for the accounting department on a Layer 3 switch. Users in accounting are connected to access ports that have already been assigned to VLAN 30, but the users cannot reach their default gateway. The administrator confirms that the VLAN exists in the switch's VLAN database and that the physical ports are up. Which action should the administrator take NEXT to allow hosts in VLAN 30 to use the switch as their gateway?

  1. A

    Create and configure an SVI for VLAN 30 with an IP address to serve as the default gateway

  2. B

    Enable port security on all access ports assigned to VLAN 30

  3. C

    Convert the access ports for accounting users to trunk ports and allow VLAN 30

  4. D

    Add VLAN 30 to the native VLAN setting on the uplink port

Show answer and explanation

Correct answer: A

Explanation

This scenario tests the relationship between the VLAN database, VLAN membership on switch ports, and the SVI. A VLAN being present in the VLAN database only means the switch recognizes that VLAN and can assign ports to it. That alone does not provide Layer 3 gateway functionality. On a multilayer switch, the correct practice is to create an SVI for the VLAN, assign it an IP address in the subnet used by that VLAN, and configure clients to use that IP as their default gateway. This is standard behavior on enterprise switches from major vendors. Best practices also include verifying the VLAN is active, confirming at least one port in the VLAN is up, and ensuring routing is enabled if communication beyond the local VLAN is required. The key concept is that VLAN creation and port assignment are Layer 2 tasks, while the SVI provides the Layer 3 interface needed for gateway services.

  • A. Correct.

    Correct. On a Layer 3 switch, hosts in a VLAN use the switch virtual interface (SVI) for that VLAN as their default gateway. Even if VLAN 30 exists in the VLAN database and access ports are assigned correctly, users will not be able to reach a gateway on the switch until an interface VLAN 30 is created and given an IP address. In many environments, the SVI must also be administratively up and have at least one active port in the VLAN before it becomes operational.

  • B. Incorrect.

    Incorrect. Port security controls which MAC addresses can use a port, helping with access control and limiting unauthorized devices. It does not create a Layer 3 gateway or provide inter-VLAN or local VLAN gateway functionality. Someone might pick this if they confuse connectivity problems with security restrictions.

  • C. Incorrect.

    Incorrect. End-user devices such as PCs should normally connect to access ports, not trunk ports. Trunks are used to carry traffic for multiple VLANs between switches, routers, or other infrastructure devices. Changing user ports to trunks would not solve the missing default gateway issue and would create an improper configuration.

  • D. Incorrect.

    Incorrect. The native VLAN applies to untagged traffic on an 802.1Q trunk. It is unrelated to creating a gateway for hosts in VLAN 30. Adding VLAN 30 as the native VLAN on an uplink does not provide an IP interface for hosts and may introduce tagging mismatches if done improperly.

Timed practice exam

Take a N10-009 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam