Where is the QoS trust boundary established on a LAN?

Network Security and QoS

Where does an administrator establish the trust boundary on a LAN?

  1. access switch Source Reference Answer
  2. distribution switch
  3. voice VLAN
  4. core router

Community Votes

A
100%

100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The question tests the concept of 'classification at the source'; the common trap is confusing the trust boundary with other security or routing boundaries located at the distribution or core layers.

In Cisco network design, the QoS trust boundary is established at the access switch to classify traffic as close to the source as possible. Community consensus confirms that the access layer is the correct location for defining which devices are trusted with DSCP/CoS markings.

Candidates often select Distribution Switch or Core Router because those layers handle aggregation and policy enforcement, but the initial trust decision regarding endpoint markings must happen at the Access Switch where endpoints connect.

Community Discussion (3 comments)

G0y0 👍 1 Selected: A
The notion of trusting or not trusting forms the basis for the trust boundary. Ideally, classification should be done as close to the source as possible. In this case, A. is correct.
b3532e4 👍 3
Based on the search results from your PDF, the correct answer to the question "Where does an administrator establish the trust boundary on a LAN?" is: A. access switch This is because the trust boundary is typically established at the access switch where devices such as Cisco IP phones are connected. The configuration on the switch allows it to trust the QoS markings from these devices
Maleck 👍 1 Selected: A
Answer is A. On a LAN, the trust boundary is configured on the access switch.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The trust boundary is the point in the network where QoS classifications (such as DSCP or CoS values) from endpoints are accepted as valid. According to best practices, classification should occur as close to the source as possible to ensure consistent tagging throughout the network. The access switch is the first network device connected to end-user devices (like PCs and IP phones), making it the logical place to establish this boundary.

Why the Other Options Are Wrong

Distribution switches and core routers typically enforce policies based on markings received from lower layers but do not establish the initial trust boundary for end-hosts. A voice VLAN is a configuration mechanism for separating traffic types, not a physical or logical network boundary where trust is defined. Trusting markings at higher layers would allow untrusted endpoints to manipulate traffic priority before any inspection occurs.

Community Comment Notes

Comment [1] correctly identifies that access switches handle connections for devices like Cisco IP phones, which rely on trusting QoS markings. Comment [2] reinforces the principle that classification should happen near the source, validating option A. Comment [3] provides a concise confirmation that the access switch is the standard configuration point for this boundary.

Official Reference

Exam Strategy

When asked about QoS trust boundaries, always look for the layer closest to the end-user devices (Access Layer). Remember that 'trust' implies accepting incoming markings without re-marking, so the boundary must be set before traffic enters the trusted infrastructure.

Related Analysis

← Back to 350-801 Study Guide