Configuring QoS Trust for Cisco Desk Phones on Catalyst Switches

Which set of QoS commands must be configured on an interface of a catalyst switch so the ingress traffic can be trusted for a desk phone?

  1. Switch(config)# interface gigabitethernet2/0/1
  2. Switch(config)# interface gigabitethernet2/0/1
  3. Switch(config)# interface gigabitethernet2/0/1
  4. Switch(config)# interface gigabitethernet2/0/1 Source Reference Answer

Community Votes

D
100%

100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

This question tests device-aware QoS trust policies, trapping candidates who default to generic CoS or DSCP trust commands instead of the phone-specific variant.

Trusting ingress QoS markings for IP phones requires explicit endpoint verification via CDP or LLDP-MED. Community consensus confirms that mls qos trust device cisco-phone is the mandatory command, ensuring only validated voice devices inherit priority traffic handling.

Candidates often choose mls qos trust cos or dscp, which blindly accept all incoming priority markings and bypass critical security checks for untrusted data hosts.

Community Discussion (4 comments)

JefferX 👍 1 Selected: D
mls qos trust device cisco-phone would be the only command accepted on the interface of a SW
b3532e4 👍 2
mls qos trust device cisco-phone Answer: D
sneff91 👍 1 Selected: D
There's a typo in D (it has "mis" instead of "mls"), but it's otherwise correct.
c6176b5 👍 1 Selected: D
It seems to be D https://community.cisco.com/t5/switching/mls-qos-trust-cos-and-device-cisco-phone/td-p/1311619

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The command mls qos trust device cisco-phone explicitly instructs the Catalyst switch to verify incoming frames via CDP or LLDP-MED before trusting their CoS values. This ensures only authorized Cisco IP phones receive priority treatment while preventing untrusted hosts from spoofing voice traffic markings.

Why the Other Options Are Wrong

Generic trust commands like mls qos trust cos or dscp lack endpoint validation, making them unsuitable for secure VoIP deployments. Option D contains a known typo in the dump mis instead of mls, but it remains the only functionally correct choice when interpreted as intended.

Community Comment Notes

Multiple voters confirmed D based on the exact command syntax, noting the typo issue. One comment linked to the official Cisco switching forum thread validating the configuration approach for enterprise voice environments.

Official Reference

Exam Strategy

Focus on keyword matching for VoIP scenarios; always prioritize device-aware trust commands over blanket CoS/DSCP configurations when IP phones are involved. Practice verifying CDP advertisement states in your simulation labs to prevent configuration mismatches during the exam.

Related Analysis

← Back to 350-801 Study Guide