CCNA Switching and Network Access Practice Question
A switch port connected to an edge host immediately transitions to forwarding and then later goes err-disabled after a BPDU is received. Which feature combination most likely produced this behavior?
⚠ Common exam trap
Beware of confusing BPDU Guard with other protection mechanisms like Root Guard or Loop Guard; each serves a different purpose.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
PortFast with BPDU Guard
The most likely combination is PortFast with BPDU Guard. In practical terms, PortFast explains why the port moved quickly into forwarding when the host connected. BPDU Guard explains why the same port later shut down after seeing a BPDU that should not normally appear on an edge port. This is a very common enterprise edge-port design pattern and a classic exam scenario.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
PortFast with BPDU Guard
Why this is correct
PortFast immediately moves a switchport from blocking to forwarding, bypassing the STP listening and learning states, which is exactly what an edge host needs to start communicating right away. BPDU Guard then protects that edge port by placing it in errdisable state if any BPDU is received, preventing a rogue switch from forming an unintended loop. Together, these STP edge-port protections both speed up the transition and maintain loop safety for a directly connected host.
- ✗
NetFlow with SNMP traps
Why it's wrong here
NetFlow is a flow-based accounting and telemetry mechanism that samples packet statistics, and SNMP traps are asynchronous alerts pushed to a management station; both are monitoring tools that only observe or report network behavior. Neither modifies Spanning Tree Protocol parameters, changes the STP port state, or provides the loop-prevention guard needed on an edge port. Thus, they are visibility technologies and cannot cause an immediate forwarding transition or protect against BPDUs.
When this WOULD be correct
If the exam question asked about monitoring and alerting mechanisms for network traffic and events, a scenario involving the use of NetFlow to collect data and SNMP traps to notify administrators of significant events would make this option correct.
- ✗
OSPF passive-interface with EUI-64
Why it's wrong here
OSPF passive-interface merely stops OSPF hello/advertisement traffic on a link, while EUI-64 is an IPv6 interface-identifier construction method; neither interacts with Spanning Tree Protocol state machines. An access port's transition out of blocking/listening is governed by STP timers or PortFast, not by routing-protocol or address-autoconfiguration settings. Therefore, this combination cannot cause an edge switchport to transition immediately to forwarding.
When this WOULD be correct
If the question were about configuring OSPF on a router where the administrator wants to prevent OSPF advertisements on specific interfaces while using EUI-64 addressing for IPv6, this option would be correct. It would focus on controlling OSPF traffic without affecting Layer 2 switch behavior.
- ✗
WPA3 with CAPWAP
Why it's wrong here
WPA3 is an authentication/encryption framework for Wi-Fi clients, and CAPWAP is the control/forwarding protocol used between a wireless LAN controller and access points; both operate at the wireless data plane and are irrelevant to a wired Ethernet switchport. An edge host connected to a switch requires Layer 2 STP edge-port behavior to skip listening/learning, which WPA3 and CAPWAP cannot influence. Additionally, neither feature detects or suppresses BPDUs on a physical switch port.
When this WOULD be correct
If the exam question asked about wireless network security configurations and their impact on access point behavior in a CAPWAP environment, then WPA3 could be the correct answer, particularly in scenarios involving secure connections and management of wireless clients.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The 200-301 exam frequently reuses these exact scenarios with slightly different constraints.
✓PortFast with BPDU GuardCorrect answer▾
Why this is correct
PortFast immediately moves a switchport from blocking to forwarding, bypassing the STP listening and learning states, which is exactly what an edge host needs to start communicating right away. BPDU Guard then protects that edge port by placing it in errdisable state if any BPDU is received, preventing a rogue switch from forming an unintended loop. Together, these STP edge-port protections both speed up the transition and maintain loop safety for a directly connected host.
✗NetFlow with SNMP trapsWrong answer — click to see why▾
Why this is wrong here
NetFlow is used for traffic monitoring and analysis, while SNMP traps are used for network management notifications. Neither feature affects STP behavior or port state transitions; they do not cause a port to go err-disabled upon receiving a BPDU.
★ When this WOULD be the correct answer
If the exam question asked about monitoring and alerting mechanisms for network traffic and events, a scenario involving the use of NetFlow to collect data and SNMP traps to notify administrators of significant events would make this option correct.
Why candidates choose this
Students might confuse the concept of 'traps' or 'alerts' with the err-disabled state, thinking that SNMP traps could trigger a port shutdown. However, err-disabled is a hardware-level protection mechanism, not a management action.
✗OSPF passive-interface with EUI-64Wrong answer — click to see why▾
Why this is wrong here
OSPF passive-interface prevents OSPF from sending routing updates on an interface but does not affect STP or port security. EUI-64 is used for IPv6 address generation. Neither feature relates to BPDU handling or err-disable behavior.
★ When this WOULD be the correct answer
If the question were about configuring OSPF on a router where the administrator wants to prevent OSPF advertisements on specific interfaces while using EUI-64 addressing for IPv6, this option would be correct. It would focus on controlling OSPF traffic without affecting Layer 2 switch behavior.
Why candidates choose this
The term 'passive' might be misassociated with a port being disabled or inactive. Additionally, EUI-64 might be confused with a security feature, but it is unrelated to STP.
✗WPA3 with CAPWAPWrong answer — click to see why▾
Why this is wrong here
WPA3 is a wireless security protocol, and CAPWAP is a control and provisioning protocol for wireless access points. These are entirely unrelated to wired switch port STP behavior and cannot cause a port to go err-disabled due to BPDU reception.
★ When this WOULD be the correct answer
If the exam question asked about wireless network security configurations and their impact on access point behavior in a CAPWAP environment, then WPA3 could be the correct answer, particularly in scenarios involving secure connections and management of wireless clients.
Why candidates choose this
The acronyms might be confusing; a student might think 'BPDU' is related to wireless or that 'Guard' is similar to security protocols. However, BPDU Guard is a wired STP feature.
Analysis generated from the official 200-301blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Visual reference
Go deeper
Related to this question
Learn chapter
Configuring Switch Ports for Desktops, VoIP Phones, APs, IoT, and Virtualized Hosts
Key term
Switch
A switch is a networking device that connects devices on a local area network and uses MAC addresses to forward data only to the intended recipient.
Key term
Bridge Protocol Data Unit
A Bridge Protocol Data Unit (BPDU) is a special message that network switches exchange to detect and prevent loops in an Ethernet network.
About these practice questions
This 200-301 question is part of Courseiva's 1,389-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-301 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-301 exam.