Courseiva
Switching and Network AccesshardMultiple ChoiceObjective-mapped

CCNA Switching and Network Access Practice Question

A switch port connected to an edge host immediately transitions to forwarding and then later goes err-disabled after a BPDU is received. Which feature combination most likely produced this behavior?

⚠ Common exam trap

Beware of confusing BPDU Guard with other protection mechanisms like Root Guard or Loop Guard; each serves a different purpose.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

PortFast with BPDU Guard

The most likely combination is PortFast with BPDU Guard. In practical terms, PortFast explains why the port moved quickly into forwarding when the host connected. BPDU Guard explains why the same port later shut down after seeing a BPDU that should not normally appear on an edge port. This is a very common enterprise edge-port design pattern and a classic exam scenario.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • PortFast with BPDU Guard

    Why this is correct

    PortFast immediately moves a switchport from blocking to forwarding, bypassing the STP listening and learning states, which is exactly what an edge host needs to start communicating right away. BPDU Guard then protects that edge port by placing it in errdisable state if any BPDU is received, preventing a rogue switch from forming an unintended loop. Together, these STP edge-port protections both speed up the transition and maintain loop safety for a directly connected host.

  • NetFlow with SNMP traps

    Why it's wrong here

    NetFlow is a flow-based accounting and telemetry mechanism that samples packet statistics, and SNMP traps are asynchronous alerts pushed to a management station; both are monitoring tools that only observe or report network behavior. Neither modifies Spanning Tree Protocol parameters, changes the STP port state, or provides the loop-prevention guard needed on an edge port. Thus, they are visibility technologies and cannot cause an immediate forwarding transition or protect against BPDUs.

    When this WOULD be correct

    If the exam question asked about monitoring and alerting mechanisms for network traffic and events, a scenario involving the use of NetFlow to collect data and SNMP traps to notify administrators of significant events would make this option correct.

  • OSPF passive-interface with EUI-64

    Why it's wrong here

    OSPF passive-interface merely stops OSPF hello/advertisement traffic on a link, while EUI-64 is an IPv6 interface-identifier construction method; neither interacts with Spanning Tree Protocol state machines. An access port's transition out of blocking/listening is governed by STP timers or PortFast, not by routing-protocol or address-autoconfiguration settings. Therefore, this combination cannot cause an edge switchport to transition immediately to forwarding.

    When this WOULD be correct

    If the question were about configuring OSPF on a router where the administrator wants to prevent OSPF advertisements on specific interfaces while using EUI-64 addressing for IPv6, this option would be correct. It would focus on controlling OSPF traffic without affecting Layer 2 switch behavior.

  • WPA3 with CAPWAP

    Why it's wrong here

    WPA3 is an authentication/encryption framework for Wi-Fi clients, and CAPWAP is the control/forwarding protocol used between a wireless LAN controller and access points; both operate at the wireless data plane and are irrelevant to a wired Ethernet switchport. An edge host connected to a switch requires Layer 2 STP edge-port behavior to skip listening/learning, which WPA3 and CAPWAP cannot influence. Additionally, neither feature detects or suppresses BPDUs on a physical switch port.

    When this WOULD be correct

    If the exam question asked about wireless network security configurations and their impact on access point behavior in a CAPWAP environment, then WPA3 could be the correct answer, particularly in scenarios involving secure connections and management of wireless clients.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The 200-301 exam frequently reuses these exact scenarios with slightly different constraints.

PortFast with BPDU GuardCorrect answer

Why this is correct

PortFast immediately moves a switchport from blocking to forwarding, bypassing the STP listening and learning states, which is exactly what an edge host needs to start communicating right away. BPDU Guard then protects that edge port by placing it in errdisable state if any BPDU is received, preventing a rogue switch from forming an unintended loop. Together, these STP edge-port protections both speed up the transition and maintain loop safety for a directly connected host.

NetFlow with SNMP trapsWrong answer — click to see why

Why this is wrong here

NetFlow is used for traffic monitoring and analysis, while SNMP traps are used for network management notifications. Neither feature affects STP behavior or port state transitions; they do not cause a port to go err-disabled upon receiving a BPDU.

★ When this WOULD be the correct answer

If the exam question asked about monitoring and alerting mechanisms for network traffic and events, a scenario involving the use of NetFlow to collect data and SNMP traps to notify administrators of significant events would make this option correct.

Why candidates choose this

Students might confuse the concept of 'traps' or 'alerts' with the err-disabled state, thinking that SNMP traps could trigger a port shutdown. However, err-disabled is a hardware-level protection mechanism, not a management action.

OSPF passive-interface with EUI-64Wrong answer — click to see why

Why this is wrong here

OSPF passive-interface prevents OSPF from sending routing updates on an interface but does not affect STP or port security. EUI-64 is used for IPv6 address generation. Neither feature relates to BPDU handling or err-disable behavior.

★ When this WOULD be the correct answer

If the question were about configuring OSPF on a router where the administrator wants to prevent OSPF advertisements on specific interfaces while using EUI-64 addressing for IPv6, this option would be correct. It would focus on controlling OSPF traffic without affecting Layer 2 switch behavior.

Why candidates choose this

The term 'passive' might be misassociated with a port being disabled or inactive. Additionally, EUI-64 might be confused with a security feature, but it is unrelated to STP.

WPA3 with CAPWAPWrong answer — click to see why

Why this is wrong here

WPA3 is a wireless security protocol, and CAPWAP is a control and provisioning protocol for wireless access points. These are entirely unrelated to wired switch port STP behavior and cannot cause a port to go err-disabled due to BPDU reception.

★ When this WOULD be the correct answer

If the exam question asked about wireless network security configurations and their impact on access point behavior in a CAPWAP environment, then WPA3 could be the correct answer, particularly in scenarios involving secure connections and management of wireless clients.

Why candidates choose this

The acronyms might be confusing; a student might think 'BPDU' is related to wireless or that 'Guard' is similar to security protocols. However, BPDU Guard is a wired STP feature.

Analysis generated from the official 200-301blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

Visual reference

SW1 Root Bridge SW2 SW3 BLK DP DP RP RP STP blocks one link to prevent loops DP = Designated Port RP = Root Port BLK = Blocked

About these practice questions

This 200-301 question is part of Courseiva's 1,389-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-301 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-301 exam.