CCNA Network Services and Security Practice Question
An administrator wants an access-layer interface to shut down immediately if another switch is connected accidentally. Which feature best meets that requirement?
⚠ Common exam trap
A frequent exam trap is selecting Root Guard or Loop Guard instead of BPDU Guard. Root Guard only blocks a port from becoming a root port but does not disable the port immediately upon receiving BPDUs. Loop Guard protects against unidirectional link failures by preventing a port from transitioning to forwarding when BPDUs are lost but does not shut down the port. Candidates may also confuse PortFast as it is related to edge ports but it only speeds up STP convergence and does not disable ports. Understanding that BPDU Guard uniquely disables the port immediately upon receiving BPDUs on an edge port is essential to avoid this trap.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
BPDU Guard
BPDU Guard is designed for edge ports. If the port receives a BPDU, the switch treats that as a sign that another switch has been connected and places the interface into an err-disabled state to protect the spanning-tree topology.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Root Guard
Why it's wrong here
Root Guard is a spanning-tree protection mechanism that enforces the location of the root bridge by keeping a designated port from becoming a root port. If the port receives a superior BPDU, it is moved to a root-inconsistent state (blocked), not shut down. It does not proactively shut down an access layer interface; it merely prevents an unauthorized switch from becoming the root.
When this WOULD be correct
If the question asked for a feature that prevents a switch from becoming the root bridge in a spanning tree topology, Root Guard would be the correct answer. It would be applicable in a situation where maintaining a specific switch as the root bridge is critical.
- ✗
PortFast
Why it's wrong here
PortFast is a spanning-tree feature that immediately transitions a switch port to the forwarding state, bypassing the listening and learning states. It is designed for access ports connecting to end hosts, but it does not react to BPDUs or shut down the interface under any condition. Therefore, PortFast alone cannot cause an access layer interface to shut down; it actually speeds up convergence.
When this WOULD be correct
In a scenario where the question asks for a feature that allows a switch port to transition quickly to forwarding mode without waiting for Spanning Tree Protocol (STP) timers, PortFast would be the correct answer. This would apply in a situation where the administrator wants to optimize the connection time for end devices like PCs or printers.
- ✓
BPDU Guard
Why this is correct
BPDU Guard is the correct feature because it is specifically configured on access ports to protect the spanning-tree topology from unauthorized devices. When a port with BPDU Guard enabled receives any BPDU, it immediately puts the interface into an err-disabled state, effectively shutting it down. This behavior matches the administrator's goal of having the access layer interface shut down upon unexpected BPDU reception.
- ✗
Loop Guard
Why it's wrong here
Loop Guard is a spanning-tree enhancement that prevents alternate or root ports from transitioning to forwarding when they stop receiving BPDUs. It places the port into a loop-inconsistent state (blocked) if BPDUs are missing, but it does not disable the interface administratively. Loop Guard is not used on access ports and does not cause a shutdown; it only blocks the port to prevent Layer 2 loops.
When this WOULD be correct
In a scenario where a question asks for a feature that maintains network stability by preventing loops while still allowing ports to function normally, Loop Guard would be the correct answer. For instance, if the question focused on preventing broadcast storms due to misconfigured switches, Loop Guard would apply.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The 200-301 exam frequently reuses these exact scenarios with slightly different constraints.
✓BPDU GuardCorrect answer▾
Why this is correct
BPDU Guard is the correct feature because it is specifically configured on access ports to protect the spanning-tree topology from unauthorized devices. When a port with BPDU Guard enabled receives any BPDU, it immediately puts the interface into an err-disabled state, effectively shutting it down. This behavior matches the administrator's goal of having the access layer interface shut down upon unexpected BPDU reception.
✗Root GuardWrong answer — click to see why▾
Why this is wrong here
Root Guard is used to prevent a switch from becoming the root bridge in the spanning tree, not to shut down an interface when another switch is connected. It enforces the root bridge position on a port, but does not disable the port upon switch connection.
★ When this WOULD be the correct answer
If the question asked for a feature that prevents a switch from becoming the root bridge in a spanning tree topology, Root Guard would be the correct answer. It would be applicable in a situation where maintaining a specific switch as the root bridge is critical.
Why candidates choose this
Students may confuse Root Guard with BPDU Guard because both are STP security features. The name 'Guard' might imply protection against unauthorized switches, but Root Guard's purpose is different.
✗PortFastWrong answer — click to see why▾
Why this is wrong here
PortFast is used to immediately transition an access port to the forwarding state, bypassing the listening and learning states. It does not shut down the interface when another switch is connected; in fact, it can cause loops if BPDU Guard is not also enabled.
★ When this WOULD be the correct answer
In a scenario where the question asks for a feature that allows a switch port to transition quickly to forwarding mode without waiting for Spanning Tree Protocol (STP) timers, PortFast would be the correct answer. This would apply in a situation where the administrator wants to optimize the connection time for end devices like PCs or printers.
Why candidates choose this
PortFast is often associated with access ports, and students might think it provides protection against switch connections. However, PortFast alone does not prevent loops or shut down the port.
✗Loop GuardWrong answer — click to see why▾
Why this is wrong here
Loop Guard is used to prevent alternate or root ports from becoming designated ports in the absence of BPDUs, which can cause loops. It does not shut down an interface when a switch is connected; rather, it places the port into a loop-inconsistent state if BPDUs stop being received.
★ When this WOULD be the correct answer
In a scenario where a question asks for a feature that maintains network stability by preventing loops while still allowing ports to function normally, Loop Guard would be the correct answer. For instance, if the question focused on preventing broadcast storms due to misconfigured switches, Loop Guard would apply.
Why candidates choose this
The name 'Loop Guard' suggests it prevents loops, and students might think it would shut down a port to prevent loops caused by connecting a switch. However, its mechanism is different and does not involve immediate shutdown upon switch connection.
Analysis generated from the official 200-301blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Visual reference
Go deeper
Related to this question
Learn chapter
RA Guard — IPv6 First-Hop Security
Key term
Interface
An interface is a point of connection or interaction between two systems, devices, or software components that allows them to exchange information or signals.
Key term
Switch
A switch is a networking device that connects devices on a local area network and uses MAC addresses to forward data only to the intended recipient.
About these practice questions
Courseiva writes every 200-301 question from scratch — 1,389 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-301 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-301 exam.