Courseiva
Network Services and SecuritymediumMultiple ChoiceObjective-mapped

CCNA Network Services and Security Practice Question

An administrator wants an access-layer interface to shut down immediately if another switch is connected accidentally. Which feature best meets that requirement?

⚠ Common exam trap

A frequent exam trap is selecting Root Guard or Loop Guard instead of BPDU Guard. Root Guard only blocks a port from becoming a root port but does not disable the port immediately upon receiving BPDUs. Loop Guard protects against unidirectional link failures by preventing a port from transitioning to forwarding when BPDUs are lost but does not shut down the port. Candidates may also confuse PortFast as it is related to edge ports but it only speeds up STP convergence and does not disable ports. Understanding that BPDU Guard uniquely disables the port immediately upon receiving BPDUs on an edge port is essential to avoid this trap.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

BPDU Guard

BPDU Guard is designed for edge ports. If the port receives a BPDU, the switch treats that as a sign that another switch has been connected and places the interface into an err-disabled state to protect the spanning-tree topology.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Root Guard

    Why it's wrong here

    Root Guard is a spanning-tree protection mechanism that enforces the location of the root bridge by keeping a designated port from becoming a root port. If the port receives a superior BPDU, it is moved to a root-inconsistent state (blocked), not shut down. It does not proactively shut down an access layer interface; it merely prevents an unauthorized switch from becoming the root.

    When this WOULD be correct

    If the question asked for a feature that prevents a switch from becoming the root bridge in a spanning tree topology, Root Guard would be the correct answer. It would be applicable in a situation where maintaining a specific switch as the root bridge is critical.

  • PortFast

    Why it's wrong here

    PortFast is a spanning-tree feature that immediately transitions a switch port to the forwarding state, bypassing the listening and learning states. It is designed for access ports connecting to end hosts, but it does not react to BPDUs or shut down the interface under any condition. Therefore, PortFast alone cannot cause an access layer interface to shut down; it actually speeds up convergence.

    When this WOULD be correct

    In a scenario where the question asks for a feature that allows a switch port to transition quickly to forwarding mode without waiting for Spanning Tree Protocol (STP) timers, PortFast would be the correct answer. This would apply in a situation where the administrator wants to optimize the connection time for end devices like PCs or printers.

  • BPDU Guard

    Why this is correct

    BPDU Guard is the correct feature because it is specifically configured on access ports to protect the spanning-tree topology from unauthorized devices. When a port with BPDU Guard enabled receives any BPDU, it immediately puts the interface into an err-disabled state, effectively shutting it down. This behavior matches the administrator's goal of having the access layer interface shut down upon unexpected BPDU reception.

  • Loop Guard

    Why it's wrong here

    Loop Guard is a spanning-tree enhancement that prevents alternate or root ports from transitioning to forwarding when they stop receiving BPDUs. It places the port into a loop-inconsistent state (blocked) if BPDUs are missing, but it does not disable the interface administratively. Loop Guard is not used on access ports and does not cause a shutdown; it only blocks the port to prevent Layer 2 loops.

    When this WOULD be correct

    In a scenario where a question asks for a feature that maintains network stability by preventing loops while still allowing ports to function normally, Loop Guard would be the correct answer. For instance, if the question focused on preventing broadcast storms due to misconfigured switches, Loop Guard would apply.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The 200-301 exam frequently reuses these exact scenarios with slightly different constraints.

BPDU GuardCorrect answer

Why this is correct

BPDU Guard is the correct feature because it is specifically configured on access ports to protect the spanning-tree topology from unauthorized devices. When a port with BPDU Guard enabled receives any BPDU, it immediately puts the interface into an err-disabled state, effectively shutting it down. This behavior matches the administrator's goal of having the access layer interface shut down upon unexpected BPDU reception.

Root GuardWrong answer — click to see why

Why this is wrong here

Root Guard is used to prevent a switch from becoming the root bridge in the spanning tree, not to shut down an interface when another switch is connected. It enforces the root bridge position on a port, but does not disable the port upon switch connection.

★ When this WOULD be the correct answer

If the question asked for a feature that prevents a switch from becoming the root bridge in a spanning tree topology, Root Guard would be the correct answer. It would be applicable in a situation where maintaining a specific switch as the root bridge is critical.

Why candidates choose this

Students may confuse Root Guard with BPDU Guard because both are STP security features. The name 'Guard' might imply protection against unauthorized switches, but Root Guard's purpose is different.

PortFastWrong answer — click to see why

Why this is wrong here

PortFast is used to immediately transition an access port to the forwarding state, bypassing the listening and learning states. It does not shut down the interface when another switch is connected; in fact, it can cause loops if BPDU Guard is not also enabled.

★ When this WOULD be the correct answer

In a scenario where the question asks for a feature that allows a switch port to transition quickly to forwarding mode without waiting for Spanning Tree Protocol (STP) timers, PortFast would be the correct answer. This would apply in a situation where the administrator wants to optimize the connection time for end devices like PCs or printers.

Why candidates choose this

PortFast is often associated with access ports, and students might think it provides protection against switch connections. However, PortFast alone does not prevent loops or shut down the port.

Loop GuardWrong answer — click to see why

Why this is wrong here

Loop Guard is used to prevent alternate or root ports from becoming designated ports in the absence of BPDUs, which can cause loops. It does not shut down an interface when a switch is connected; rather, it places the port into a loop-inconsistent state if BPDUs stop being received.

★ When this WOULD be the correct answer

In a scenario where a question asks for a feature that maintains network stability by preventing loops while still allowing ports to function normally, Loop Guard would be the correct answer. For instance, if the question focused on preventing broadcast storms due to misconfigured switches, Loop Guard would apply.

Why candidates choose this

The name 'Loop Guard' suggests it prevents loops, and students might think it would shut down a port to prevent loops caused by connecting a switch. However, its mechanism is different and does not involve immediate shutdown upon switch connection.

Analysis generated from the official 200-301blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

Visual reference

SW1 Root Bridge SW2 SW3 BLK DP DP RP RP STP blocks one link to prevent loops DP = Designated Port RP = Root Port BLK = Blocked

About these practice questions

Courseiva writes every 200-301 question from scratch — 1,389 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-301 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-301 exam.