CCNA Switching and Network Access Practice Question
An engineer wants rapid transition to forwarding on end-user switchports while still protecting the topology from accidental switch connections. Which two STP-related features fit that design?
⚠ Common exam trap
Beware of confusing STP features that secure or optimize ports with those that manage root bridge roles or loop prevention.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
PortFast on user-facing access ports
PortFast improves the user experience on edge ports, and BPDU Guard keeps those ports from becoming unintended switch uplinks.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
PortFast on user-facing access ports
Why this is correct
PortFast is a spanning-tree feature that immediately transitions a switch port from blocking to forwarding when the link comes up, bypassing the 15-second listening and 15-second learning states required by legacy 802.1D. For user-facing access ports, this eliminates the forwarding delay, allowing an end host to obtain a DHCP lease and start communicating almost instantly. It is the primary mechanism for rapid transition to forwarding on edge endpoints.
- ✓
BPDU Guard on those same access ports
Why this is correct
BPDU Guard is a protective feature that immediately error-disables a PortFast edge port if any BPDU is received, preventing an unauthorized switch from creating a loop. It is correct to enable BPDU Guard on the same user-facing access ports as PortFast because it secures the fast-forwarding port without delaying host traffic. Although BPDU Guard does not itself shorten the forwarding transition, it ensures that the PortFast-enabled port remains an endpoint and does not cause instability.
- ✗
Root Guard on every user-facing port instead of PortFast
Why it's wrong here
Root Guard forces a port to remain a designated port and blocks the port from becoming a root port, preserving the intended spanning-tree root location. It does not alter the normal listening and learning timers, so an end-user workstation would still experience the standard 30-second delay before traffic can be forwarded. Using Root Guard instead of PortFast on every user-facing port would therefore fail to achieve rapid transition to forwarding; it is designed for switch-to-switch topology protection, not edge access.
When this WOULD be correct
Root Guard would be correct in a question asking: 'Which STP feature prevents an unauthorized switch from becoming the root bridge on a specific port?'
- ✗
Loop Guard on hosts to accelerate DHCP
Why it's wrong here
Loop Guard is a spanning-tree protocol feature that detects unidirectional link failures by monitoring BPDU reception and placing a non-designated port into loop-inconsistent state when BPDUs stop arriving. It is configured on switch ports that participate in spanning tree, never on end hosts, and it has no relationship to DHCP or host startup timing. Consequently, applying Loop Guard to hosts would be both invalid and useless for accelerating DHCP, because it neither forwards traffic faster nor addresses client configuration.
When this WOULD be correct
In a question asking for a feature that prevents bridging loops caused by unidirectional link failures on point-to-point links, Loop Guard would be the correct answer.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The 200-301 exam frequently reuses these exact scenarios with slightly different constraints.
✓PortFast on user-facing access portsCorrect answer▾
Why this is correct
PortFast is a spanning-tree feature that immediately transitions a switch port from blocking to forwarding when the link comes up, bypassing the 15-second listening and 15-second learning states required by legacy 802.1D. For user-facing access ports, this eliminates the forwarding delay, allowing an end host to obtain a DHCP lease and start communicating almost instantly. It is the primary mechanism for rapid transition to forwarding on edge endpoints.
✗Root Guard on every user-facing port instead of PortFastWrong answer — click to see why▾
Why this is wrong here
Root Guard prevents a port from becoming a root port, but it does not provide rapid transition to forwarding or protect against accidental switch connections. PortFast and BPDU Guard are needed for those goals.
★ When this WOULD be the correct answer
Root Guard would be correct in a question asking: 'Which STP feature prevents an unauthorized switch from becoming the root bridge on a specific port?'
Why candidates choose this
Candidates may confuse Root Guard with BPDU Guard, thinking both protect against unwanted switches, or they may overestimate Root Guard's role in rapid transition.
✗Loop Guard on hosts to accelerate DHCPWrong answer — click to see why▾
Why this is wrong here
Loop Guard is used to prevent alternate or root ports from becoming designated in the absence of BPDUs, not to accelerate DHCP or provide rapid transition to forwarding on end-user switchports.
★ When this WOULD be the correct answer
In a question asking for a feature that prevents bridging loops caused by unidirectional link failures on point-to-point links, Loop Guard would be the correct answer.
Why candidates choose this
Candidates may confuse Loop Guard with features that speed up convergence or associate it with DHCP snooping due to the mention of 'accelerate DHCP' in the option.
Analysis generated from the official 200-301blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Visual reference
Go deeper
Related to this question
Learn chapter
Configuring Switch Ports for Desktops, VoIP Phones, APs, IoT, and Virtualized Hosts
Key term
STP
STP (Spanning Tree Protocol) is a network protocol that prevents loops in Ethernet networks by creating a loop-free logical topology.
Key term
BPDU Guard
BPDU Guard is a Cisco switch feature that protects the network from unauthorized devices by disabling a port if it receives a Bridge Protocol Data Unit (BPDU).
About these practice questions
One of 1,389 original 200-301 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-301 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-301 exam.