CCNA Switching and Network Access Practice Question
A network engineer notices that an uplink port on a distribution switch has moved to a root-inconsistent state and is blocking traffic. The port is configured with Root Guard and is connected to a new access switch. The new access switch has a lower bridge priority than the current root bridge. What is the most likely cause?
⚠ Common exam trap
Cisco often tests the distinction between Root Guard and BPDU Guard, where candidates confuse the root-inconsistent state with an errdisable state or assume any BPDU-related protection will errdisable the port.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Root Guard has placed the port into root-inconsistent state because the new switch advertised a superior BPDU.
Root Guard is configured on the uplink port of the distribution switch. When the new access switch advertises a superior BPDU (lower bridge priority than the current root bridge), Root Guard places the port into a root-inconsistent state to prevent the distribution switch from accepting the new switch as the root bridge. This blocks traffic on that port to protect the spanning-tree topology.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
BPDU Guard has errdisabled the port because a BPDU was received on an access port.
Why it's wrong here
BPDU Guard is a PortFast enhancement that places a port into errdisable state, not a root-inconsistent STP state, when an unauthorized BPDU is received. It is typically enabled only on access ports that use PortFast to connect to end hosts, so an uplink trunk carrying BPDUs to another switch would not normally trigger it. Even if BPDU Guard were triggered, the port would show as err-disabled, not root-inconsistent, which is the state described in the scenario.
- ✗
BPDU Filter is blocking inbound BPDUs, causing the switch to fail to detect the topology change and isolate the port.
Why it's wrong here
BPDU Filter, whether configured globally or per port, simply suppresses BPDU transmission or processing; it does not create a root-inconsistent port state or block forwarded traffic. If inbound BPDUs were actually being filtered, the switch would never have seen the superior BPDU that triggered the problem, which directly contradicts the stated symptom. The failure to receive BPDUs would instead cause STP to age out information and potentially transition the port to designated, not root-inconsistent, making this explanation inconsistent with the observed behavior.
- ✓
Root Guard has placed the port into root-inconsistent state because the new switch advertised a superior BPDU.
Why this is correct
Root Guard is designed to prevent the port from becoming a root port. Upon receiving a superior BPDU (lower bridge ID), it places the port in root-inconsistent state, effectively blocking traffic. This directly matches the symptom described.
- ✗
Loop Guard has detected a unidirectional link and placed the port in a blocking state to prevent a loop.
Why it's wrong here
Loop Guard is designed to detect the loss of BPDUs on non-designated ports, which often indicates a unidirectional link, and it transitions the port to a loop-inconsistent state rather than a root-inconsistent state. Here the problem is not missing BPDUs but receiving a superior BPDU from a new switch, which is exactly the condition Root Guard monitors. Loop Guard would not be triggered by an incoming superior BPDU, and its resulting state name does not match the root-inconsistent state described in the question.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The 200-301 exam frequently reuses these exact scenarios with slightly different constraints.
✓Root Guard has placed the port into root-inconsistent state because the new switch advertised a superior BPDU.Correct answer▾
Why this is correct
Root Guard is designed to prevent the port from becoming a root port. Upon receiving a superior BPDU (lower bridge ID), it places the port in root-inconsistent state, effectively blocking traffic. This directly matches the symptom described.
✗BPDU Guard has errdisabled the port because a BPDU was received on an access port.Wrong answer — click to see why▾
Why this is wrong here
Candidates mistakenly equate BPDU Guard with any BPDU-induced blocking, but the state 'root-inconsistent' is specific to Root Guard.
✗BPDU Filter is blocking inbound BPDUs, causing the switch to fail to detect the topology change and isolate the port.Wrong answer — click to see why▾
Why this is wrong here
Candidates may think that filtering BPDUs leads to port isolation, but BPDU Filter would not trigger a protective state like root-inconsistent.
✗Loop Guard has detected a unidirectional link and placed the port in a blocking state to prevent a loop.Wrong answer — click to see why▾
Why this is wrong here
Candidates often confuse Loop Guard and Root Guard because both can cause inconsistent states, but Loop Guard triggers loop-inconsistent, not root-inconsistent, and is triggered by BPDU loss, not receipt of superior BPDUs.
Analysis generated from the official 200-301blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Visual reference
Go deeper
Related to this question
Learn chapter
Configuring Switch Ports for Desktops, VoIP Phones, APs, IoT, and Virtualized Hosts
Key term
Bridge Protocol Data Unit
A Bridge Protocol Data Unit (BPDU) is a special message that network switches exchange to detect and prevent loops in an Ethernet network.
Key term
Root bridge
The root bridge is the central reference point in a Spanning Tree Protocol (STP) network, serving as the logical root of the spanning tree topology.
About these practice questions
This 200-301 question is part of Courseiva's 1,389-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-301 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-301 exam.