Drag or tap steps into the slots.
CCNA PortFast Practice Question
Which of the following sequences correctly configures and verifies PortFast and BPDU Guard on a Cisco IOS-XE switch interface, and then recovers after a BPDU guard violation?
⚠ Common exam trap
The exam trap is that candidates may confuse the order of PortFast and BPDU Guard, or think that recovery requires a switch reload or a special clear command. Remember: PortFast first, then BPDU Guard; recovery is always 'shutdown/no shutdown' on the interface.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
Enter global configuration mode, then interface configuration mode, enable PortFast, enable BPDU Guard, verify with show commands, and recover by shutting down and no shutting down the interface.
The correct sequence is described in option A: enter global configuration mode, then interface configuration mode, enable PortFast first, then BPDU Guard, verify with show commands, and recover by shutting down and no shutting down the interface. Options B, C, and D are incorrect because they contain errors such as wrong order of enabling features, improper recovery methods (reload, removal of BPDU Guard, or clear errdisable interface), or enabling BPDU Guard globally. Only option A follows the proper Cisco IOS-XE procedure for configuring and recovering from a BPDU guard violation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Enter global configuration mode, then interface configuration mode, enable PortFast, enable BPDU Guard, verify with show commands, and recover by shutting down and no shutting down the interface.
Why this is correct
Correct. It follows the proper order: global config, interface, PortFast, BPDU Guard, verification, and recovery with shutdown/no shutdown.
- ✗
Enter interface configuration mode, enable BPDU Guard, enable PortFast, exit to global config, verify, and recover by reloading the switch.
Why it's wrong here
Incorrect. BPDU Guard should be enabled after PortFast, not before. Also, recovery by reloading the switch is not the standard method; shutdown/no shutdown or clear errdisable interface is preferred.
- ✗
Enter global configuration mode, enable BPDU Guard globally, then enter interface configuration mode, enable PortFast, verify, and recover by removing BPDU Guard.
Why it's wrong here
Incorrect. The question specifies configuring on an interface, but this option enables BPDU Guard globally. Also, recovery by removing BPDU Guard does not bring the interface out of error-disable state; it must be manually re-enabled.
- ✗
Enter interface configuration mode, enable PortFast, enable BPDU Guard, exit to global config, verify, and recover by issuing 'clear errdisable interface' command.
Why it's wrong here
Incorrect. While the order of enabling PortFast before BPDU Guard is correct, the recovery method using 'clear errdisable interface' is not the standard recovery in the context of this sequence. The expected recovery is shutdown/no shutdown.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The 200-301 exam frequently reuses these exact scenarios with slightly different constraints.
✓Enter global configuration mode, then interface configuration mode, enable PortFast, enable BPDU Guard, verify with show commands, and recover by shutting down and no shutting down the interface.Correct answer▾
Why this is correct
Correct. It follows the proper order: global config, interface, PortFast, BPDU Guard, verification, and recovery with shutdown/no shutdown.
✗Enter interface configuration mode, enable BPDU Guard, enable PortFast, exit to global config, verify, and recover by reloading the switch.Wrong answer — click to see why▾
Why this is wrong here
The specific factual error: BPDU Guard is typically enabled after PortFast, and recovery from errdisable does not require reloading the switch.
Why candidates choose this
Candidates might think BPDU Guard can be enabled independently of PortFast, or that a reload is necessary to clear the errdisable state.
✗Enter global configuration mode, enable BPDU Guard globally, then enter interface configuration mode, enable PortFast, verify, and recover by removing BPDU Guard.Wrong answer — click to see why▾
Why this is wrong here
The specific factual error: The order suggests global BPDU Guard before interface PortFast, and recovery involves removing BPDU Guard, which is unnecessary.
Why candidates choose this
Candidates may confuse global and interface-level configuration, or think that removing the protective feature is part of recovery.
✗Enter interface configuration mode, enable PortFast, enable BPDU Guard, exit to global config, verify, and recover by issuing 'clear errdisable interface' command.Wrong answer — click to see why▾
Why this is wrong here
The specific factual error: 'clear errdisable interface' is not a valid Cisco IOS command; the correct recovery is 'shutdown' followed by 'no shutdown'.
Why candidates choose this
Candidates might assume there is a 'clear' command to reset errdisable state, similar to 'clear counters' or 'clear mac address-table'.
Analysis generated from the official 200-301blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Visual reference
Go deeper
Related to this question
Learn chapter
Cisco IOS Password Types
Key term
Interface
An interface is a point of connection or interaction between two systems, devices, or software components that allows them to exchange information or signals.
Key term
BPDU
A Bridge Protocol Data Unit is a layer 2 frame that switches use to exchange information about the Spanning Tree Protocol (STP) to prevent network loops.
About these practice questions
One of 1,450 original 200-301 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-301 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-301 exam.