Courseiva
Switching and Network AccessmediumDrag & DropObjective-mapped

CCNA Switching and Network Access Practice Question

Drag and drop the following steps into the correct order to configure and recover from a BPDU guard violation on a PortFast-enabled access port.

Drag steps to the numbered slots on the right, or tap a step then tap a slot.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

⚠ Common exam trap

The trap is to think recovery must happen first, but the violation must occur to put the port into errdisable before recovery. The correct order is configure, trigger violation, recover, verify.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Configure PortFast and BPDU guard on the interface.

The correct order is: first configure PortFast and BPDU guard on the interface (A). Then connect a switch to trigger a BPDU guard violation (B). Next, perform a shutdown followed by no shutdown to recover from the errdisable state (C). Finally, verify that the port is forwarding traffic (D). This sequence ensures the violation occurs before recovery, which is the realistic scenario.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Configure PortFast and BPDU guard on the interface.

    Why this is correct

    Configuring PortFast and BPDU guard is the first step because it establishes the protective mechanism that will later be tested. PortFast allows the access port to bypass STP listening and learning, while BPDU guard monitors that port and errdisables it if a BPDU is received. Without enabling both features on the interface, there is no guard to trigger during the subsequent violation test, making this configuration a prerequisite for the sequence.

  • Connect a switch to the port to trigger a BPDU guard violation.

    Why this is correct

    Connecting a switch to the port to trigger a BPDU guard violation is the second step because it sends a real BPDU into the PortFast-enabled access port, causing BPDU guard to detect the unexpected bridge and place the port into errdisable. This intentionally simulates a rogue switch to verify that the guard is functioning correctly. Without this step, the protective feature would not be exercised, and you would have no evidence that the port is protected.

  • Perform a shutdown and no shutdown on the interface to recover from the errdisable state.

    Why this is correct

    Performing a shutdown and no shutdown is the recovery step that clears the errdisable state created by BPDU guard. When a port enters errdisable, it is administratively disabled and does not forward traffic; the interface must be manually reinitialized to resume operation. This is the correct third step because it occurs after the intentional violation has been triggered and before any verification of the port's operational status.

  • Verify that the port is back in service and forwarding traffic.

    Why this is correct

    Verifying that the port is back in service and forwarding traffic is the final validation step. You would check the interface status with commands like 'show interfaces status' or 'show interfaces switchport' to confirm the port is not in an errdisable state and is in forwarding mode, then test actual data-plane connectivity by pinging from an end device. This step proves that the configuration and recovery actions were effective and the port is fully operational.

Visual reference

SW1 Root Bridge SW2 SW3 BLK DP DP RP RP STP blocks one link to prevent loops DP = Designated Port RP = Root Port BLK = Blocked

Go deeper

Related to this question

About these practice questions

One of 1,389 original 200-301 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-301 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-301 exam.