Drag steps to the numbered slots on the right, or tap a step then tap a slot.
CCNA Switching and Network Access Practice Question
Drag and drop the following steps into the correct order to configure and recover from a BPDU guard violation on a PortFast-enabled access port.
⚠ Common exam trap
The trap is to think recovery must happen first, but the violation must occur to put the port into errdisable before recovery. The correct order is configure, trigger violation, recover, verify.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
Configure PortFast and BPDU guard on the interface.
The correct order is: first configure PortFast and BPDU guard on the interface (A). Then connect a switch to trigger a BPDU guard violation (B). Next, perform a shutdown followed by no shutdown to recover from the errdisable state (C). Finally, verify that the port is forwarding traffic (D). This sequence ensures the violation occurs before recovery, which is the realistic scenario.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Configure PortFast and BPDU guard on the interface.
Why this is correct
Configuring PortFast and BPDU guard is the first step because it establishes the protective mechanism that will later be tested. PortFast allows the access port to bypass STP listening and learning, while BPDU guard monitors that port and errdisables it if a BPDU is received. Without enabling both features on the interface, there is no guard to trigger during the subsequent violation test, making this configuration a prerequisite for the sequence.
- ✓
Connect a switch to the port to trigger a BPDU guard violation.
Why this is correct
Connecting a switch to the port to trigger a BPDU guard violation is the second step because it sends a real BPDU into the PortFast-enabled access port, causing BPDU guard to detect the unexpected bridge and place the port into errdisable. This intentionally simulates a rogue switch to verify that the guard is functioning correctly. Without this step, the protective feature would not be exercised, and you would have no evidence that the port is protected.
- ✓
Perform a shutdown and no shutdown on the interface to recover from the errdisable state.
Why this is correct
Performing a shutdown and no shutdown is the recovery step that clears the errdisable state created by BPDU guard. When a port enters errdisable, it is administratively disabled and does not forward traffic; the interface must be manually reinitialized to resume operation. This is the correct third step because it occurs after the intentional violation has been triggered and before any verification of the port's operational status.
- ✓
Verify that the port is back in service and forwarding traffic.
Why this is correct
Verifying that the port is back in service and forwarding traffic is the final validation step. You would check the interface status with commands like 'show interfaces status' or 'show interfaces switchport' to confirm the port is not in an errdisable state and is in forwarding mode, then test actual data-plane connectivity by pinging from an end device. This step proves that the configuration and recovery actions were effective and the port is fully operational.
Visual reference
Go deeper
Related to this question
Learn chapter
Configuring Switch Ports for Desktops, VoIP Phones, APs, IoT, and Virtualized Hosts
Key term
Switch
A switch is a networking device that connects devices on a local area network and uses MAC addresses to forward data only to the intended recipient.
Key term
PortFast
PortFast is a Cisco switch feature that immediately brings a port into the forwarding state, bypassing the normal Spanning Tree Protocol (STP) listening and learning phases, so that devices connected to that port can start communicating right away.
About these practice questions
One of 1,389 original 200-301 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-301 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-301 exam.