Drag or tap steps into the slots.
CCNA PortFast Practice Question
Drag and drop the following steps into the correct order to configure PortFast and BPDU Guard on a switch access port, and then recover after a BPDU Guard error-disable event.
⚠ Common exam trap
Be aware that there are multiple valid ways to configure and recover from BPDU Guard. The order of steps within each method must be respected: PortFast must be enabled before BPDU Guard on the interface (unless using global defaults), and recovery commands must be configured before the error occurs for automatic recovery. Do not mix steps from different methods.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
Enter global configuration mode, then interface configuration mode, enable PortFast, enable BPDU Guard, and after an error-disable event, manually re-enable the interface using the 'shutdown' command followed by the 'no shutdown' command.
This drag-and-drop question presents four distinct step sequences, each representing a valid method to configure PortFast and BPDU Guard on an access port and handle a BPDU Guard error-disable event. Option A describes the manual recovery method: enter global config, interface config, enable PortFast, enable BPDU Guard, then manually recover with 'shutdown' followed by 'no shutdown'. Option B describes automatic recovery using the 'errdisable recovery cause bpduguard' global command, which must be configured before the error occurs. Option C describes an alternative using the 'clear spanning-tree bpduguard' command to recover without manual interface reset. Option D uses the global default 'spanning-tree portfast bpduguard default' command. All sequences are correct when ordered properly for their specific approach.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Enter global configuration mode, then interface configuration mode, enable PortFast, enable BPDU Guard, and after an error-disable event, manually re-enable the interface using the 'shutdown' command followed by the 'no shutdown' command.
Why this is correct
This sequence correctly follows the standard Cisco configuration steps: first enter global config, then interface config, enable PortFast (spanning-tree portfast), enable BPDU Guard (spanning-tree bpduguard enable), and after an error-disable event, recover by re-enabling the port with 'no shutdown'.
- ✓
Enter global configuration mode, enable BPDU Guard, enable PortFast, then after an error-disable event, automatically recover the port using the 'errdisable recovery cause bpduguard' command.
Why this is correct
This is incorrect because BPDU Guard should be enabled after PortFast on the interface, and automatic recovery is not the default recovery method; manual recovery with 'no shutdown' is the standard approach.
- ✓
Enter interface configuration mode directly, enable PortFast, enable BPDU Guard, and after an error-disable event, use the 'clear spanning-tree bpduguard' command to recover the port.
Why this is correct
This is incorrect because you must first enter global configuration mode before interface configuration mode, and the 'clear spanning-tree bpduguard' command does not recover an error-disabled port; it clears BPDU Guard statistics.
- ✓
Enter global configuration mode, then interface configuration mode, enable BPDU Guard, enable PortFast, and after an error-disable event, automatically recover by configuring 'spanning-tree portfast bpduguard default' globally.
Why this is correct
This is incorrect because PortFast must be enabled before BPDU Guard on the interface, and the global command 'spanning-tree portfast bpduguard default' enables BPDU Guard globally on all PortFast-enabled ports, but it does not automatically recover an error-disabled port.
Visual reference
Go deeper
Related to this question
Learn chapter
Lab: Configure Port Security
Key term
Interface
An interface is a point of connection or interaction between two systems, devices, or software components that allows them to exchange information or signals.
Key term
BPDU
A Bridge Protocol Data Unit is a layer 2 frame that switches use to exchange information about the Spanning Tree Protocol (STP) to prevent network loops.
About these practice questions
This 200-301 question is part of Courseiva's 1,450-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-301 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-301 exam.