Courseiva
Switching and Network AccesshardMultiple ChoiceObjective-mapped

CCNA Switching and Network Access Practice Question

Exhibit

Interface Gi1/0/12:
 switchport mode access
 spanning-tree portfast
 spanning-tree bpduguard enable
Status after connection: err-disabled

Exhibit: After a new switch was connected, the access-layer port went into err-disabled state immediately. Which feature most likely caused this?

⚠ Common exam trap

Be cautious not to confuse BPDU Guard with other features that cause err-disabled states, like Port Security or UDLD, which are unrelated to BPDU receipt.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

BPDU Guard

BPDU Guard is the most likely cause because it immediately places a PortFast-enabled port into the err-disabled state upon receiving any BPDU, which is exactly what happens when a new switch is connected to an access port meant for end devices. Root Guard does not err-disable a port; instead, it puts the port into a root-inconsistent state when a superior BPDU is received, preventing the port from becoming a root port but still allowing traffic. UDLD aggressive can cause err-disabled states, but it is specifically designed to detect unidirectional links on fiber connections and requires a delay or misconfiguration, making it less immediate than BPDU Guard in this scenario. Storm control can err-disable a port if traffic exceeds thresholds, but this is not immediate upon connection unless a broadcast storm is already occurring, which is not indicated in the scenario.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Root Guard

    Why it's wrong here

    Root Guard prevents a port from becoming a root port or propagating superior BPDUs, but it does not disable the port upon receiving BPDUs from an unauthorized switch. Instead, it moves the port to a root-inconsistent state while still allowing normal STP operation otherwise. In this access-layer scenario, a newly attached switch sending BPDUs would not be blocked; Root Guard only stops that switch from assuming the root bridge role, leaving the network vulnerable to loops or topology changes.

    When this WOULD be correct

    In a scenario where a switch port is configured with Root Guard and a rogue switch attempts to become the root bridge by sending BPDUs, the port would go into a blocking state to protect the network. A question could ask about the impact of Root Guard on a port when a new switch sends BPDUs.

  • UDLD aggressive

    Why it's wrong here

    UDLD aggressive mode detects unidirectional links by exchanging periodic hello packets and error-disables the port when the link fails to echo back, typically on fiber or point-to-point connections. It does not interpret or respond to the content of BPDUs, so a rogue switch sending STP frames would remain undetected. The problem here is unauthorized STP participation, not one-way physical connectivity; therefore UDLD aggressive is a distractor.

    When this WOULD be correct

    If the exam question asked about a scenario where a switch port was connected to a device that was misconfigured, causing a unidirectional link, then UDLD aggressive could be the correct answer as it would disable the port to prevent network issues.

  • BPDU Guard

    Why this is correct

    BPDU Guard is the correct choice because it protects access ports from unauthorized switches by immediately placing the port in an err-disabled state when any BPDU is received. This stops the newly connected switch from participating in Spanning Tree Protocol, preventing potential loops or root bridge manipulation. It is specifically designed for access-layer ports where no BPDUs should ever legitimately appear, making it the right defense for this scenario.

  • Storm control

    Why it's wrong here

    Storm control monitors incoming traffic for broadcast, multicast, or unknown unicast packets and applies a threshold to prevent a packet storm from overwhelming the link. It does not inspect or react to BPDUs, so connecting a new switch that sends STP frames would not trigger storm control. The port would remain up and the rogue switch could still cause an STP issue; storm control is designed for data-plane flooding, not to enforce access-layer port security.

    When this WOULD be correct

    If the question were about a switch port that was experiencing excessive broadcast traffic due to a misconfigured device, leading to the port being disabled by storm control, then this option would be correct. It would involve a scenario where traffic thresholds were exceeded, triggering storm control mechanisms.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The 200-301 exam frequently reuses these exact scenarios with slightly different constraints.

BPDU GuardCorrect answer

Why this is correct

BPDU Guard is the correct choice because it protects access ports from unauthorized switches by immediately placing the port in an err-disabled state when any BPDU is received. This stops the newly connected switch from participating in Spanning Tree Protocol, preventing potential loops or root bridge manipulation. It is specifically designed for access-layer ports where no BPDUs should ever legitimately appear, making it the right defense for this scenario.

Root GuardWrong answer — click to see why

Why this is wrong here

Root Guard does not cause a port to go into err-disabled state; instead, it places the port into a root-inconsistent state if a superior BPDU is received, blocking traffic but not disabling the port. The question describes an immediate err-disabled state, which is characteristic of BPDU Guard, not Root Guard.

★ When this WOULD be the correct answer

In a scenario where a switch port is configured with Root Guard and a rogue switch attempts to become the root bridge by sending BPDUs, the port would go into a blocking state to protect the network. A question could ask about the impact of Root Guard on a port when a new switch sends BPDUs.

Why candidates choose this

Students may confuse Root Guard with BPDU Guard because both are STP security features that react to BPDUs. However, Root Guard only prevents a port from becoming a root port, while BPDU Guard disables the port upon BPDU reception.

UDLD aggressiveWrong answer — click to see why

Why this is wrong here

UDLD aggressive mode does not immediately cause an err-disabled state upon connecting a new switch; it detects unidirectional links by sending probes and can put the port into err-disabled state only after a failure is detected, which takes time. The immediate err-disabled state suggests a feature that reacts instantly to BPDUs.

★ When this WOULD be the correct answer

If the exam question asked about a scenario where a switch port was connected to a device that was misconfigured, causing a unidirectional link, then UDLD aggressive could be the correct answer as it would disable the port to prevent network issues.

Why candidates choose this

Students may associate UDLD with err-disabled state because it can disable ports, but UDLD is for detecting unidirectional links, not for preventing unauthorized switches. The immediate reaction to a new switch connection is more indicative of BPDU Guard.

Storm controlWrong answer — click to see why

Why this is wrong here

Storm control does not cause a port to go into err-disabled state by default; it typically drops traffic exceeding a threshold or can be configured to shut down the port, but the immediate err-disabled state upon connecting a new switch is not typical for storm control. The scenario points to a feature that reacts to BPDUs, not broadcast storms.

★ When this WOULD be the correct answer

If the question were about a switch port that was experiencing excessive broadcast traffic due to a misconfigured device, leading to the port being disabled by storm control, then this option would be correct. It would involve a scenario where traffic thresholds were exceeded, triggering storm control mechanisms.

Why candidates choose this

Students might think that a new switch could cause a broadcast storm, leading to storm control triggering. However, storm control is designed to handle excessive broadcast, multicast, or unicast traffic, not the initial connection of a switch.

Analysis generated from the official 200-301blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

Visual reference

SW1 Root Bridge SW2 SW3 BLK DP DP RP RP STP blocks one link to prevent loops DP = Designated Port RP = Root Port BLK = Blocked

About these practice questions

This 200-301 question is part of Courseiva's 1,389-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-301 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-301 exam.