Courseiva
IP RoutingmediumMultiple ChoiceObjective-mapped

CCNA IP Routing Practice Question

What problem do first-hop redundancy protocols such as HSRP solve?

⚠ Common exam trap

A frequent exam trap is mistaking HSRP for a protocol that prevents duplicate MAC addresses or replaces Spanning Tree Protocol (STP). While STP prevents Layer 2 loops by blocking redundant paths, HSRP operates at Layer 3 to provide gateway redundancy. Another trap is assuming HSRP encrypts traffic between hosts and routers, which it does not. Candidates might also confuse HSRP with routing protocols like OSPF or EIGRP, but HSRP only manages default gateway availability, not routing decisions. Understanding these distinctions is crucial to avoid selecting incorrect options that describe unrelated network functions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

They provide a backup default gateway for end hosts

First-hop redundancy protocols allow hosts to use a virtual default gateway that can remain available even if one physical router fails.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • They prevent duplicate MAC addresses on a LAN

    Why it's wrong here

    FHRPs intentionally use a shared virtual MAC address for the active and standby routers, but detecting or preventing duplicate MAC addresses on a LAN is not their function. Duplicate MAC issues are generally resolved by Layer 2 features like MAC address table consistency checks, spanning tree, or careful network design. HSRP's virtual MAC is a single alias, not a mechanism to police other devices' MAC addresses.

    When this WOULD be correct

    In a different exam scenario, a question might ask about methods to manage MAC address conflicts in a LAN environment. In that context, an answer discussing how to prevent duplicate MAC addresses through network design or protocols would be correct.

  • They provide a backup default gateway for end hosts

    Why this is correct

    FHRPs such as HSRP create a virtual IP and virtual MAC address that a group of routers share. One router is elected active and forwards traffic, while the standby router takes over seamlessly if the active fails. End hosts are configured with the virtual IP as their default gateway, so they always have a reachable next hop without needing to change their configuration.

  • They replace spanning tree on switched networks

    Why it's wrong here

    Spanning Tree Protocol (STP) prevents Layer 2 forwarding loops in a switched or bridged network, while FHRPs provide default gateway redundancy for IP hosts. STP blocks redundant paths and maintains a loop-free topology; HSRP does not interact with bridge loops or switch port states. These protocols solve different problems and operate at different layers, so FHRP is not a substitute for STP.

    When this WOULD be correct

    If the exam question asked about the role of protocols that manage network topology and prevent loops in switched environments, then this option could be correct. For instance, a question might ask what protocols are used to ensure efficient data flow without loops, where spanning tree is the focus.

  • They encrypt traffic between users and the default gateway

    Why it's wrong here

    FHRPs operate at the network and data-link layers to provide gateway redundancy; they have no mechanism for encrypting user payload. Encryption of host traffic is handled by protocols such as IPsec, TLS, or SSL, which are independent of HSRP/VRRP operation. While a failover may keep the gateway reachable, it does nothing to protect the confidentiality or integrity of the traffic itself.

    When this WOULD be correct

    In a different question asking about security measures for protecting data in transit between users and gateways, an option discussing encryption protocols like IPsec or SSL/TLS would be correct. If the question specifically asked about securing communication with the default gateway, this option could be relevant.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The 200-301 exam frequently reuses these exact scenarios with slightly different constraints.

They provide a backup default gateway for end hostsCorrect answer

Why this is correct

FHRPs such as HSRP create a virtual IP and virtual MAC address that a group of routers share. One router is elected active and forwards traffic, while the standby router takes over seamlessly if the active fails. End hosts are configured with the virtual IP as their default gateway, so they always have a reachable next hop without needing to change their configuration.

They prevent duplicate MAC addresses on a LANWrong answer — click to see why

Why this is wrong here

This option is incorrect because first-hop redundancy protocols like HSRP do not address the issue of duplicate MAC addresses; instead, they focus on providing redundancy for default gateways to ensure network availability.

★ When this WOULD be the correct answer

In a different exam scenario, a question might ask about methods to manage MAC address conflicts in a LAN environment. In that context, an answer discussing how to prevent duplicate MAC addresses through network design or protocols would be correct.

Why candidates choose this

Candidates may find this option tempting due to a general understanding of network protocols and their roles in managing network traffic, leading them to mistakenly associate redundancy protocols with MAC address management.

They replace spanning tree on switched networksWrong answer — click to see why

Why this is wrong here

This option is wrong because first-hop redundancy protocols like HSRP do not replace spanning tree protocols; rather, they work alongside them to ensure gateway availability. Spanning tree protocols manage loop prevention in switched networks, which is unrelated to first-hop redundancy.

★ When this WOULD be the correct answer

If the exam question asked about the role of protocols that manage network topology and prevent loops in switched environments, then this option could be correct. For instance, a question might ask what protocols are used to ensure efficient data flow without loops, where spanning tree is the focus.

Why candidates choose this

Candidates may find this option tempting due to the association of HSRP with network redundancy and stability, leading them to mistakenly believe it relates to loop prevention, which is a common concern in network design.

They encrypt traffic between users and the default gatewayWrong answer — click to see why

Why this is wrong here

This option is wrong because first-hop redundancy protocols like HSRP do not provide encryption for traffic; they focus on ensuring high availability of the default gateway for end hosts.

★ When this WOULD be the correct answer

In a different question asking about security measures for protecting data in transit between users and gateways, an option discussing encryption protocols like IPsec or SSL/TLS would be correct. If the question specifically asked about securing communication with the default gateway, this option could be relevant.

Why candidates choose this

Candidates may choose this option due to a common misconception that redundancy protocols also include security features, leading them to associate first-hop redundancy with overall network protection.

Analysis generated from the official 200-301blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

Visual reference

SW1 Root Bridge SW2 SW3 BLK DP DP RP RP STP blocks one link to prevent loops DP = Designated Port RP = Root Port BLK = Blocked

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

This 200-301 question is part of Courseiva's 1,389-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-301 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-301 exam.