CCNA IP Routing Practice Question
What problem do first-hop redundancy protocols such as HSRP solve?
⚠ Common exam trap
A frequent exam trap is mistaking HSRP for a protocol that prevents duplicate MAC addresses or replaces Spanning Tree Protocol (STP). While STP prevents Layer 2 loops by blocking redundant paths, HSRP operates at Layer 3 to provide gateway redundancy. Another trap is assuming HSRP encrypts traffic between hosts and routers, which it does not. Candidates might also confuse HSRP with routing protocols like OSPF or EIGRP, but HSRP only manages default gateway availability, not routing decisions. Understanding these distinctions is crucial to avoid selecting incorrect options that describe unrelated network functions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
They provide a backup default gateway for end hosts
First-hop redundancy protocols allow hosts to use a virtual default gateway that can remain available even if one physical router fails.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
They prevent duplicate MAC addresses on a LAN
Why it's wrong here
FHRPs intentionally use a shared virtual MAC address for the active and standby routers, but detecting or preventing duplicate MAC addresses on a LAN is not their function. Duplicate MAC issues are generally resolved by Layer 2 features like MAC address table consistency checks, spanning tree, or careful network design. HSRP's virtual MAC is a single alias, not a mechanism to police other devices' MAC addresses.
When this WOULD be correct
In a different exam scenario, a question might ask about methods to manage MAC address conflicts in a LAN environment. In that context, an answer discussing how to prevent duplicate MAC addresses through network design or protocols would be correct.
- ✓
They provide a backup default gateway for end hosts
Why this is correct
FHRPs such as HSRP create a virtual IP and virtual MAC address that a group of routers share. One router is elected active and forwards traffic, while the standby router takes over seamlessly if the active fails. End hosts are configured with the virtual IP as their default gateway, so they always have a reachable next hop without needing to change their configuration.
- ✗
They replace spanning tree on switched networks
Why it's wrong here
Spanning Tree Protocol (STP) prevents Layer 2 forwarding loops in a switched or bridged network, while FHRPs provide default gateway redundancy for IP hosts. STP blocks redundant paths and maintains a loop-free topology; HSRP does not interact with bridge loops or switch port states. These protocols solve different problems and operate at different layers, so FHRP is not a substitute for STP.
When this WOULD be correct
If the exam question asked about the role of protocols that manage network topology and prevent loops in switched environments, then this option could be correct. For instance, a question might ask what protocols are used to ensure efficient data flow without loops, where spanning tree is the focus.
- ✗
They encrypt traffic between users and the default gateway
Why it's wrong here
FHRPs operate at the network and data-link layers to provide gateway redundancy; they have no mechanism for encrypting user payload. Encryption of host traffic is handled by protocols such as IPsec, TLS, or SSL, which are independent of HSRP/VRRP operation. While a failover may keep the gateway reachable, it does nothing to protect the confidentiality or integrity of the traffic itself.
When this WOULD be correct
In a different question asking about security measures for protecting data in transit between users and gateways, an option discussing encryption protocols like IPsec or SSL/TLS would be correct. If the question specifically asked about securing communication with the default gateway, this option could be relevant.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The 200-301 exam frequently reuses these exact scenarios with slightly different constraints.
✓They provide a backup default gateway for end hostsCorrect answer▾
Why this is correct
FHRPs such as HSRP create a virtual IP and virtual MAC address that a group of routers share. One router is elected active and forwards traffic, while the standby router takes over seamlessly if the active fails. End hosts are configured with the virtual IP as their default gateway, so they always have a reachable next hop without needing to change their configuration.
✗They prevent duplicate MAC addresses on a LANWrong answer — click to see why▾
Why this is wrong here
This option is incorrect because first-hop redundancy protocols like HSRP do not address the issue of duplicate MAC addresses; instead, they focus on providing redundancy for default gateways to ensure network availability.
★ When this WOULD be the correct answer
In a different exam scenario, a question might ask about methods to manage MAC address conflicts in a LAN environment. In that context, an answer discussing how to prevent duplicate MAC addresses through network design or protocols would be correct.
Why candidates choose this
Candidates may find this option tempting due to a general understanding of network protocols and their roles in managing network traffic, leading them to mistakenly associate redundancy protocols with MAC address management.
✗They replace spanning tree on switched networksWrong answer — click to see why▾
Why this is wrong here
This option is wrong because first-hop redundancy protocols like HSRP do not replace spanning tree protocols; rather, they work alongside them to ensure gateway availability. Spanning tree protocols manage loop prevention in switched networks, which is unrelated to first-hop redundancy.
★ When this WOULD be the correct answer
If the exam question asked about the role of protocols that manage network topology and prevent loops in switched environments, then this option could be correct. For instance, a question might ask what protocols are used to ensure efficient data flow without loops, where spanning tree is the focus.
Why candidates choose this
Candidates may find this option tempting due to the association of HSRP with network redundancy and stability, leading them to mistakenly believe it relates to loop prevention, which is a common concern in network design.
✗They encrypt traffic between users and the default gatewayWrong answer — click to see why▾
Why this is wrong here
This option is wrong because first-hop redundancy protocols like HSRP do not provide encryption for traffic; they focus on ensuring high availability of the default gateway for end hosts.
★ When this WOULD be the correct answer
In a different question asking about security measures for protecting data in transit between users and gateways, an option discussing encryption protocols like IPsec or SSL/TLS would be correct. If the question specifically asked about securing communication with the default gateway, this option could be relevant.
Why candidates choose this
Candidates may choose this option due to a common misconception that redundancy protocols also include security features, leading them to associate first-hop redundancy with overall network protection.
Analysis generated from the official 200-301blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Visual reference
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
Learn chapter
Interpreting HSRP and VRRP Operational Status
Key term
Redundancy
Redundancy is the practice of adding extra components or systems so that if one fails, another can take over without interruption.
Key term
Virtual IP
A Virtual IP (VIP) is a floating IP address shared among multiple servers or network devices to provide high availability and fault tolerance without being tied to a single physical interface.
About these practice questions
This 200-301 question is part of Courseiva's 1,389-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-301 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-301 exam.