Courseiva
Switching and Network AccessmediumMultiple ChoiceObjective-mapped

CCNA Switching and Network Access Practice Question

Why is BPDU Guard commonly enabled on PortFast-enabled access ports?

⚠ Common exam trap

Don't confuse BPDU Guard with PortFast or BPDU filtering; each has distinct roles.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

To err-disable a port if it receives unexpected BPDUs

PortFast ports are meant for end devices, not for switches. BPDU Guard protects the LAN by shutting down a PortFast port that unexpectedly starts receiving BPDUs, which usually means an unauthorized switch was connected.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • To make STP root election happen faster

    Why it's wrong here

    Root bridge election speed depends on BPDU exchange, bridge priorities, and link costs, not on BPDU Guard. BPDU Guard is a security mechanism that reacts to unexpected BPDUs by error-disabling the port; it does not accelerate or otherwise affect the root election algorithm. In fact, if a legitimate BPDU is received, BPDU Guard would rather shut the port than allow STP to process it, which could impair convergence rather than speed it up.

    When this WOULD be correct

    In a scenario where the exam question asks about methods to optimize STP performance and mentions features that can enhance the speed of root bridge election, this option could be correct if it was framed around a hypothetical technology that accelerates STP processes.

  • To disable STP permanently on access ports

    Why it's wrong here

    PortFast does not disable Spanning Tree Protocol; it only skips the listening and learning states during the initial link-up to speed up access port convergence. The port still participates in STP and can transition to a blocking state if a superior BPDU is received. BPDU Guard adds a shutdown trigger, but STP remains active and can alter port states based on topology changes.

    When this WOULD be correct

    In a different exam scenario, if the question asked about a feature that disables STP on access ports to prevent any STP-related traffic, this option could be correct. For example, a question could specify a configuration where STP is not needed due to a specific network design.

  • To err-disable a port if it receives unexpected BPDUs

    Why this is correct

    BPDU Guard is a protective feature used with PortFast on access ports to prevent loops from unauthorized BPDUs. If the port receives any BPDU, which should not occur on an end-node connection, the switch immediately err-disables the interface to stop potential bridging loops. This safeguards the network from misconfigured or malicious devices.

  • To allow only one MAC address on the access port

    Why it's wrong here

    The restriction of a single MAC address on an access port is implemented by port security, which monitors MAC addresses and can shut down or restrict the port if the limit is exceeded. BPDU Guard has no effect on MAC address learning; it only scrutinizes BPDU frames arriving on the port. A port with BPDU Guard enabled can still learn multiple MAC addresses unless port security is separately configured with a maximum of one.

    When this WOULD be correct

    In a different exam scenario, if the question asked about the purpose of MAC address filtering on access ports, option D could be correct. For example, a question could state, 'What is the function of limiting MAC addresses on an access port?' where the correct answer would be to allow only one MAC address.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The 200-301 exam frequently reuses these exact scenarios with slightly different constraints.

To err-disable a port if it receives unexpected BPDUsCorrect answer

Why this is correct

BPDU Guard is a protective feature used with PortFast on access ports to prevent loops from unauthorized BPDUs. If the port receives any BPDU, which should not occur on an end-node connection, the switch immediately err-disables the interface to stop potential bridging loops. This safeguards the network from misconfigured or malicious devices.

To make STP root election happen fasterWrong answer — click to see why

Why this is wrong here

BPDU Guard is a security feature that err-disables a port upon receiving BPDUs; it does not accelerate root election. Root election speed is influenced by STP timers and bridge priorities, not BPDU Guard.

★ When this WOULD be the correct answer

In a scenario where the exam question asks about methods to optimize STP performance and mentions features that can enhance the speed of root bridge election, this option could be correct if it was framed around a hypothetical technology that accelerates STP processes.

Why candidates choose this

The name 'Guard' might suggest it protects or speeds up STP processes, but its purpose is purely protective, not performance-related.

To disable STP permanently on access portsWrong answer — click to see why

Why this is wrong here

BPDU Guard does not disable STP permanently; it only reacts to BPDU reception by err-disabling the port. STP remains active on other ports, and the port can be re-enabled after the violation is resolved.

★ When this WOULD be the correct answer

In a different exam scenario, if the question asked about a feature that disables STP on access ports to prevent any STP-related traffic, this option could be correct. For example, a question could specify a configuration where STP is not needed due to a specific network design.

Why candidates choose this

Students may confuse BPDU Guard with disabling STP because it prevents BPDU processing on the port, but STP is still running globally and on other ports.

To allow only one MAC address on the access portWrong answer — click to see why

Why this is wrong here

Limiting MAC addresses on a port is the function of port security, not BPDU Guard. BPDU Guard specifically monitors for BPDU frames and takes action if any are received.

★ When this WOULD be the correct answer

In a different exam scenario, if the question asked about the purpose of MAC address filtering on access ports, option D could be correct. For example, a question could state, 'What is the function of limiting MAC addresses on an access port?' where the correct answer would be to allow only one MAC address.

Why candidates choose this

Both features are commonly applied to access ports for security, leading to confusion between BPDU Guard and port security's MAC address limiting.

Analysis generated from the official 200-301blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

Visual reference

SW1 Root Bridge SW2 SW3 BLK DP DP RP RP STP blocks one link to prevent loops DP = Designated Port RP = Root Port BLK = Blocked

About these practice questions

This 200-301 question is part of Courseiva's 1,389-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-301 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-301 exam.