CCNA Switching and Network Access Practice Question
Why is BPDU Guard commonly enabled on PortFast-enabled access ports?
⚠ Common exam trap
Don't confuse BPDU Guard with PortFast or BPDU filtering; each has distinct roles.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
To err-disable a port if it receives unexpected BPDUs
PortFast ports are meant for end devices, not for switches. BPDU Guard protects the LAN by shutting down a PortFast port that unexpectedly starts receiving BPDUs, which usually means an unauthorized switch was connected.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
To make STP root election happen faster
Why it's wrong here
Root bridge election speed depends on BPDU exchange, bridge priorities, and link costs, not on BPDU Guard. BPDU Guard is a security mechanism that reacts to unexpected BPDUs by error-disabling the port; it does not accelerate or otherwise affect the root election algorithm. In fact, if a legitimate BPDU is received, BPDU Guard would rather shut the port than allow STP to process it, which could impair convergence rather than speed it up.
When this WOULD be correct
In a scenario where the exam question asks about methods to optimize STP performance and mentions features that can enhance the speed of root bridge election, this option could be correct if it was framed around a hypothetical technology that accelerates STP processes.
- ✗
To disable STP permanently on access ports
Why it's wrong here
PortFast does not disable Spanning Tree Protocol; it only skips the listening and learning states during the initial link-up to speed up access port convergence. The port still participates in STP and can transition to a blocking state if a superior BPDU is received. BPDU Guard adds a shutdown trigger, but STP remains active and can alter port states based on topology changes.
When this WOULD be correct
In a different exam scenario, if the question asked about a feature that disables STP on access ports to prevent any STP-related traffic, this option could be correct. For example, a question could specify a configuration where STP is not needed due to a specific network design.
- ✓
To err-disable a port if it receives unexpected BPDUs
Why this is correct
BPDU Guard is a protective feature used with PortFast on access ports to prevent loops from unauthorized BPDUs. If the port receives any BPDU, which should not occur on an end-node connection, the switch immediately err-disables the interface to stop potential bridging loops. This safeguards the network from misconfigured or malicious devices.
- ✗
To allow only one MAC address on the access port
Why it's wrong here
The restriction of a single MAC address on an access port is implemented by port security, which monitors MAC addresses and can shut down or restrict the port if the limit is exceeded. BPDU Guard has no effect on MAC address learning; it only scrutinizes BPDU frames arriving on the port. A port with BPDU Guard enabled can still learn multiple MAC addresses unless port security is separately configured with a maximum of one.
When this WOULD be correct
In a different exam scenario, if the question asked about the purpose of MAC address filtering on access ports, option D could be correct. For example, a question could state, 'What is the function of limiting MAC addresses on an access port?' where the correct answer would be to allow only one MAC address.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The 200-301 exam frequently reuses these exact scenarios with slightly different constraints.
✓To err-disable a port if it receives unexpected BPDUsCorrect answer▾
Why this is correct
BPDU Guard is a protective feature used with PortFast on access ports to prevent loops from unauthorized BPDUs. If the port receives any BPDU, which should not occur on an end-node connection, the switch immediately err-disables the interface to stop potential bridging loops. This safeguards the network from misconfigured or malicious devices.
✗To make STP root election happen fasterWrong answer — click to see why▾
Why this is wrong here
BPDU Guard is a security feature that err-disables a port upon receiving BPDUs; it does not accelerate root election. Root election speed is influenced by STP timers and bridge priorities, not BPDU Guard.
★ When this WOULD be the correct answer
In a scenario where the exam question asks about methods to optimize STP performance and mentions features that can enhance the speed of root bridge election, this option could be correct if it was framed around a hypothetical technology that accelerates STP processes.
Why candidates choose this
The name 'Guard' might suggest it protects or speeds up STP processes, but its purpose is purely protective, not performance-related.
✗To disable STP permanently on access portsWrong answer — click to see why▾
Why this is wrong here
BPDU Guard does not disable STP permanently; it only reacts to BPDU reception by err-disabling the port. STP remains active on other ports, and the port can be re-enabled after the violation is resolved.
★ When this WOULD be the correct answer
In a different exam scenario, if the question asked about a feature that disables STP on access ports to prevent any STP-related traffic, this option could be correct. For example, a question could specify a configuration where STP is not needed due to a specific network design.
Why candidates choose this
Students may confuse BPDU Guard with disabling STP because it prevents BPDU processing on the port, but STP is still running globally and on other ports.
✗To allow only one MAC address on the access portWrong answer — click to see why▾
Why this is wrong here
Limiting MAC addresses on a port is the function of port security, not BPDU Guard. BPDU Guard specifically monitors for BPDU frames and takes action if any are received.
★ When this WOULD be the correct answer
In a different exam scenario, if the question asked about the purpose of MAC address filtering on access ports, option D could be correct. For example, a question could state, 'What is the function of limiting MAC addresses on an access port?' where the correct answer would be to allow only one MAC address.
Why candidates choose this
Both features are commonly applied to access ports for security, leading to confusion between BPDU Guard and port security's MAC address limiting.
Analysis generated from the official 200-301blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Visual reference
Go deeper
Related to this question
Learn chapter
Configuring Switch Ports for Desktops, VoIP Phones, APs, IoT, and Virtualized Hosts
Key term
Switch
A switch is a networking device that connects devices on a local area network and uses MAC addresses to forward data only to the intended recipient.
Key term
BPDU Guard
BPDU Guard is a Cisco switch feature that protects the network from unauthorized devices by disabling a port if it receives a Bridge Protocol Data Unit (BPDU).
About these practice questions
This 200-301 question is part of Courseiva's 1,389-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-301 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-301 exam.