Courseiva
Network Assurance →hardMultiple Choice

CCNP Network Assurance Practice Question

A company has a network with multiple VLANs connected via a Layer 3 switch acting as the gateway for all VLANs. The network uses Rapid PVST+ for spanning tree. Recently, the network team added a new access switch to VLAN 100. After the switch was connected, users in VLAN 100 experienced intermittent connectivity, and the Layer 3 switch logs show 'SPANTREE-2-ROOTGUARD_BLOCK' messages for the port connected to the new switch. The new switch is intended to provide additional access ports for VLAN 100. The network team ensured that the new switch's configuration is correct for VLAN 100 access. What is the most likely cause of the issue, and what action should be taken to resolve it?

⚠ Common exam trap

Cisco often tests the misconception that Root Guard is the problem and should be disabled, when in fact the root cause is the new switch's bridge priority being too low, and the correct fix is to adjust the priority on the new switch.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure the new switch with a higher bridge priority (e.g., 28672) to prevent it from becoming the root bridge.

The issue is that the new switch, intended as an access switch, has a lower bridge priority (or default priority of 32768) than the existing root bridge for VLAN 100. When connected, it becomes the new root bridge, causing topology changes and intermittent connectivity. Root Guard on the Layer 3 switch port detects this superior BPDU and blocks the port to protect the root bridge position. Configuring the new switch with a higher bridge priority (e.g., 28672) ensures it cannot become the root bridge, resolving the Root Guard blocks.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Change the port configuration on the new switch to access mode for VLAN 100.

    Why it's wrong here

    Changing the new switch port to access mode for VLAN 100 does not stop the switch from transmitting spanning-tree BPDUs; access ports still participate in STP and can send BPDUs. Additionally, this change does not address the root guard mechanism, which blocks the port based on superior BPDUs received, regardless of trunk or access mode. It would also likely break VLAN 100 trunking for other VLANs, making this fix ineffective and harmful to the network design.

  • ✗

    Disable Root Guard on the Layer 3 switch port connected to the new switch.

    Why it's wrong here

    Disabling Root Guard on the Layer 3 switch port connected to the new switch removes the protection that prevents unauthorized or misconfigured switches from becoming the root bridge. If Root Guard is disabled, the new switch's lower bridge priority (or lower bridge ID) would cause it to be elected as root, leading to suboptimal forwarding paths and possible network instability. The correct solution is to reconfigure the new switch's STP priority so that it does not attempt to become root, not to disable a safety mechanism on the existing switch.

  • ✓

    Configure the new switch with a higher bridge priority (e.g., 28672) to prevent it from becoming the root bridge.

    Why this is correct

    Configuring the new switch with a higher bridge priority (e.g., 28672) ensures that its BPDUs are inferior to those of the current root bridge, so Root Guard on the Layer 3 switch port will no longer block the port. Since bridge priority is the first criterion in root bridge election, setting a value like 28672 (higher than the current root's priority) makes the new switch a non-root candidate. This resolves the root guard blocking while keeping the new switch operational and preserving the intended spanning-tree topology.

  • ✗

    Remove the new switch from the network because it is causing a BPDU attack.

    Why it's wrong here

    Removing the new switch from the network is an overreaction and incorrect because the switch is a legitimate part of the infrastructure, not a rogue device launching a BPDU attack. The port blocking is caused by Root Guard detecting superior BPDUs from the new switch, which is a configuration issue rather than a security breach. Simply removing the switch would disrupt connectivity and leave the underlying STP misconfiguration unresolved; the proper fix is to adjust the new switch's bridge priority.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

Quick reference

OSI Model Reference

LayerNamePDUKey Protocols / Devices
7ApplicationDataHTTP, HTTPS, DNS, SMTP, FTP, SSH
6PresentationDataTLS / SSL, JPEG, ASCII encoding
5SessionDataNetBIOS, RPC, SIP
4TransportSegment / DatagramTCP, UDP
3NetworkPacketIP, ICMP, OSPF — Routers
2Data LinkFrameEthernet, Wi-Fi, PPP — Switches, Bridges
1PhysicalBitsCables, NICs, Hubs, Repeaters

About these practice questions

Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.