CCNP Network Assurance Practice Question
A company has a network with multiple VLANs connected via a Layer 3 switch acting as the gateway for all VLANs. The network uses Rapid PVST+ for spanning tree. Recently, the network team added a new access switch to VLAN 100. After the switch was connected, users in VLAN 100 experienced intermittent connectivity, and the Layer 3 switch logs show 'SPANTREE-2-ROOTGUARD_BLOCK' messages for the port connected to the new switch. The new switch is intended to provide additional access ports for VLAN 100. The network team ensured that the new switch's configuration is correct for VLAN 100 access. What is the most likely cause of the issue, and what action should be taken to resolve it?
⚠ Common exam trap
Cisco often tests the misconception that Root Guard is the problem and should be disabled, when in fact the root cause is the new switch's bridge priority being too low, and the correct fix is to adjust the priority on the new switch.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure the new switch with a higher bridge priority (e.g., 28672) to prevent it from becoming the root bridge.
The issue is that the new switch, intended as an access switch, has a lower bridge priority (or default priority of 32768) than the existing root bridge for VLAN 100. When connected, it becomes the new root bridge, causing topology changes and intermittent connectivity. Root Guard on the Layer 3 switch port detects this superior BPDU and blocks the port to protect the root bridge position. Configuring the new switch with a higher bridge priority (e.g., 28672) ensures it cannot become the root bridge, resolving the Root Guard blocks.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Change the port configuration on the new switch to access mode for VLAN 100.
Why it's wrong here
Changing the new switch port to access mode for VLAN 100 does not stop the switch from transmitting spanning-tree BPDUs; access ports still participate in STP and can send BPDUs. Additionally, this change does not address the root guard mechanism, which blocks the port based on superior BPDUs received, regardless of trunk or access mode. It would also likely break VLAN 100 trunking for other VLANs, making this fix ineffective and harmful to the network design.
- ✗
Disable Root Guard on the Layer 3 switch port connected to the new switch.
Why it's wrong here
Disabling Root Guard on the Layer 3 switch port connected to the new switch removes the protection that prevents unauthorized or misconfigured switches from becoming the root bridge. If Root Guard is disabled, the new switch's lower bridge priority (or lower bridge ID) would cause it to be elected as root, leading to suboptimal forwarding paths and possible network instability. The correct solution is to reconfigure the new switch's STP priority so that it does not attempt to become root, not to disable a safety mechanism on the existing switch.
- ✓
Configure the new switch with a higher bridge priority (e.g., 28672) to prevent it from becoming the root bridge.
Why this is correct
Configuring the new switch with a higher bridge priority (e.g., 28672) ensures that its BPDUs are inferior to those of the current root bridge, so Root Guard on the Layer 3 switch port will no longer block the port. Since bridge priority is the first criterion in root bridge election, setting a value like 28672 (higher than the current root's priority) makes the new switch a non-root candidate. This resolves the root guard blocking while keeping the new switch operational and preserving the intended spanning-tree topology.
- ✗
Remove the new switch from the network because it is causing a BPDU attack.
Why it's wrong here
Removing the new switch from the network is an overreaction and incorrect because the switch is a legitimate part of the infrastructure, not a rogue device launching a BPDU attack. The port blocking is caused by Root Guard detecting superior BPDUs from the new switch, which is a configuration issue rather than a security breach. Simply removing the switch would disrupt connectivity and leave the underlying STP misconfiguration unresolved; the proper fix is to adjust the new switch's bridge priority.
Visual reference
Quick reference
OSI Model Reference
| Layer | Name | PDU | Key Protocols / Devices |
|---|---|---|---|
| 7 | Application | Data | HTTP, HTTPS, DNS, SMTP, FTP, SSH |
| 6 | Presentation | Data | TLS / SSL, JPEG, ASCII encoding |
| 5 | Session | Data | NetBIOS, RPC, SIP |
| 4 | Transport | Segment / Datagram | TCP, UDP |
| 3 | Network | Packet | IP, ICMP, OSPF — Routers |
| 2 | Data Link | Frame | Ethernet, Wi-Fi, PPP — Switches, Bridges |
| 1 | Physical | Bits | Cables, NICs, Hubs, Repeaters |
About these practice questions
Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.