CCNP Security Practice Question
A network administrator at a small company wants to prevent users from plugging unauthorized switches into wall jacks and creating loops or bypassing security controls. The administrator decides to implement BPDU Guard on all access ports on a Cisco Catalyst switch. Which statement accurately describes the behavior of BPDU Guard when configured on an access port?
⚠ Common exam trap
It's easy for candidates to confuse BPDU Guard with BPDU Filter, where BPDU Filter suppresses BPDUs while BPDU Guard disables the port upon receiving one.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
It places the port into err-disabled state if a BPDU is received on the port.
BPDU Guard protects access ports by err-disabling them when any BPDU is received. This prevents unauthorized switches from being connected and potentially disrupting the spanning tree topology. It is commonly deployed alongside PortFast on access ports to ensure that end-user devices cannot participate in STP.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
It filters BPDUs from being forwarded out of the port while allowing the port to remain active.
Why it's wrong here
BPDU filtering prevents BPDUs from being transmitted out of a port, which is a different feature. BPDU Guard does not filter outbound BPDUs; instead, it monitors inbound BPDUs and disables the port upon detection, which is a more aggressive protective action.
- ✗
It converts the access port into a trunk port when BPDUs are detected to allow proper spanning tree convergence.
Why it's wrong here
BPDU Guard never converts an access port into a trunk port. Its purpose is to prevent unauthorized switches from connecting, so converting the port would defeat the security objective. Trunk negotiation is controlled by DTP, not by BPDU Guard.
- ✓
It places the port into err-disabled state if a BPDU is received on the port.
Why this is correct
BPDU Guard is designed to protect access ports from receiving BPDUs. When a BPDU is detected on a port with BPDU Guard enabled, the switch immediately places that port into err-disabled state, preventing the unauthorized device from participating in spanning tree and potentially causing loops or topology changes.
- ✗
It sends a syslog message and drops only the offending BPDU while keeping the port operational.
Why it's wrong here
BPDU Guard does not merely drop the BPDU and keep the port up. The entire port is placed into err-disabled state, which stops all traffic on that interface. This is more severe than just filtering individual BPDUs and is intentional to fully block the unauthorized device.
Visual reference
About these practice questions
One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.