Courseiva
mediumMultiple Choice

CCNP Practice Question: Examine the following configuration snippet:…

Examine the following configuration snippet:

interface GigabitEthernet1/0/1
 switchport mode access
 switchport access vlan 100
 spanning-tree portfast
 spanning-tree bpduguard enable

What is the effect of this configuration?

⚠ Common exam trap

Cisco often tests the distinction between PortFast (which speeds up convergence) and BPDU Guard (which protects against loops) — the trap here is assuming PortFast alone prevents BPDU issues, when in fact BPDU Guard is required to error-disable the port upon BPDU reception.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The port will immediately transition to forwarding state and will be error-disabled if a BPDU is received.

The configuration enables PortFast and BPDU Guard on an access port. PortFast immediately transitions the port to forwarding state, bypassing the usual STP listening and learning phases. BPDU Guard monitors for incoming BPDUs; if any are received, it error-disables the port to prevent a potential bridging loop from an unauthorized switch connection.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The port will immediately transition to forwarding state and will be error-disabled if a BPDU is received.

    Why this is correct

    With PortFast configured on an access port, the switch port bypasses the normal Spanning Tree Protocol (STP) listening and learning states and transitions directly to forwarding, allowing endpoints such as PCs or IP phones to come up immediately. When BPDU Guard is also enabled (as is typical for access ports), the arrival of any Bridge Protocol Data Unit—which would indicate another switch has been connected—triggers an immediate error-disable of the port, preventing potential Layer 2 loops. This behavior is deterministic: forwarding first, then shutdown on any unexpected BPDU.

  • ✗

    The port will remain in blocking state until a BPDU is received from the root bridge.

    Why it's wrong here

    This is incorrect because PortFast fundamentally overrides the STP state machine that would normally hold a port in the blocking state while it waits to determine the root bridge and listen for BPDUs. On a PortFast-enabled port, STP convergence is skipped entirely, so the port never enters blocking or listening; it moves straight to forwarding within milliseconds. Furthermore, if a BPDU from a root bridge or any switch were actually received, BPDU Guard would not keep the port in blocking—it would error-disable the port immediately, which is a different outcome than remaining in a stable STP state.

  • ✗

    The port will only forward BPDUs and will not forward data traffic.

    Why it's wrong here

    This is wrong because a PortFast access port is designed to forward data traffic immediately, not merely to process spanning-tree BPDUs. In normal STP operation, a designated port in the forwarding state both sends and receives BPDUs while also forwarding user data frames; PortFast does not change this—it simply accelerates the transition to forwarding. If a BPDU arrives, BPDU Guard does not respond by just letting the port forward BPDUs; it shuts the port down entirely, placing it in the error-disabled state, so the port stops forwarding both data and BPDUs.

  • ✗

    The port will participate in RSTP and will not be affected by BPDU reception.

    Why it's wrong here

    This option misrepresents how PortFast and BPDU Guard interact with RSTP or any STP variant. PortFast is an administrative override that puts the port into forwarding state immediately, regardless of whether the switch is running classic 802.1D, PVST+, or Rapid PVST+ (RSTP); it does not make the port a passive participant. BPDU Guard is equally agnostic to the STP variant—if any BPDU is received on a BPDU Guard-protected port, the port is error-disabled, not left unaffected. Therefore, the premise that RSTP participation somehow exempts the port from BPDU reactions is false.

Visual reference

SW1 Root Bridge SW2 SW3 BLK DP DP RP RP STP blocks one link to prevent loops DP = Designated Port RP = Root Port BLK = Blocked

About these practice questions

This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.