Courseiva

CCNA Spanning Tree Questions

40 questions · Spanning Tree topic · All types, answers revealed

1
MCQeasy

A network engineer runs the following command on Switch SW5: SW5# show spanning-tree vlan 50 VLAN0050 Spanning tree enabled protocol ieee Root ID Priority 24626 Address aabb.cc00.0800 Cost 4 Port 1 (GigabitEthernet0/1) Hello Time 2 sec Max Age 20 sec Forward Delay 15 sec Bridge ID Priority 32768 (priority 32768 sys-id-ext 50) Address aabb.cc00.0900 Hello Time 2 sec Max Age 20 sec Forward Delay 15 sec Aging Time 300 sec Interface Role Sts Cost Prio.Nbr Type ------------------- ---- --- --------- -------- ------------------------------ Gi0/1 Root FWD 4 128.1 P2p Gi0/2 Desg FWD 4 128.2 P2p Gi0/3 Desg FWD 4 128.3 P2p Gi0/4 Altn BLK 4 128.4 P2p Based on this output, how many ports are in the Forwarding state?

A.1
B.2
C.3
D.4
AnswerC

Option 3 is correct. The `show spanning-tree` output for this VLAN/instance lists Gi0/1, Gi0/2, and Gi0/3 in the Forwarding (FWD) state, meaning these three ports are actively forwarding Ethernet frames. Gi0/4 is shown in the Blocking (BLK) state, so it is not forwarding user traffic. Therefore, exactly three ports are in the forwarding state, making answer 3 the correct choice.

Why this answer

The output shows four interfaces: Gi0/1 (Root FWD), Gi0/2 (Desg FWD), Gi0/3 (Desg FWD), and Gi0/4 (Altn BLK). Three ports (Gi0/1, Gi0/2, Gi0/3) are in the Forwarding state, while Gi0/4 is in the Blocking state. Therefore, the correct answer is 3.

Exam trap

Cisco often tests the ability to distinguish between port roles and port states; candidates may confuse the number of ports in a role (e.g., Root, Designated) with the number in the Forwarding state, or mistakenly count the Alternate port as forwarding because it has a role, ignoring its BLK state.

How to eliminate wrong answers

Option A is wrong because only 1 port in Forwarding would ignore the two Designated ports (Gi0/2 and Gi0/3) that are clearly marked FWD. Option B is wrong because 2 ports in Forwarding would miss either the Root port or one of the Designated ports, but all three are actively forwarding. Option D is wrong because 4 ports in Forwarding would include the Alternate port Gi0/4, which is in the Blocking (BLK) state, not Forwarding.

2
MCQmedium

Examine the following configuration snippet on a Cisco IOS switch: interface GigabitEthernet0/2 switchport mode access switchport access vlan 50 spanning-tree portfast Which statement is true about this interface?

A.The interface will immediately forward traffic without any spanning-tree delay.
B.The interface will participate in trunking and forward multiple VLANs.
C.The interface will still go through listening and learning states before forwarding.
D.The interface will only forward traffic for VLAN 1.
AnswerA

PortFast is configured on this access port, so the switch immediately moves the interface to the STP forwarding state, bypassing the 15-second listening and 15-second learning states. It still runs Spanning Tree Protocol and can send BPDUs, but it does not wait for the normal 30-second convergence delay before forwarding user traffic. This is intended for end hosts that should not cause a layer-2 loop.

Why this answer

The `spanning-tree portfast` command on an access port configured with `switchport mode access` and `switchport access vlan 50` causes the interface to bypass the normal spanning-tree listening and learning states. This allows the port to transition directly to the forwarding state, enabling immediate traffic forwarding without the usual 30-second delay (15 seconds for listening, 15 seconds for learning) associated with Rapid Spanning Tree Protocol (RSTP) or the 50-second delay with classic STP (802.1D).

Exam trap

Cisco often tests the misconception that `spanning-tree portfast` only applies to trunk ports or that it still requires the listening/learning states, when in fact it is designed specifically to bypass those states on access ports (or trunk ports with the `spanning-tree portfast trunk` variant).

How to eliminate wrong answers

Option B is wrong because the interface is configured as an access port (`switchport mode access`), which does not participate in trunking and only forwards traffic for a single VLAN (VLAN 50), not multiple VLANs. Option C is wrong because `spanning-tree portfast` specifically causes the interface to skip the listening and learning states and immediately enter the forwarding state, contradicting the claim that it will still go through those states. Option D is wrong because the `switchport access vlan 50` command assigns the interface to VLAN 50, not VLAN 1; the default VLAN for access ports is VLAN 1 only if no explicit access VLAN is configured.

3
MCQmedium

A network engineer is troubleshooting an STP issue in a switched network. The network has two distribution switches connected via a trunk, and each distribution switch connects to the same access switch. The engineer notices that the root bridge is not the intended distribution switch. Upon checking, the engineer sees that the access switch has a higher priority than the distribution switches. The engineer needs to ensure that the intended distribution switch becomes the root bridge without causing a temporary loop. What should the engineer do?

A.Configure the 'spanning-tree vlan vlan-id root primary' command on the intended distribution switch.
B.Set the priority of the access switch to 0 using the 'spanning-tree vlan vlan-id priority 0' command.
C.Increase the priority of the distribution switch to 61440 using the 'spanning-tree vlan vlan-id priority 61440' command.
D.Disable STP on the distribution switch and manually configure it as the root bridge.
AnswerA

The `spanning-tree vlan vlan-id root primary` command is a Cisco macro that forces the switch to become the root bridge by automatically setting its bridge priority to 24576, or to 4096 less than the current lowest priority if another switch already has a priority below 24576. This adjusts the priority dynamically without manual calculation, ensuring the intended distribution switch wins the root election. The command also configures the switch to be the primary root for that VLAN, which is exactly the desired outcome.

Why this answer

The 'spanning-tree vlan vlan-id root primary' command dynamically sets the switch's bridge priority to 24576 (or 4096 if the current root has a priority lower than 24576) and ensures the switch becomes the root bridge without manual priority miscalculation. This command also adjusts the priority of neighboring switches if needed, preventing temporary loops by avoiding the need to disable or reset STP. It is the safest and most efficient method to force a specific switch to become the root bridge in a live network.

Exam trap

Cisco often tests the misconception that increasing a switch's priority (making it numerically higher) helps it become root, when in fact the root bridge is elected based on the lowest bridge priority value.

How to eliminate wrong answers

Option B is wrong because setting the access switch's priority to 0 would make it the root bridge, which is the opposite of the intended goal (the distribution switch should be root). Option C is wrong because increasing the distribution switch's priority to 61440 (a high value) would make it less likely to become the root bridge, not more; the root bridge is elected with the lowest priority value. Option D is wrong because disabling STP on the distribution switch would break loop prevention entirely, potentially causing a Layer 2 loop and network outage, and manually configuring it as root without STP is not a valid or safe method.

4
Multi-Selecthard

Which three statements about the Multiple Spanning Tree Protocol (MSTP) are true? (Choose three.)

Select 3 answers
A.MSTP allows multiple VLANs to be mapped to a single spanning-tree instance.
B.MSTP uses an Internal Spanning Tree (IST) to interconnect MST regions.
C.MSTP is backward compatible with 802.1D and RSTP.
D.MSTP requires a separate spanning-tree instance for every VLAN.
E.MSTP uses a different BPDU format than RSTP.
AnswersA, B, C

MSTP maps many VLANs onto a single spanning-tree instance, so a handful of instances can serve hundreds of VLANs. This is the protocol's core efficiency gain over per-VLAN spanning tree, reducing bridge processing and control-plane load.

Why this answer

Option A is correct because MSTP (IEEE 802.1s) lets you group many VLANs into a single Multiple Spanning Tree Instance (MSTI), so one topology serves all VLANs mapped to it, greatly reducing the number of spanning-tree instances compared with PVST+. Option B is correct because MSTP builds an Internal Spanning Tree (IST) as instance 0, which carries the Common and Internal Spanning Tree (CIST) information and connects MST regions to each other and to other STP domains. Option C is correct because MSTP is designed to interoperate with 802.1D (classic STP) and 802.1w (RSTP) devices, treating them as part of the CIST so legacy switches can participate in the topology.

Option D is wrong because requiring one instance per VLAN describes PVST+/RPVST+, whereas MSTP's whole purpose is to map multiple VLANs to a single instance. Option E is wrong because MSTP uses the same RSTP-style BPDU format (with MSTP-specific extensions in the MSTI configuration messages), not a fundamentally different BPDU format.

Exam trap

350-401 often tests the misconception that MSTP requires one instance per VLAN (that's PVST+) or that it uses a unique BPDU format, when it actually reuses RSTP BPDUs with MSTP extensions.

5
MCQmedium

interface GigabitEthernet0/2 spanning-tree link-type point-to-point end What is the effect of this configuration?

A.The port will use RSTP fast transition mechanisms assuming a point-to-point link.
B.The port will become a designated port immediately.
C.The port will disable STP on that link.
D.The port will use shared medium behavior.
AnswerA

Setting the link type to point-to-point marks the switchport as a direct, full-duplex connection between exactly two switches, which lets Rapid Spanning Tree (RSTP/Rapid PVST+) invoke its proposal/agreement mechanism. Once the root port sends a proposal and receives agreement from the downstream designated port, the port can enter the forwarding state immediately instead of waiting through the default 15-second listening and 15-second learning timers. This fast transition is the key benefit of RSTP over classic 802.1D STP and is only used when the link is treated as point-to-point.

Why this answer

The `spanning-tree link-type point-to-point` command manually overrides the port's link type to point-to-point, forcing the port to use Rapid Spanning Tree Protocol (RSTP) fast transition mechanisms (proposal/agreement handshake) instead of the slower 802.1D listening/learning states. This is correct because RSTP relies on the link type to determine whether it can safely perform a fast transition to the forwarding state; a point-to-point link allows immediate transition without waiting for timers.

Exam trap

The trap here is that candidates often confuse the `spanning-tree link-type point-to-point` command with disabling STP or forcing a designated port, when in reality it only influences the RSTP fast transition behavior based on the perceived link type.

How to eliminate wrong answers

Option B is wrong because the command does not directly force a port to become a designated port; the RSTP proposal/agreement process determines the port role (root, designated, alternate, backup) based on bridge ID and path cost, not the link-type setting. Option C is wrong because the command does not disable STP; STP remains active and the port still participates in spanning tree calculations, just with faster convergence. Option D is wrong because the command explicitly sets the link type to point-to-point, which is the opposite of shared medium behavior; shared medium behavior would be used with a hub or half-duplex link, and this command forces point-to-point even if the physical medium is shared.

6
MCQhard

An engineer is designing a Layer 2 network with redundancy. The network uses MST (Multiple Spanning Tree) to reduce the number of STP instances. The engineer has configured two regions: Region 1 and Region 2. The engineer notices that switches in Region 1 are not forming a single MST region, and instead, they are treating each other as if they are in different regions. The engineer checks the configuration and finds that the region name and revision number are the same on all switches in Region 1, but the VLAN-to-instance mapping is different on one switch. What is the most likely cause of the issue?

A.The VLAN-to-instance mapping is not consistent across all switches in Region 1.
B.The root bridge for each MST instance is not configured correctly.
C.BPDU Guard is enabled on the inter-switch links, preventing BPDU exchange.
D.PortFast is enabled on the inter-switch links, causing the switches to ignore BPDUs.
AnswerA

The IEEE 802.1s MST region is identified by a computed configuration digest, which is derived from the VLAN-to-instance mapping, the region name, and the revision number. If one switch in Region 1 uses a different mapping (for example, VLAN 10 assigned to instance 2 instead of instance 1), its digest differs even if the name and revision match. Switches with different digests cannot distinguish internal MST BPDUs from external ones, so they treat each other as separate regions, causing an incorrect top-level tree and per-instance topology. This is exactly the failure symptom described in the scenario.

Why this answer

In MST, all switches within a region must agree on three parameters: the region name, the revision number, and the VLAN-to-instance mapping. Even if the region name and revision number match, a single mismatch in the VLAN-to-instance mapping causes the switches to treat each other as if they belong to different regions, preventing them from forming a single MST region.

Exam trap

Cisco often tests the fact that all three components of the MST configuration (name, revision, and VLAN-to-instance mapping) must match exactly for switches to be in the same region, and candidates mistakenly think only the name and revision matter.

How to eliminate wrong answers

Option B is wrong because the root bridge configuration for each MST instance affects the spanning-tree topology within the region but does not determine whether switches belong to the same region; region membership is based solely on the MST configuration identifier (name, revision, mapping). Option C is wrong because BPDU Guard is a port security feature that shuts down a port upon receiving a BPDU, but it does not prevent BPDU exchange before the port is err-disabled; moreover, the issue described is about region formation, not BPDU filtering. Option D is wrong because PortFast immediately transitions a port to the forwarding state but does not cause switches to ignore BPDUs; BPDUs are still processed, and PortFast does not affect MST region formation.

7
MCQmedium

Consider the following configuration on a Cisco IOS-XE switch: interface GigabitEthernet1/0/1 switchport mode access authentication port-control auto dot1x pae authenticator dot1x timeout tx-period 5 spanning-tree portfast What is the effect of this configuration?

A.The port will immediately transition to forwarding state and then wait for authentication.
B.The switch will act as an 802.1X authenticator and the port will be unauthorized until a successful authentication.
C.The port will be placed in a VLAN assigned by the RADIUS server after authentication.
D.The switch will act as a supplicant and respond to EAP requests from an upstream authenticator.
AnswerB

The 'dot1x pae authenticator' command configures the switch port to operate as the 802.1X authenticator, meaning it initiates and manages EAP exchanges with the connected client (supplicant). The 'authentication port-control auto' setting explicitly places the port in the unauthorized state initially, allowing only EAPOL traffic to flow. Only after the client successfully authenticates against the configured authentication method (e.g., RADIUS) does the controlled port transition to the authorized state and forward normal data traffic.

Why this answer

The configuration enables 802.1X authentication on the port with `authentication port-control auto`, making the port start in the unauthorized state. The `dot1x pae authenticator` command configures the switch as the authenticator (not a supplicant). The `spanning-tree portfast` command allows the port to transition to forwarding quickly after authentication succeeds, but until then, the port remains unauthorized and blocks traffic.

Option B correctly states that the switch acts as an authenticator and the port is unauthorized until successful authentication.

Exam trap

Cisco often tests the distinction between authenticator and supplicant roles, and the trap here is that candidates confuse `dot1x pae authenticator` with a supplicant configuration or assume that `spanning-tree portfast` overrides the unauthorized state, leading them to pick Option A or D.

How to eliminate wrong answers

Option A is wrong because the port does not immediately transition to forwarding; it remains in the unauthorized state until 802.1X authentication completes, and `spanning-tree portfast` only speeds up the transition after authentication succeeds. Option C is wrong because the configuration does not include any RADIUS-assigned VLAN commands (such as `authentication fallback` or `vlan assignment`), and the port is configured as a static access port without dynamic VLAN assignment. Option D is wrong because the `dot1x pae authenticator` command explicitly sets the switch to act as an authenticator, not a supplicant; a supplicant role would require `dot1x pae supplicant` or similar.

8
MCQmedium

Examine the following configuration: interface Port-channel1 switchport mode trunk ! interface GigabitEthernet0/1 switchport mode trunk channel-group 1 mode active spanning-tree portfast ! interface GigabitEthernet0/2 switchport mode trunk channel-group 1 mode active spanning-tree portfast What is the effect of the 'spanning-tree portfast' command on the member interfaces of this EtherChannel?

A.The PortFast will be applied to the EtherChannel, causing it to immediately transition to forwarding.
B.The PortFast on the member interfaces will be ignored because they are part of an EtherChannel.
C.The PortFast will cause the EtherChannel to form faster.
D.The configuration will cause a spanning-tree loop because PortFast is used on trunk ports.
AnswerB

When interfaces are grouped into an EtherChannel, the software creates a single logical port-channel interface that represents the entire bundle. STP treats this logical port-channel as the spanning-tree port, and per-interface STP parameters on the physical member links are effectively overridden and ignored. The member interfaces are not independent STP ports; they are just physical paths within the aggregated link. Therefore, PortFast configured on the members has no effect on the STP state of the EtherChannel, making this statement correct.

Why this answer

When interfaces are configured as members of an EtherChannel, any spanning-tree configuration applied directly to the member interfaces (such as 'spanning-tree portfast') is ignored. Spanning-tree operates on the logical port-channel interface, not the individual physical members. Therefore, the PortFast command on GigabitEthernet0/1 and GigabitEthernet0/2 has no effect; instead, PortFast must be configured on the Port-channel interface itself to apply to the bundle.

Exam trap

Cisco often tests the misconception that STP features configured on physical interfaces are inherited by the EtherChannel, when in fact they are ignored and must be applied to the logical port-channel interface.

How to eliminate wrong answers

Option A is wrong because PortFast is not applied to the EtherChannel from the member interfaces; it is ignored, so the EtherChannel does not immediately transition to forwarding. Option C is wrong because PortFast on member interfaces does not cause the EtherChannel to form faster; EtherChannel formation depends on LACP or PAgP negotiation, not PortFast. Option D is wrong because using PortFast on trunk ports does not inherently cause a spanning-tree loop; loops are prevented by spanning-tree itself, and PortFast simply bypasses the listening/learning states on access or trunk ports (with caution), but here it is ignored entirely.

9
MCQmedium

A network engineer runs the following command on Switch SW5: SW5# show running-config | section interface port-channel interface Port-channel1 switchport mode trunk switchport trunk allowed vlan 1-100,200-300 ! interface Port-channel2 switchport mode access switchport access vlan 10 ! SW5# show interfaces trunk Port Mode Encapsulation Status Native vlan Po1 on 802.1q trunking 1 Port Vlans allowed on trunk Po1 1-100,200-300 Port Vlans allowed and active in management domain Po1 1-100,200-300 Port Vlans in spanning tree forwarding state and not pruned Po1 1-100,200-300 Based on this output, what can be concluded?

A.Port-channel2 is also trunking but not displayed due to a software bug.
B.Port-channel1 is trunking and allowed VLANs include VLANs 101-199.
C.Port-channel1 is operational as a trunk with the configured allowed VLANs.
D.The native VLAN on Po1 is VLAN 10.
AnswerC

The output confirms Port-channel1 is in trunking mode, is operationally up, and its allowed VLAN list matches the configured VLANs of 1-100 and 200-300. The 'show interfaces trunk' command verifies that the port-channel is carrying traffic for the exact set of VLANs that were configured, with no unexpected additions or removals. This matches the correct operational state expected for a properly configured EtherChannel trunk.

Why this answer

The 'show interfaces trunk' output confirms that Port-channel1 is trunking with an operational status of 'trunking', and the 'Vlans allowed on trunk' line matches the configured allowed VLANs (1-100,200-300). This indicates the trunk is up and functioning with the intended VLAN list, making option C correct.

Exam trap

Cisco often tests the distinction between trunk and access port behavior, and the trap here is assuming that a port-channel with an access configuration will still appear in trunk output or that the native VLAN can be inferred from the access VLAN configuration.

How to eliminate wrong answers

Option A is wrong because Port-channel2 is configured as an access port (switchport mode access), so it will not appear in the 'show interfaces trunk' output, which only displays trunk ports; there is no software bug. Option B is wrong because the allowed VLANs explicitly exclude VLANs 101-199, as shown in the configuration and trunk output (only 1-100 and 200-300 are allowed). Option D is wrong because the native VLAN on Po1 is VLAN 1, as indicated by the 'Native vlan' column in the trunk output, not VLAN 10.

10
MCQhard

A network engineer runs the following command on Switch SW1: SW1# show interfaces trunk Port Mode Encapsulation Status Native vlan Gi0/1 on 802.1q trunking 1 Gi0/2 on 802.1q trunking 1 Port Vlans allowed on trunk Gi0/1 1-1005 Gi0/2 1-1005 Port Vlans allowed and active in management domain Gi0/1 1,10,20 Gi0/2 1,10,20 Port Vlans in spanning tree forwarding state and not pruned Gi0/1 1,10,20 Gi0/2 1,10,20 Based on this output, what can be concluded?

A.VLANs 2-9 are allowed but not active on the trunk.
B.The trunk is using ISL encapsulation.
C.VLAN 1 is pruned from the trunk.
D.Only VLANs 10 and 20 are forwarding traffic.
AnswerA

The allowed list spans 1-1005, but the active management domain shows only 1, 10 and 20, proving VLANs 2-9 exist in the allowed range yet carry no active ports. Spanning-tree forwarding state confirms the same set, so those VLANs are permitted but dormant.

Why this answer

The output shows that VLANs 1-1005 are allowed on the trunk, but only VLANs 1, 10, and 20 are listed as active in the management domain. This means VLANs 2-9 are configured on the trunk but are not active (i.e., not created or not present on the switch), so they do not forward traffic. Option A correctly identifies this condition.

Exam trap

Cisco often tests the difference between 'allowed on trunk' and 'active in management domain' to trick candidates into thinking all allowed VLANs are forwarding, when in fact only active VLANs forward traffic.

How to eliminate wrong answers

Option B is wrong because the encapsulation is explicitly shown as '802.1q', not ISL, which is a Cisco proprietary protocol that is now largely deprecated. Option C is wrong because VLAN 1 is listed in the 'Vlans in spanning tree forwarding state and not pruned' section, indicating it is forwarding and not pruned; pruning would remove it from that list. Option D is wrong because VLAN 1 is also in the forwarding state and not pruned, so traffic for VLAN 1 is also being forwarded, not just VLANs 10 and 20.

11
MCQmedium

A network engineer is troubleshooting a Layer 2 loop that occurred in a network using Rapid PVST+. The network has three switches: SW1 (root), SW2, and SW3. The engineer examines the topology and finds that SW2 and SW3 are connected via a link that is not supposed to be there. The engineer suspects that an unauthorized switch was connected to the network, causing the loop. The engineer wants to prevent such loops in the future by configuring a feature that will disable any port that receives a BPDU from an unauthorized switch. Which feature should the engineer configure on the access ports?

A.Enable BPDU Guard on all access ports.
B.Enable Loop Guard on all access ports.
C.Enable Root Guard on all access ports.
D.Enable UDLD on all access ports.
AnswerA

BPDU Guard is the correct choice because it actively shuts down the port by placing it into an errdisable state whenever any BPDU is received on an access port. Since access ports should never receive BPDUs from an end host, a received BPDU indicates an unauthorized switch attempting to participate in spanning tree, and BPDU Guard immediately blocks that port to preserve the intended STP topology and prevent potential loops.

Why this answer

BPDU Guard is the correct feature because it immediately error-disables a port when a BPDU is received, preventing loops from unauthorized switches. Since the engineer wants to protect access ports from receiving BPDUs (which should never occur on a properly configured access port), BPDU Guard directly addresses the scenario of an unauthorized switch being connected and sending BPDUs.

Exam trap

Cisco often tests the distinction between BPDU Guard and Root Guard, where candidates mistakenly choose Root Guard because they think it protects against unauthorized switches, but Root Guard only prevents a port from becoming root, not from receiving BPDUs and causing loops.

How to eliminate wrong answers

Option B is wrong because Loop Guard prevents alternate or root ports from becoming designated in the absence of BPDUs, but it does not disable a port upon receiving an unexpected BPDU; it only prevents loops caused by unidirectional link failures. Option C is wrong because Root Guard prevents a port from becoming a root port by placing it into a root-inconsistent state if a superior BPDU is received, but it does not disable the port; it still allows BPDU reception and does not block all BPDUs from unauthorized switches. Option D is wrong because UDLD detects and disables ports experiencing unidirectional links, but it does not react to BPDU reception; it uses its own keepalive mechanism and is unrelated to preventing loops from unauthorized switches sending BPDUs.

12
MCQeasy

A network administrator at a small company wants to prevent users from plugging unauthorized switches into wall jacks and creating loops or bypassing security controls. The administrator decides to implement BPDU Guard on all access ports on a Cisco Catalyst switch. Which statement accurately describes the behavior of BPDU Guard when configured on an access port?

A.It filters BPDUs from being forwarded out of the port while allowing the port to remain active.
B.It converts the access port into a trunk port when BPDUs are detected to allow proper spanning tree convergence.
C.It places the port into err-disabled state if a BPDU is received on the port.
D.It sends a syslog message and drops only the offending BPDU while keeping the port operational.
AnswerC

BPDU Guard is designed to protect access ports from receiving BPDUs. When a BPDU is detected on a port with BPDU Guard enabled, the switch immediately places that port into err-disabled state, preventing the unauthorized device from participating in spanning tree and potentially causing loops or topology changes.

Why this answer

BPDU Guard protects access ports by err-disabling them when any BPDU is received. This prevents unauthorized switches from being connected and potentially disrupting the spanning tree topology. It is commonly deployed alongside PortFast on access ports to ensure that end-user devices cannot participate in STP.

Exam trap

The trap here is confusing BPDU Guard with BPDU Filter, where BPDU Filter suppresses BPDUs while BPDU Guard disables the port upon receiving one.

13
MCQeasy

A network engineer is configuring a new switch that will be used as an access layer switch. The switch connects to two distribution switches via trunk links. The engineer wants to ensure that the access switch does not become the root bridge for any VLAN. The engineer also wants to provide redundancy so that if one uplink fails, the other uplink takes over quickly. The engineer is using Rapid PVST+. What configuration should the engineer apply on the access switch?

A.Configure 'spanning-tree vlan vlan-list priority 61440' on the access switch.
B.Configure 'spanning-tree vlan vlan-list priority 0' on the access switch.
C.Enable UplinkFast on the access switch to provide fast failover.
D.Enable PortFast on the trunk ports to speed up convergence.
AnswerA

Setting the switch's spanning-tree priority to 61440 (the highest numerical value) ensures its bridge ID will never be preferred over a legitimate root, because the root election down-selects the lowest bridge priority. Since Rapid PVST+ (802.1w) is already active, link failures are recovered through explicit proposal/agreement handshakes, eliminating the need for any extra convergence mechanism. This is the recommended way to pin the root on a distribution switch while making access switches incapable of becoming root even after a topology change.

Why this answer

Setting the spanning-tree priority to 61440 (which is 0xF000 in hex) makes the switch a very unlikely root bridge candidate. In Rapid PVST+, the bridge priority is a 4-bit value (0-15) multiplied by 4096, so 61440 corresponds to priority 15 — the highest possible value. This ensures the access switch will never become the root bridge for any VLAN, while Rapid PVST+ provides fast failover (sub-second convergence) via its alternate/backup port mechanism without needing UplinkFast.

Exam trap

Cisco often tests the misconception that UplinkFast is needed with Rapid PVST+ for fast failover, but Rapid PVST+ already includes its own fast convergence (based on the 802.1w standard), making UplinkFast obsolete.

How to eliminate wrong answers

Option B is wrong because setting priority 0 makes the switch the most likely root bridge candidate, which directly contradicts the requirement to never become root. Option C is wrong because UplinkFast is a legacy Cisco proprietary feature for 802.1D STP; Rapid PVST+ already provides fast failover (typically 1-2 seconds) via its own convergence mechanism, making UplinkFast unnecessary and redundant. Option D is wrong because PortFast is designed for access ports connected to end hosts to bypass listening/learning states; applying it to trunk ports would disable STP on those links, risking loops and violating the requirement for redundancy with STP protection.

14
MCQmedium

interface GigabitEthernet0/3 spanning-tree guard root end What is the effect of this configuration?

A.The port will error-disable if it receives a BPDU that would cause the switch to become a non-root bridge.
B.The port will block all BPDUs received from other switches.
C.The port will become the root port for the VLAN.
D.The port will ignore BPDUs from switches with lower bridge ID.
AnswerA

Root Guard is a protection mechanism enabled on designated ports of a switch that should remain the root bridge. If such a port receives a BPDU from another switch that advertises a lower bridge ID or better root path cost, that BPDU is 'superior' and would normally cause the local switch to surrender root status. Rather than accept it, Root Guard places the port into a root-inconsistent (blocking) state — often referred to as error-disabling the port — so the intended root remains authoritative. The port does not pass traffic until the invalid BPDUs stop and the STP topology stabilizes.

Why this answer

The `spanning-tree guard root` command enables Root Guard on the interface. Root Guard prevents the port from becoming a root port by error-disabling the port if it receives a superior BPDU (one that would cause the switch to become a non-root bridge). This protects the spanning-tree root bridge placement from being usurped by an unauthorized switch.

Exam trap

Cisco often tests the distinction between Root Guard and BPDU Guard: candidates confuse Root Guard (which error-disables upon receiving a superior BPDU) with BPDU Guard (which error-disables upon receiving any BPDU on a PortFast port), or mistakenly think Root Guard blocks or ignores BPDUs entirely.

How to eliminate wrong answers

Option B is wrong because Root Guard does not block all BPDUs; it only monitors for superior BPDUs and error-disables the port if one is received, while normal BPDU processing continues otherwise. Option C is wrong because Root Guard prevents the port from becoming a root port; it does not force the port to become the root port. Option D is wrong because Root Guard does not ignore BPDUs from switches with lower bridge ID; instead, it reacts to superior BPDUs (which typically come from switches with a lower bridge ID) by error-disabling the port.

15
MCQmedium

Examine the following configuration snippet: interface GigabitEthernet1/0/1 switchport mode access switchport access vlan 100 spanning-tree portfast spanning-tree bpduguard enable What is the effect of this configuration?

A.The port will immediately transition to forwarding state and will be error-disabled if a BPDU is received.
B.The port will remain in blocking state until a BPDU is received from the root bridge.
C.The port will only forward BPDUs and will not forward data traffic.
D.The port will participate in RSTP and will not be affected by BPDU reception.
AnswerA

With PortFast configured on an access port, the switch port bypasses the normal Spanning Tree Protocol (STP) listening and learning states and transitions directly to forwarding, allowing endpoints such as PCs or IP phones to come up immediately. When BPDU Guard is also enabled (as is typical for access ports), the arrival of any Bridge Protocol Data Unit—which would indicate another switch has been connected—triggers an immediate error-disable of the port, preventing potential Layer 2 loops. This behavior is deterministic: forwarding first, then shutdown on any unexpected BPDU.

Why this answer

The configuration enables PortFast and BPDU Guard on an access port. PortFast immediately transitions the port to forwarding state, bypassing the usual STP listening and learning phases. BPDU Guard monitors for incoming BPDUs; if any are received, it error-disables the port to prevent a potential bridging loop from an unauthorized switch connection.

Exam trap

Cisco often tests the distinction between PortFast (which speeds up convergence) and BPDU Guard (which protects against loops) — the trap here is assuming PortFast alone prevents BPDU issues, when in fact BPDU Guard is required to error-disable the port upon BPDU reception.

How to eliminate wrong answers

Option B is wrong because PortFast forces the port into forwarding state immediately, not blocking; BPDU Guard does not alter this behavior. Option C is wrong because the port forwards normal data traffic as an access port in VLAN 100, not just BPDUs. Option D is wrong because BPDU Guard explicitly reacts to BPDU reception by error-disabling the port, so the port is affected by BPDUs; RSTP is not relevant here as PortFast overrides the STP state machine.

16
MCQmedium

spanning-tree vlan 10 priority 4096 What is the effect of this global configuration command?

A.The switch will have a bridge priority of 4096 for VLAN 10, increasing its chance to become root bridge.
B.The switch will have a bridge priority of 4096 for all VLANs.
C.The switch will become the root bridge for VLAN 10 immediately.
D.The switch will have a bridge priority of 4096 for VLAN 10 and all other VLANs will use 32768.
AnswerA

The command 'spanning tree vlan 10 priority 4096' sets the bridge priority for the VLAN 10 spanning tree instance to 4096, lowering it from the default 32768. Because STP elects the root bridge using the lowest bridge ID (priority + MAC address), this significantly increases the switch's chances of winning the election for that VLAN. However, it does not guarantee the switch becomes root—any switch with a lower priority value or an equal priority but lower MAC address will still be preferred.

Why this answer

The command `spanning-tree vlan 10 priority 4096` sets the bridge priority for VLAN 10 to 4096. A lower bridge priority value increases the likelihood that this switch will be elected as the root bridge for that VLAN, because the spanning-tree algorithm selects the switch with the lowest bridge priority as the root. However, it does not guarantee immediate root status, as other switches with an even lower priority could still win the election.

Exam trap

Cisco often tests the distinction between setting a priority that influences root election versus guaranteeing root status, leading candidates to mistakenly think the switch becomes root immediately.

How to eliminate wrong answers

Option B is wrong because the command specifies VLAN 10, so the priority change applies only to that VLAN, not to all VLANs. Option C is wrong because setting the priority to 4096 does not force the switch to become root immediately; it only increases its chance, and the root election still depends on comparing priorities with other switches. Option D is wrong because the command does not affect other VLANs; they retain their default priority of 32768, but the statement incorrectly implies that the switch explicitly sets other VLANs to 32768, which is not configured by this command.

17
MCQmedium

Given the following configuration snippet on a Cisco IOS-XE switch: interface GigabitEthernet1/0/1 switchport mode access switchport access vlan 10 spanning-tree portfast monitor session 1 source interface GigabitEthernet1/0/1 both monitor session 1 destination interface GigabitEthernet1/0/2 What is the effect of this configuration?

A.All traffic entering and leaving GigabitEthernet1/0/1 is copied to GigabitEthernet1/0/2.
B.Only traffic entering GigabitEthernet1/0/1 is copied to GigabitEthernet1/0/2.
C.Traffic on GigabitEthernet1/0/2 is replicated to GigabitEthernet1/0/1.
D.The configuration is invalid because the destination port must be in trunk mode.
AnswerA

The monitor session statement names GigabitEthernet1/0/1 as source with the 'both' keyword, so ingress and egress frames on that port are replicated to the destination port GigabitEthernet1/0/2. SPAN copies traffic; it does not alter forwarding on the access port.

Why this answer

The configuration uses a local SPAN session to copy traffic from a source interface (GigabitEthernet1/0/1) to a destination interface (GigabitEthernet1/0/2). The keyword 'both' specifies that both ingress and egress traffic on the source port are mirrored, so all traffic entering and leaving GigabitEthernet1/0/1 is sent to the destination port for monitoring.

Exam trap

The trap here is that candidates often confuse 'both' with 'rx' or 'tx' and assume only one direction is mirrored, or they mistakenly think the destination port must be in trunk mode to carry VLAN tags, but in local SPAN the destination port can be an access port and the mirrored frames are sent untagged by default.

How to eliminate wrong answers

Option B is wrong because it claims only ingress traffic is copied, but the 'both' keyword explicitly includes egress traffic as well. Option C is wrong because it reverses the direction of the SPAN session, stating traffic from the destination is replicated to the source, which is not how SPAN works; the source is always the monitored port. Option D is wrong because the destination port in a local SPAN session does not need to be in trunk mode; it can be an access port, and the configuration is valid as long as the destination port is not used for normal data forwarding.

18
MCQhard

A network engineer runs the following command on Switch SW1: SW1# show interfaces gi0/1 trunk Port Mode Encapsulation Status Native vlan Gi0/1 on 802.1q trunking 1 Port Vlans allowed on trunk Gi0/1 10,20 Port Vlans allowed and active in management domain Gi0/1 10,20 Port Vlans in spanning tree forwarding state and not pruned Gi0/1 10,20 Based on this output, what can be concluded?

A.VLAN 1 is allowed on this trunk.
B.The trunk is using DTP dynamic desirable mode.
C.Only VLANs 10 and 20 are allowed on this trunk.
D.The native VLAN is 10.
AnswerC

The output explicitly contains 'Vlans allowed on trunk: 10,20'. On Cisco Catalyst switches, this line is the definitive list of VLANs permitted to traverse the trunk link; all other VLANs, including VLAN 1, are pruned or dropped at ingress. Thus only VLANs 10 and 20 are eligible for trunking, making this statement correct.

Why this answer

The output shows that the 'Vlans allowed on trunk' list contains only VLANs 10 and 20. This means the trunk has been explicitly configured to permit only those VLANs, and all other VLANs (including VLAN 1) are pruned or blocked from traversing the trunk. Therefore, only VLANs 10 and 20 are allowed, making option C correct.

Exam trap

Cisco often tests the distinction between the native VLAN and the allowed VLAN list; candidates mistakenly assume that the native VLAN is always permitted on the trunk, but the allowed list explicitly controls which VLANs can pass traffic, and the native VLAN must be included in that list to be forwarded.

How to eliminate wrong answers

Option A is wrong because the 'Vlans allowed on trunk' line explicitly lists only VLANs 10 and 20; VLAN 1 is not included, so it is not allowed on this trunk. Option B is wrong because the 'Mode' field shows 'on', which indicates that trunking is statically configured (no DTP negotiation), not using DTP dynamic desirable mode. Option D is wrong because the 'Native vlan' field shows '1', not 10; the native VLAN is the VLAN used for untagged traffic on the trunk, and here it is VLAN 1.

19
MCQhard

An engineer is configuring a new access switch that connects to two distribution switches via trunk links. The distribution switches are configured with Rapid PVST+ and are both running as root bridges for different VLANs. The engineer wants to ensure that the access switch does not become the root bridge for any VLAN, even if the distribution switches fail. The engineer also wants to prevent any unauthorized switch from becoming root. What configuration should the engineer apply on the access switch?

A.Configure 'spanning-tree vlan 1-4094 priority 61440' and enable Root Guard on the uplink ports.
B.Configure 'spanning-tree vlan 1-4094 priority 0' and enable BPDU Guard on the uplink ports.
C.Configure 'spanning-tree vlan 1-4094 priority 4096' and enable Loop Guard on the uplink ports.
D.Configure 'spanning-tree vlan 1-4094 priority 61440' and enable BPDU Guard on the uplink ports.
AnswerA

Setting the bridge priority to 61440, the maximum valid value, makes this switch the least preferred candidate in the root bridge election, so it can never assume the root role. Enabling Root Guard on the uplink ports monitors incoming BPDUs and places any port receiving a superior BPDU into a root-inconsistent state, blocking that path and preserving the current root. Together, these actions ensure the switch stays as a non-root and remains resilient against an unauthorized switch attempting to claim root.

Why this answer

Setting the spanning-tree priority to 61440 (the highest possible value) ensures the access switch will never become the root bridge, even if the current root bridges fail. Enabling Root Guard on the uplink ports prevents any unauthorized switch from becoming root by placing the port into a root-inconsistent state if a superior BPDU is received, thus protecting the root bridge election.

Exam trap

Cisco often tests the distinction between Root Guard and BPDU Guard, where candidates mistakenly apply BPDU Guard (which shuts down ports receiving any BPDU) instead of Root Guard (which specifically protects the root bridge election) on trunk links.

How to eliminate wrong answers

Option B is wrong because setting the priority to 0 makes the access switch the most likely candidate to become root, which directly contradicts the requirement to prevent it from becoming root. Option C is wrong because priority 4096 is a low value that could allow the access switch to become root if the distribution switches fail, and Loop Guard prevents alternate/root port loops but does not protect against unauthorized root bridges. Option D is wrong because while the priority 61440 is correct, BPDU Guard is used to shut down ports that receive BPDUs (typically on access ports), not to prevent unauthorized root bridges on trunk links; Root Guard is the appropriate feature for this purpose.

20
MCQhard

A company has a network with multiple VLANs connected via a Layer 3 switch acting as the gateway for all VLANs. The network uses Rapid PVST+ for spanning tree. Recently, the network team added a new access switch to VLAN 100. After the switch was connected, users in VLAN 100 experienced intermittent connectivity, and the Layer 3 switch logs show 'SPANTREE-2-ROOTGUARD_BLOCK' messages for the port connected to the new switch. The new switch is intended to provide additional access ports for VLAN 100. The network team ensured that the new switch's configuration is correct for VLAN 100 access. What is the most likely cause of the issue, and what action should be taken to resolve it?

A.Change the port configuration on the new switch to access mode for VLAN 100.
B.Disable Root Guard on the Layer 3 switch port connected to the new switch.
C.Configure the new switch with a higher bridge priority (e.g., 28672) to prevent it from becoming the root bridge.
D.Remove the new switch from the network because it is causing a BPDU attack.
AnswerC

Configuring the new switch with a higher bridge priority (e.g., 28672) ensures that its BPDUs are inferior to those of the current root bridge, so Root Guard on the Layer 3 switch port will no longer block the port. Since bridge priority is the first criterion in root bridge election, setting a value like 28672 (higher than the current root's priority) makes the new switch a non-root candidate. This resolves the root guard blocking while keeping the new switch operational and preserving the intended spanning-tree topology.

Why this answer

The issue is that the new switch, intended as an access switch, has a lower bridge priority (or default priority of 32768) than the existing root bridge for VLAN 100. When connected, it becomes the new root bridge, causing topology changes and intermittent connectivity. Root Guard on the Layer 3 switch port detects this superior BPDU and blocks the port to protect the root bridge position.

Configuring the new switch with a higher bridge priority (e.g., 28672) ensures it cannot become the root bridge, resolving the Root Guard blocks.

Exam trap

Cisco often tests the misconception that Root Guard is the problem and should be disabled, when in fact the root cause is the new switch's bridge priority being too low, and the correct fix is to adjust the priority on the new switch.

How to eliminate wrong answers

Option A is wrong because the port is already configured as an access port for VLAN 100 (the team verified correct configuration), and changing it again would not address the root bridge election issue. Option B is wrong because disabling Root Guard would allow the new switch to become the root bridge, causing the same intermittent connectivity and potential instability; Root Guard is a protective feature, not the cause. Option D is wrong because the new switch is not causing a BPDU attack; it is simply sending superior BPDUs due to its default bridge priority, which is a normal behavior that Root Guard is designed to protect against.

21
MCQmedium

A company has a campus network with two distribution switches (DSW1 and DSW2) connected via a Layer 2 trunk. Each distribution switch connects to two access switches. Spanning Tree Protocol (STP) is running with default settings. Recently, a network administrator added a new access switch (ASW3) and connected it to both distribution switches. After the connection, network performance degraded significantly, and users in VLAN 10 reported intermittent connectivity. The administrator checked the logs and saw multiple TCN notifications. What is the most likely cause of the issue?

A.The new switch is causing a Layer 2 loop due to redundant links without proper STP configuration.
B.The new switch is not configured with the same VLANs as the distribution switches.
C.The new switch has a lower bridge priority than the current root bridge.
D.The new switch has become the root bridge and is sending inferior BPDUs.
AnswerA

A Layer 2 loop occurs when redundant paths exist without Spanning Tree Protocol actively blocking one of them. The new switch, if connected with multiple links to the distribution switches and STP disabled or misconfigured, will forward broadcast frames out all ports, causing a broadcast storm. This leads to severe symptoms such as high CPU utilization on all switches, MAC address table flapping, and complete network unavailability.

Why this answer

When ASW3 is connected to both DSW1 and DSW2 via Layer 2 trunk links, it creates a physical loop in the network. With default STP settings, the new switch will participate in the spanning tree algorithm, but the sudden addition of redundant links can cause a temporary loop or instability until STP converges. The multiple TCN (Topology Change Notification) messages indicate that the spanning tree topology is flapping, leading to MAC address table flushes and intermittent connectivity for VLAN 10 users.

This is the classic symptom of a Layer 2 loop caused by redundant links without proper STP configuration or before convergence completes.

Exam trap

Cisco often tests the distinction between a Layer 2 loop causing TCN flapping and a root bridge election, where candidates mistakenly think a new root bridge is the primary problem rather than the redundant physical loop itself.

How to eliminate wrong answers

Option B is wrong because mismatched VLANs would cause traffic to be dropped or not forwarded, but would not generate TCN notifications or cause a Layer 2 loop; TCNs are triggered by changes in the spanning tree topology, not by VLAN mismatches. Option C is wrong because a lower bridge priority would make the new switch more likely to become the root bridge, but that alone does not cause a loop or performance degradation; STP would still converge and block redundant ports. Option D is wrong because if the new switch becomes the root bridge, it sends superior BPDUs (not inferior), and while this would cause a topology change, it would not inherently create a loop or cause the severe performance degradation described; the issue is the physical loop, not the root bridge election.

22
MCQeasy

A network administrator is troubleshooting a Cisco Catalyst switch and suspects a Layer 2 loop. The administrator wants to verify the Spanning Tree Protocol (STP) topology and identify the root bridge. Which command should be used?

A.show mac address-table
B.show spanning-tree
C.show interfaces trunk
D.show cdp neighbors
AnswerB

The 'show spanning-tree' command displays the STP topology, including the root bridge, root port, designated ports, and port states. It is the primary command to verify STP operation and detect loops. On a Cisco Catalyst switch, this command provides detailed information for each VLAN, helping the administrator identify the root bridge and any blocked ports.

Why this answer

To verify STP topology and identify the root bridge, the 'show spanning-tree' command is the correct choice. It provides detailed output for each VLAN, including the root bridge ID, root path cost, and port roles. This allows the administrator to confirm the expected topology and detect any loops or misconfigurations.

Exam trap

The trap here is confusing MAC address table output with STP topology information; seeing the same MAC on multiple ports suggests a loop but does not confirm STP status.

23
MCQmedium

A network engineer runs the following command on Switch SW1: SW1# show interfaces gi0/1 trunk Port Mode Encapsulation Status Native vlan Gi0/1 desirable n-802.1q trunking 1 Port Vlans allowed on trunk Gi0/1 1-1005 Port Vlans allowed and active in management domain Gi0/1 1,10,20 Port Vlans in spanning tree forwarding state and not pruned Gi0/1 1,10,20 Based on this output, what can be concluded?

A.The interface is configured as an access port.
B.The trunk is using ISL encapsulation.
C.VLANs 2-9 are allowed but not active.
D.The native VLAN is 10.
AnswerC

This is correct because the trunk's allowed VLAN list permits VLANs 1-1005, but the VLAN database only has VLANs 1, 10, and 20 in an active/up state (for instance, 'Status: active'). VLANs 2-9 are therefore permitted on the trunk but are not active, so they will not carry traffic until they are created and brought up, or until ports are assigned to them. Being allowed on a trunk does not make a VLAN operationally active; the VLAN must exist and have an active administrative state.

Why this answer

The output shows that VLANs 1-1005 are allowed on the trunk, but only VLANs 1, 10, and 20 are active in the management domain. This means VLANs 2-9 and 11-19, 21-1005 are allowed but not active (i.e., not created or not present on the switch). Option C correctly identifies that VLANs 2-9 are among those allowed but not active.

Exam trap

The trap here is that candidates often confuse 'allowed on trunk' with 'active in management domain', leading them to assume all allowed VLANs are actually forwarding traffic, when in fact only those listed in the second line are active.

How to eliminate wrong answers

Option A is wrong because the interface is in 'desirable' mode and shows 'trunking' status, which indicates it is a trunk port, not an access port. Option B is wrong because the encapsulation is 'n-802.1q' (likely a typo for '802.1q'), which is IEEE 802.1Q, not ISL (Cisco's proprietary encapsulation). Option D is wrong because the output explicitly shows 'Native vlan 1', not 10.

24
MCQhard

A network engineer is troubleshooting an STP issue in a network that uses Rapid PVST+. The network has a root bridge (SW1) and a secondary root bridge (SW2). The engineer notices that after a link failure between SW1 and SW2, the network takes longer than expected to converge. The engineer checks the configuration and finds that SW2 has the 'spanning-tree uplinkfast' command enabled. The engineer also notices that SW2 has a lower priority than SW1. What is the most likely cause of the slow convergence?

A.UplinkFast is enabled, which is incompatible with Rapid PVST+ and causes the switch to use legacy STP convergence.
B.SW2 has a lower priority than SW1, so it takes longer to become the root bridge after failure.
C.BPDU Guard is enabled on the uplink ports, which prevents BPDU exchange.
D.Loop Guard is enabled on the uplink ports, which delays port transition.
AnswerA

Correct because UplinkFast is a proprietary Cisco feature designed for legacy 802.1D PVST+ to quickly fail over to a precomputed alternate root port when the primary uplink fails. However, UplinkFast is mutually exclusive with Rapid PVST+/RSTP, and when enabled it forces the switch to fall back to the classic Spanning Tree Protocol algorithm. That legacy mode relies on Max Age (20 seconds) and Forward Delay (15 seconds) timers, so after a root port failure the switch takes 30–50 seconds to converge instead of milliseconds, matching the behavior described.

Why this answer

UplinkFast is a legacy STP feature that is incompatible with Rapid PVST+. When enabled on a switch running Rapid PVST+, it forces the switch to revert to 802.1D STP convergence behavior on the affected ports, disabling the rapid transition mechanisms (such as proposal/agreement and sync). This causes the network to take longer to converge after a link failure, as the switch falls back to the slower listening and learning states.

Exam trap

Cisco often tests the misconception that UplinkFast is a harmless optimization that can be combined with Rapid PVST+, when in fact it forces a fallback to legacy STP behavior, causing slow convergence.

How to eliminate wrong answers

Option B is wrong because SW2 having a lower priority than SW1 means SW2 is less likely to become the root bridge; after a failure, the switch with the lowest priority becomes root, so a lower priority (higher numerical value) does not cause slower convergence. Option C is wrong because BPDU Guard would disable a port upon receiving a BPDU, preventing BPDU exchange entirely, which would cause a different failure mode (port errdisable) rather than slow convergence. Option D is wrong because Loop Guard prevents alternate/backup ports from transitioning to forwarding when BPDUs stop, which can cause a blocking state but does not inherently delay port transition in a way that explains longer-than-expected convergence after a link failure.

25
MCQeasy

A network engineer runs the following command on Switch SW7: SW7# show spanning-tree vlan 70 VLAN0070 Spanning tree enabled protocol ieee Root ID Priority 24646 Address aabb.cc00.0c00 Cost 4 Port 1 (GigabitEthernet0/1) Hello Time 2 sec Max Age 20 sec Forward Delay 15 sec Bridge ID Priority 32768 (priority 32768 sys-id-ext 70) Address aabb.cc00.0d00 Hello Time 2 sec Max Age 20 sec Forward Delay 15 sec Aging Time 300 sec Interface Role Sts Cost Prio.Nbr Type ------------------- ---- --- --------- -------- ------------------------------ Gi0/1 Root FWD 4 128.1 P2p Gi0/2 Desg FWD 4 128.2 P2p Gi0/3 Altn BLK 4 128.3 P2p Based on this output, which port is the alternate port?

A.GigabitEthernet0/1
B.GigabitEthernet0/2
C.GigabitEthernet0/3
D.There is no alternate port.
AnswerC

GigabitEthernet0/3 is the correct alternate port because its port state is shown as Altn BLK, indicating it is blocked but has received a superior BPDU from another switch. This gives a different path to the root bridge than the root port, so it will transition to forwarding if Gi0/1 fails.

Why this answer

The alternate port is GigabitEthernet0/3 because it is in the 'Altn' role with a 'BLK' (blocking) state. In Rapid Spanning Tree Protocol (RSTP) and Per-VLAN Spanning Tree Plus (PVST+), an alternate port provides an alternative path to the root bridge and remains blocked unless the current root port fails. The output clearly shows Gi0/3 as 'Altn BLK', making it the alternate port.

Exam trap

Cisco often tests the distinction between alternate and backup ports; the trap here is that candidates may confuse 'Altn' (alternate, which provides a backup to the root port) with 'Backup' (which provides a backup to the designated port on the same segment), or assume that only root and designated ports exist in a stable topology.

How to eliminate wrong answers

Option A is wrong because GigabitEthernet0/1 is the root port (Role: Root, State: FWD), which is the best path to the root bridge, not an alternate port. Option B is wrong because GigabitEthernet0/2 is a designated port (Role: Desg, State: FWD), which forwards traffic on the segment and is not an alternate port. Option D is wrong because an alternate port is explicitly listed in the output (Gi0/3 with role 'Altn'), so the statement 'There is no alternate port' is false.

26
MCQhard

An enterprise campus uses Cisco Catalyst 9000 switches in a StackWise Virtual configuration at the distribution layer. The network team wants dual-homed access switches to use all uplinks simultaneously while avoiding spanning-tree blocking, and they want the distribution pair to appear as a single logical device to routing peers. Which statement describes how StackWise Virtual supports this design?

A.The pair presents one control plane and a single management IP, and Multichassis EtherChannel allows access switches to use all uplinks without STP blocking.
B.The two chassis elect an active and standby supervisor, and only the active chassis forwards traffic at any time.
C.The pair requires VSS with a virtual switch domain and PAgP to form the virtual switch link between the two chassis.
D.The pair operates as two independent Layer 3 gateways that share a virtual IP using HSRP on each VLAN interface.
AnswerA

StackWise Virtual merges two Catalyst 9000 chassis into one logical switch with a unified control plane, one management address, and one configuration. Multichassis EtherChannel, an MEC, lets a downstream access switch bundle uplinks to both chassis into one port-channel, so all links forward and spanning tree sees a single logical neighbor. This satisfies both the bandwidth and the single-logical-device requirements in the distribution pair.

Why this answer

StackWise Virtual combines two Catalyst 9000 chassis into one logical switch with a shared control plane, one management IP, and one configuration. Multichassis EtherChannel lets downstream switches bundle uplinks to both chassis into a single port-channel, so all links actively forward while spanning tree sees one logical device, and routing peers see a single next hop.

Exam trap

The trap here is assuming that only the active chassis forwards traffic in StackWise Virtual, when both chassis actively forward data-plane traffic.

27
MCQmedium

Examine the following partial Cisco IOS-XE configuration: interface GigabitEthernet0/1 switchport mode access switchport access vlan 10 ip access-group ACL_IN in spanning-tree portfast What is the effect of this configuration?

A.The port will immediately transition to forwarding state, reducing STP convergence time for end hosts.
B.The port will become a trunk port and participate in VLAN trunking.
C.The port will use Rapid PVST+ and immediately forward after a link failure.
D.The port will block all inbound traffic due to the ACL.
AnswerA

spanning-tree portfast moves the access port straight to forwarding, bypassing listening and learning states, so end hosts gain connectivity without waiting for STP convergence. The port remains access in VLAN 10 with ACL_IN applied inbound.

Why this answer

The configuration enables PortFast on an access port, allowing it to transition directly to forwarding state, bypassing the listening and learning phases. This is commonly used for end-host ports to avoid delays caused by spanning-tree convergence.

28
MCQeasy

A network engineer is troubleshooting a connectivity issue in a switched network. The network uses Rapid PVST+ with multiple VLANs. The engineer notices that a host connected to an access port on SW1 cannot communicate with the default gateway, which is on a distribution switch. The access port is configured with PortFast and BPDU Guard. The engineer checks the switch logs and sees that the port went into errdisable state. What is the most likely cause of the errdisable state?

A.Another switch was connected to the access port, causing BPDU Guard to disable the port.
B.A broadcast storm occurred due to a loop in the network.
C.The host connected to the port caused a duplex mismatch.
D.The cable connecting the host is faulty, causing link flaps.
AnswerA

When an access port is configured with PortFast, it assumes only an end host is attached, and BPDU Guard is often enabled to protect the STP domain. If another switch connects and sends a BPDU, BPDU Guard immediately places the port in errdisable state, which matches the log's reference to BPDU Guard. This is the only option that explains why the port was disabled and why the log specifically cites BPDU Guard.

Why this answer

The access port is configured with PortFast and BPDU Guard. PortFast immediately transitions the port to forwarding, but BPDU Guard monitors for incoming BPDUs. When another switch is connected to this access port, it sends BPDUs, triggering BPDU Guard to error-disable the port to prevent a potential bridging loop.

This matches the log entry showing the port went into errdisable state. Note that BPDU Guard is specifically designed to protect against unauthorized switches, and Root Guard is a separate mechanism used on uplinks.

Exam trap

Cisco often tests the distinction between BPDU Guard (which reacts to BPDUs) and other errdisable causes like loop guard, UDLD, or link-flap; the trap here is assuming that any errdisable on an access port must be due to a physical issue (duplex, cable) rather than a deliberate STP protection mechanism.

How to eliminate wrong answers

Option B is wrong because a broadcast storm due to a loop would typically cause high CPU utilization and potential port flapping, but it would not directly trigger BPDU Guard to error-disable a port; BPDU Guard specifically reacts to BPDU reception, not broadcast storms. Option C is wrong because a duplex mismatch causes CRC errors, late collisions, and performance degradation, but it does not cause BPDU Guard to disable the port; duplex mismatch is detected by interface counters, not by BPDU Guard. Option D is wrong because a faulty cable causing link flaps would result in the port repeatedly going up/down, which could trigger errdisable due to link-flap protection (if configured), but not BPDU Guard; the logs specifically mention errdisable from BPDU Guard, not from link flaps.

29
MCQmedium

spanning-tree mode rapid-pvst What is the effect of this global configuration command?

A.The switch will use Rapid PVST+ for all VLANs, providing faster convergence than classic STP.
B.The switch will use MSTP for all VLANs.
C.The switch will use classic STP for all VLANs.
D.The switch will disable STP on all ports.
AnswerA

Rapid PVST+ runs a separate 802.1w instance per VLAN, so each VLAN's topology converges independently using rapid handshake proposals and agreements rather than timers. This satisfies the stem's requirement of faster convergence than classic 802.1D STP while retaining per-VLAN load balancing.

Why this answer

The command 'spanning-tree mode rapid-pvst' enables Rapid PVST+ (Per-VLAN Spanning Tree Plus) on the switch, which runs a separate instance of RSTP (802.1w) for each VLAN. This provides faster convergence than classic STP (802.1D) by using mechanisms such as sync/agreement handshakes, edge ports, and link types, while still maintaining per-VLAN topology independence.

Exam trap

Cisco often tests the distinction between 'rapid-pvst' (RSTP per VLAN) and 'mst' (MSTP, which maps multiple VLANs to fewer instances), and candidates may confuse 'rapid-pvst' with simply enabling RSTP globally without understanding it applies per VLAN.

How to eliminate wrong answers

Option B is wrong because MSTP (Multiple Spanning Tree Protocol, 802.1s) is enabled with the command 'spanning-tree mode mst', not 'rapid-pvst'. Option C is wrong because classic STP (802.1D) is the default mode on many switches or is set with 'spanning-tree mode pvst', not with 'rapid-pvst'. Option D is wrong because the command does not disable STP; STP is disabled globally with 'no spanning-tree vlan <vlan>' or 'spanning-tree mode none' (if supported), not by setting the mode to rapid-pvst.

30
MCQmedium

interface GigabitEthernet0/1 spanning-tree portfast spanning-tree bpduguard enable end What is the effect of this configuration?

A.The port will immediately transition to forwarding state and will be error-disabled if a BPDU is received.
B.The port will go through normal STP states and will be error-disabled if a BPDU is received.
C.The port will immediately transition to forwarding and ignore any BPDUs received.
D.The port will remain in blocking state until a BPDU is received.
AnswerA

Enabling PortFast on a switchport causes it to bypass the STP listening and learning states and transition directly to forwarding, which is appropriate for host-facing access ports. If BPDU Guard is also enabled on that port, any received BPDU—which should never arrive from an end host—is treated as a misconfiguration, and the port is immediately placed into the error-disabled state. This protects the access domain from accidental loops or rogue switch connections, and the port stays in error-disable until manual intervention or an errdisable recovery timer is configured.

Why this answer

The `spanning-tree portfast` command causes the port to immediately transition to the forwarding state, bypassing the listening and learning states. The `spanning-tree bpduguard enable` command places the port in an error-disabled state if any BPDU is received, as BPDU reception on a PortFast-enabled port indicates an unauthorized switch connection, which could cause a bridging loop.

Exam trap

Cisco often tests the misconception that BPDUguard ignores BPDUs or that PortFast still goes through STP states, but the key trap is that BPDUguard error-disables the port upon BPDU reception, not just ignores or blocks it.

How to eliminate wrong answers

Option B is wrong because PortFast causes immediate transition to forwarding, not normal STP states. Option C is wrong because BPDUguard does not ignore BPDUs; it error-disables the port upon BPDU reception. Option D is wrong because PortFast immediately transitions to forwarding, not remaining in blocking state, and BPDUguard does not require a BPDU to unblock.

31
MCQhard

A network engineer runs the following command on Switch SW2: SW2# show spanning-tree vlan 10 VLAN0010 Spanning tree enabled protocol ieee Root ID Priority 32778 Address aabb.cc00.0100 Cost 19 Port 1 (GigabitEthernet0/1) Hello Time 2 sec Max Age 20 sec Forward Delay 15 sec Bridge ID Priority 32778 (priority 32768 sys-id-ext 10) Address aabb.cc00.0200 Hello Time 2 sec Max Age 20 sec Forward Delay 15 sec Aging Time 300 sec Interface Role Sts Cost Prio.Nbr Type ------------------- ---- --- --------- -------- -------------------------------- Gi0/1 Root FWD 19 128.1 P2p Gi0/2 Altn BLK 19 128.2 P2p Gi0/3 Desg FWD 19 128.3 P2p Based on this output, what can be concluded?

A.SW2 is the root bridge for VLAN 10.
B.The root bridge for VLAN 10 has MAC address aabb.cc00.0100.
C.Port Gi0/2 is in forwarding state.
D.The STP priority for VLAN 10 is 32768.
AnswerB

The Root ID field in the spanning-tree output announces the root bridge's identifier, and it lists aabb.cc00.0100 as the root MAC for VLAN 10. STP elects the root based on the lowest bridge ID, and this MAC belongs to whichever switch has won that election for this VLAN. Therefore the root bridge for VLAN 10 is the switch with that MAC address, not the local switch.

Why this answer

The output shows that the Root ID has MAC address aabb.cc00.0100, while the Bridge ID (SW2 itself) has MAC address aabb.cc00.0200. Since SW2 is not the root bridge (its Bridge ID differs from the Root ID), the root bridge for VLAN 10 must be the switch with MAC address aabb.cc00.0100. The Root ID field always identifies the root bridge in the spanning tree.

Exam trap

Cisco often tests the distinction between the Root ID and Bridge ID fields in 'show spanning-tree' output, causing candidates to mistakenly think the local switch is the root when they see its own priority, without checking the MAC address or root port status.

How to eliminate wrong answers

Option A is wrong because SW2's Bridge ID (aabb.cc00.0200) does not match the Root ID (aabb.cc00.0100), and SW2 has a root port (Gi0/1) with a cost of 19, indicating it is not the root bridge. Option C is wrong because the output shows Gi0/2 is in the 'Altn BLK' (Alternate Blocking) role and state, not forwarding. Option D is wrong because the STP priority for VLAN 10 is 32778 (as shown in the Bridge ID line), which is the base priority 32768 plus the VLAN ID 10 (sys-id-ext), not 32768 alone.

32
MCQmedium

A network engineer runs the following command on Switch SW1: SW1# show spanning-tree vlan 10 VLAN0010 Spanning tree enabled protocol ieee Root ID Priority 32778 Address 0011.2233.4455 Cost 19 Port 1 (GigabitEthernet0/1) Hello Time 2 sec Max Age 20 sec Forward Delay 15 sec Bridge ID Priority 32778 (priority 32768 sys-id-ext 10) Address 0011.2233.4466 Hello Time 2 sec Max Age 20 sec Forward Delay 15 sec Aging Time 300 sec Interface Role Sts Cost Prio.Nbr Type ------------------- ---- --- --------- -------- -------------------------------- Gi0/1 Root FWD 19 128.1 P2p Gi0/2 Altn BLK 19 128.2 P2p Based on this output, what can be concluded?

A.The local switch is the root bridge for VLAN 10
B.The local switch is not the root bridge for VLAN 10
C.Interface Gi0/2 is in a forwarding state
D.The spanning-tree mode is Rapid PVST+
AnswerB

This is the correct inference from the spanning-tree output. The Root ID field shows a MAC address of 0011.2233.4455, whereas the local switch's Bridge ID uses 0011.2233.4466, so they are different. In STP, a switch knows it is not the root when its own bridge ID does not match the Root ID. Therefore, the local switch must be a non-root switch, and it will have a root port selected toward the root bridge.

Why this answer

The output shows that the local switch (Bridge ID 0011.2233.4466) has a Root ID of 0011.2233.4455, which is different from its own Bridge ID. Additionally, the Root Cost is 19, and the Root Port is Gi0/1. This confirms that the local switch is not the root bridge for VLAN 10; it is a non-root switch with a root port in the forwarding state.

Exam trap

Cisco often tests the distinction between the Root ID and Bridge ID in 'show spanning-tree' output, where candidates mistakenly assume the local switch is the root if they see a priority value without checking the MAC address.

How to eliminate wrong answers

Option A is wrong because the local switch's Bridge ID (0011.2233.4466) does not match the Root ID (0011.2233.4455), so it is not the root bridge. Option C is wrong because the Role column shows Gi0/2 as 'Altn' (Alternate) and the Status as 'BLK' (Blocking), not forwarding. Option D is wrong because the output shows 'Spanning tree enabled protocol ieee', which indicates IEEE 802.1D (classic STP), not Rapid PVST+ (which would show 'protocol ieee' with 'Rapid' or 'PVST' in the mode line).

33
MCQmedium

A network engineer runs the following command on Switch SW6: SW6# show spanning-tree vlan 60 VLAN0060 Spanning tree enabled protocol ieee Root ID Priority 24636 Address aabb.cc00.0a00 Cost 8 Port 1 (GigabitEthernet0/1) Hello Time 2 sec Max Age 20 sec Forward Delay 15 sec Bridge ID Priority 32768 (priority 32768 sys-id-ext 60) Address aabb.cc00.0b00 Hello Time 2 sec Max Age 20 sec Forward Delay 15 sec Aging Time 300 sec Interface Role Sts Cost Prio.Nbr Type ------------------- ---- --- --------- -------- ------------------------------ Gi0/1 Root FWD 8 128.1 P2p Gi0/2 Desg FWD 4 128.2 P2p Gi0/3 Altn BLK 4 128.3 P2p Gi0/4 Desg FWD 4 128.4 P2p Based on this output, what is the bridge priority of the root bridge for VLAN 60?

A.24576
B.24636
C.32768
D.32828
AnswerB

The Root ID priority in the output is 24636, which is the complete 16-bit priority value formed by the base priority (24576, or 0x6000) plus the VLAN system ID extension (60, or 0x003C). This value is lower than 32768, indicating that the root bridge has a higher priority (a lower numeric value) than the default, which is why it won the root election. Thus, 24636 is the correct answer.

Why this answer

The root bridge's priority is shown in the 'Root ID' section as 'Priority 24636'. This value includes the system ID extension (VLAN 60), so the actual bridge priority is 24636 - 60 = 24576. However, the question asks for the bridge priority as displayed in the output, which is 24636.

Option B is correct because the output explicitly lists the root bridge priority as 24636.

Exam trap

Cisco often tests whether candidates understand that the 'Priority' field in the 'Root ID' section includes the system ID extension (VLAN ID), so the displayed value is not the base priority but the combined value, leading many to incorrectly subtract the VLAN ID when the question simply asks for the value as shown.

How to eliminate wrong answers

Option A is wrong because 24576 is the base priority (24636 minus the VLAN 60 sys-id-ext), but the question asks for the bridge priority as shown in the output, which includes the system ID extension. Option C is wrong because 32768 is the bridge priority of the local switch (SW6), not the root bridge. Option D is wrong because 32828 is not a valid priority value in this context; it might be a distractor combining the local bridge priority (32768) with the VLAN ID (60) incorrectly.

34
MCQeasy

A network engineer runs the following command on Switch SW8: SW8# show spanning-tree vlan 80 VLAN0080 Spanning tree enabled protocol ieee Root ID Priority 24656 Address aabb.cc00.0e00 Cost 12 Port 1 (GigabitEthernet0/1) Hello Time 2 sec Max Age 20 sec Forward Delay 15 sec Bridge ID Priority 32768 (priority 32768 sys-id-ext 80) Address aabb.cc00.0f00 Hello Time 2 sec Max Age 20 sec Forward Delay 15 sec Aging Time 300 sec Interface Role Sts Cost Prio.Nbr Type ------------------- ---- --- --------- -------- ------------------------------ Gi0/1 Root FWD 12 128.1 P2p Gi0/2 Desg FWD 4 128.2 P2p Gi0/3 Desg FWD 4 128.3 P2p Gi0/4 Altn BLK 4 128.4 P2p Based on this output, what is the cost of the root port?

A.4
B.8
C.12
D.16
AnswerC

The root port Gi0/1 is assigned a port cost of 12 in the spanning-tree output, representing the cumulative cost to reach the root bridge from this switch. This value is calculated by summing the cost of the root port's link plus any upstream costs, and it determines the best path to the root. Since the output shows 'cost 12' for the root port, 12 is the correct answer.

Why this answer

The root port cost is the cost to reach the root bridge, which is explicitly shown in the 'Root ID' section as 'Cost 12'. This cost is associated with the root port (Gi0/1), which has a role of 'Root' and a status of 'FWD'. Therefore, the correct answer is 12.

Exam trap

Cisco often tests the distinction between the root port cost (shown in the 'Root ID' section) and the local port cost (shown in the 'Cost' column for each interface), leading candidates to mistakenly pick the local cost of the root port (which is 12 in this case, but the trap is that they might pick the cost of a designated port like 4).

How to eliminate wrong answers

Option A is wrong because 4 is the cost of the designated ports (Gi0/2 and Gi0/3) and the alternate port (Gi0/4), not the root port. Option B is wrong because 8 is not present in the output; it might be a distractor from adding the root cost (12) and a local port cost (4). Option D is wrong because 16 is not derived from any value in the output; it could be a misreading of the root bridge's priority (24656) or a miscalculation.

35
MCQmedium

A network engineer runs the following command on Switch SW1: SW1# show spanning-tree vlan 10 VLAN0010 Spanning tree enabled protocol ieee Root ID Priority 32778 Address 0011.2233.4455 Cost 19 Port 1 (GigabitEthernet0/1) Hello Time 2 sec Max Age 20 sec Forward Delay 15 sec Bridge ID Priority 32778 (priority 32768 sys-id-ext 10) Address 0011.2233.4466 Hello Time 2 sec Max Age 20 sec Forward Delay 15 sec Aging Time 300 sec Interface Role Sts Cost Prio.Nbr Type ------------------- ---- --- --------- -------- -------------------------------- Gi0/1 Root FWD 19 128.1 P2p Gi0/2 Altn BLK 19 128.2 P2p Gi0/3 Desg FWD 19 128.3 P2p Based on this output, what can be concluded?

A.SW1 is the root bridge for VLAN 10.
B.Gi0/2 is in blocking state due to loop prevention.
C.Gi0/3 is a root port.
D.The root bridge has a higher priority than SW1.
AnswerB

Gi0/2 is correctly placed in blocking state because Spanning Tree Protocol designates it as an alternate port, which functions as a redundant path to the root bridge that is less optimal than the root port. This blocking state is intentional loop prevention; if Gi0/2 were allowed to forward, it would create a Layer 2 forwarding loop in the switched topology. The alternate port role is typical in networks with redundant links and does not indicate a failure or misconfiguration.

Why this answer

The output shows Gi0/2 is in the Alternate (Altn) role with a Blocking (BLK) state. In Rapid PVST+ (IEEE 802.1w), an alternate port provides a backup path to the root bridge and is placed in a blocking state to prevent Layer 2 loops. Since SW1 is not the root bridge (its Bridge ID priority 32778 is equal to the Root ID priority, but its MAC address 0011.2233.4466 is higher than the root's 0011.2233.4455), Gi0/2 is blocking as a loop-prevention mechanism.

Exam trap

Cisco often tests the distinction between port roles (Root, Designated, Alternate, Backup) and port states (FWD, BLK), where candidates mistakenly assume that any port in a blocking state is a Backup port or that a Designated port must be on the root bridge, when in fact Alternate ports block to prevent loops on non-root bridges.

How to eliminate wrong answers

Option A is wrong because SW1 is not the root bridge for VLAN 10; the Root ID shows a MAC address of 0011.2233.4455, while SW1's Bridge ID MAC is 0011.2233.4466, and the root cost is 19 via Gi0/1, indicating SW1 is a non-root switch. Option C is wrong because Gi0/3 is in the Desg (Designated) role with FWD state, not a root port; the root port is Gi0/1, which has the Root role and FWD state. Option D is wrong because the root bridge has the same priority (32778) as SW1, not a higher priority; the root is elected based on the lowest bridge ID, and here the root's MAC address is lower, making it the root despite equal priority.

36
Multi-Selecthard

Which three statements about Multiple Spanning Tree Protocol (MSTP) are true? (Choose three.)

Select 3 answers
A.MSTP allows multiple VLANs to be grouped into a single spanning-tree instance, reducing CPU and memory usage.
B.In MSTP, the Internal Spanning Tree (IST) instance is instance 0 and is always present in every MST region.
C.MSTP requires that all switches in the same MST region have the same VLAN-to-instance mapping, revision number, and region name.
D.MSTP automatically load-balances traffic across all available uplinks without any configuration.
E.MSTP requires a separate root bridge to be elected for each VLAN in the network.
AnswersA, B, C

MSTP maps many VLANs onto a shared instance, so a single spanning-tree computation serves them all. That collapses per-VLAN STP processing into fewer instances, directly cutting CPU and memory load compared with PVST+ running one tree per VLAN.

Why this answer

MSTP (IEEE 802.1s) allows multiple VLANs to be mapped to a single spanning-tree instance (MST instance), reducing the number of STP instances needed. It uses an Internal Spanning Tree (IST) instance (instance 0) that always runs and carries BPDUs for the region. Switches in the same MST region must have identical VLAN-to-instance mappings, revision number, and region name.

MSTP interoperates with Rapid PVST+ at region boundaries by using PVST simulation mode. MSTP does not require a separate root bridge for each VLAN; instead, each MST instance has its own root bridge.

37
MCQeasy

A network engineer runs the following command on Switch SW4: SW4# show spanning-tree vlan 40 VLAN0040 Spanning tree enabled protocol ieee Root ID Priority 24616 Address aabb.cc00.0600 Cost 8 Port 1 (GigabitEthernet0/1) Hello Time 2 sec Max Age 20 sec Forward Delay 15 sec Bridge ID Priority 32768 (priority 32768 sys-id-ext 40) Address aabb.cc00.0700 Hello Time 2 sec Max Age 20 sec Forward Delay 15 sec Aging Time 300 sec Interface Role Sts Cost Prio.Nbr Type ------------------- ---- --- --------- -------- ------------------------------ Gi0/1 Root FWD 8 128.1 P2p Gi0/2 Desg FWD 4 128.2 P2p Gi0/3 Desg FWD 4 128.3 P2p Based on this output, which port is the root port?

A.GigabitEthernet0/1
B.GigabitEthernet0/2
C.GigabitEthernet0/3
D.There is no root port because SW4 is the root bridge.
AnswerA

GigabitEthernet0/1 is the root port on SW4. In STP, a non-root bridge selects the single port that receives the best (lowest-cost) BPDU from the root bridge, and that port is assigned the Root role. Because the output shows Gi0/1 with role 'Root', it is the path toward the root bridge, even though SW4 itself is not the root bridge.

Why this answer

The root port is the port on a non-root bridge that provides the lowest-cost path to the root bridge. In the output, SW4 is not the root bridge because its Bridge ID (priority 32768 + VLAN 40) is higher than the Root ID priority 24616, and the Root Cost is 8 via Gi0/1. The 'Role' column shows Gi0/1 as 'Root' and its 'Sts' is 'FWD', confirming it is the root port.

Exam trap

Cisco often tests the distinction between the root port (on a non-root bridge) and the designated port (on a root bridge or segment), and candidates may mistakenly think a switch with a lower-cost port is the root bridge or that all forwarding ports are root ports.

How to eliminate wrong answers

Option B is wrong because Gi0/2 has a role of 'Desg' (designated), not 'Root', and its cost of 4 is lower than the root cost of 8, but that cost is for its own segment, not the path to the root. Option C is wrong because Gi0/3 also has a role of 'Desg' and is a designated port, not a root port. Option D is wrong because SW4 is not the root bridge; the Root ID priority 24616 differs from SW4's Bridge ID priority 32768 (with sys-id-ext 40), and the root cost of 8 indicates SW4 is downstream from the root bridge.

38
MCQmedium

A large enterprise is redesigning its campus network to support 5000 users across three buildings. The design must provide high availability and fast convergence in case of a link failure. The network engineer is considering using Spanning Tree Protocol (STP) in the access layer. What is the primary design concern with using STP in this scenario?

A.STP will cause slow convergence and inefficient use of redundant links.
B.STP requires all switches to be in the same VLAN to function correctly.
C.STP cannot be used with 5000 users due to MAC address table limitations.
D.STP will cause broadcast storms in a three-building design.
AnswerA

STP (802.1D) prevents loops by placing redundant switch ports in a blocking state, leaving only one active path to a given root bridge. During a topology change, the listening and learning forward-delay timers (default 15 seconds each) plus the max-age timer can cause convergence to take 30–50 seconds, far too slow for high-availability designs. Meanwhile, the blocked redundant links remain physically connected but carry no user traffic, wasting available bandwidth and forcing traffic over a single, possibly congested path. This is why modern designs often use RSTP or link aggregation, which either converge faster or utilize all links in an EtherChannel.

Why this answer

STP (802.1D) converges slowly, typically taking 30-50 seconds (listening + learning states) after a topology change. In a large campus network with 5000 users, this delay causes unacceptable downtime. Additionally, STP blocks redundant links to prevent loops, wasting bandwidth that could be used for load balancing.

Modern alternatives like Rapid PVST+ (802.1w) or MST (802.1s) offer sub-second convergence, making classic STP a poor choice for high-availability designs.

Exam trap

Cisco often tests the misconception that STP is a suitable high-availability solution, when in fact its slow convergence and blocked link inefficiency make it a poor choice for modern campus networks; candidates may overlook the need for RSTP or MST in the design.

How to eliminate wrong answers

Option B is wrong because STP does not require all switches to be in the same VLAN; it operates per VLAN (PVST/PVST+) or per instance (MST), and switches in different VLANs can still participate in STP. Option C is wrong because STP does not impose MAC address table limitations based on user count; MAC table size is a hardware limitation of the switch ASIC, not a protocol constraint, and 5000 users is well within typical switch capacities. Option D is wrong because STP is designed to prevent broadcast storms by blocking redundant paths; broadcast storms are caused by loops, which STP actively eliminates, not creates.

39
MCQhard

A network engineer runs the following command on Switch SW3: SW3# show spanning-tree vlan 30 VLAN0030 Spanning tree enabled protocol ieee Root ID Priority 24606 Address aabb.cc00.0400 Cost 12 Port 2 (GigabitEthernet0/2) Hello Time 2 sec Max Age 20 sec Forward Delay 15 sec Bridge ID Priority 32798 (priority 32768 sys-id-ext 30) Address aabb.cc00.0500 Hello Time 2 sec Max Age 20 sec Forward Delay 15 sec Aging Time 300 sec Interface Role Sts Cost Prio.Nbr Type ------------------- ---- --- --------- -------- ------------------------------ Gi0/1 Desg FWD 4 128.1 P2p Gi0/2 Root FWD 12 128.2 P2p Gi0/3 Desg FWD 4 128.3 P2p Based on this output, what is the root path cost from SW3 to the root bridge for VLAN 30?

A.4
B.12
C.16
D.20
AnswerB

The show spanning-tree command displays the Root ID section, which includes the bridge's own root path cost. In this output, the Cost field under Root ID is 12, indicating the total accumulated path cost from this switch to the root bridge. This metric is used for root port selection and is the correct answer. It is not a per-interface value but the sum of all outgoing port costs along the best path.

Why this answer

The root path cost is the cumulative cost from the local switch to the root bridge. In the output, the Root ID section shows a cost of 12, and the Gi0/2 interface is the root port with a cost of 12. This cost represents the total path cost from SW3 to the root bridge for VLAN 30, making option B correct.

Exam trap

Cisco often tests the distinction between the root port's cost (which is the root path cost) and the cost of other ports, leading candidates to mistakenly select the cost of a designated port (like 4) instead.

How to eliminate wrong answers

Option A is wrong because 4 is the port cost of Gi0/1 and Gi0/3, which are designated ports, not the root path cost. Option C is wrong because 16 is not a value present in the output; it might be a sum of two port costs but does not represent the root path cost. Option D is wrong because 20 is not a value present in the output; it is the Max Age timer value, not a path cost.

40
Drag & Dropmedium

Drag and drop the steps of STP portfast and BPDU guard configuration into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

PortFast is enabled globally or per interface to bypass listening/learning. BPDU guard is then configured to disable the port if a BPDU is received. The configuration is applied to the interface, and the port transitions to forwarding immediately.

Finally, errdisable recovery can be set.

Ready to test yourself?

Try a timed practice session using only Spanning Tree questions.