Courseiva
Security →easyMultiple Choice

350-401 Security Practice Question

A network administrator at a small company wants to prevent users from plugging unauthorized switches into wall jacks and creating loops or bypassing security controls. The administrator decides to implement BPDU Guard on all access ports on a Cisco Catalyst switch. Which statement accurately describes the behavior of BPDU Guard when configured on an access port?

⚠ Common exam trap

It's easy for candidates to confuse BPDU Guard with BPDU Filter, where BPDU Filter suppresses BPDUs while BPDU Guard disables the port upon receiving one.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

It places the port into err-disabled state if a BPDU is received on the port.

BPDU Guard protects access ports by err-disabling them when any BPDU is received. This prevents unauthorized switches from being connected and potentially disrupting the spanning tree topology. It is commonly deployed alongside PortFast on access ports to ensure that end-user devices cannot participate in STP.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    It filters BPDUs from being forwarded out of the port while allowing the port to remain active.

    Why it's wrong here

    BPDU filtering prevents BPDUs from being transmitted out of a port, which is a different feature. BPDU Guard does not filter outbound BPDUs; instead, it monitors inbound BPDUs and disables the port upon detection, which is a more aggressive protective action.

  • ✗

    It converts the access port into a trunk port when BPDUs are detected to allow proper spanning tree convergence.

    Why it's wrong here

    BPDU Guard never converts an access port into a trunk port. Its purpose is to prevent unauthorized switches from connecting, so converting the port would defeat the security objective. Trunk negotiation is controlled by DTP, not by BPDU Guard.

  • ✓

    It places the port into err-disabled state if a BPDU is received on the port.

    Why this is correct

    BPDU Guard is designed to protect access ports from receiving BPDUs. When a BPDU is detected on a port with BPDU Guard enabled, the switch immediately places that port into err-disabled state, preventing the unauthorized device from participating in spanning tree and potentially causing loops or topology changes.

  • ✗

    It sends a syslog message and drops only the offending BPDU while keeping the port operational.

    Why it's wrong here

    BPDU Guard does not merely drop the BPDU and keep the port up. The entire port is placed into err-disabled state, which stops all traffic on that interface. This is more severe than just filtering individual BPDUs and is intentional to fully block the unauthorized device.

Visual reference

SW1 Root Bridge SW2 SW3 BLK DP DP RP RP STP blocks one link to prevent loops DP = Designated Port RP = Root Port BLK = Blocked

About these practice questions

One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.