Courseiva
hardMultiple Choice

350-401 Practice Question: An enterprise network is experiencing high CPU…

An enterprise network is experiencing high CPU utilization on the distribution layer switches. The design uses VLANs with SVIs for inter-VLAN routing, and HSRP for first-hop redundancy. The engineer notices that the standby switch is also experiencing high CPU. What is the most likely cause?

⚠ Common exam trap

Cisco often tests the misconception that the standby switch is idle or only processes traffic during failover, when in reality it must continuously process HSRP hellos for every configured group, which can become a significant CPU burden in large VLAN deployments.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The standby switch is processing HSRP hellos for all VLANs, causing CPU spikes.

In an HSRP setup, both the active and standby routers process incoming Hello messages for every VLAN on which HSRP is configured. Even though the standby switch does not forward inter-VLAN traffic, it must still receive and process periodic HSRP hellos (default every 3 seconds) to maintain its role and detect active failures. With a large number of VLANs, the cumulative CPU overhead from processing these hellos can cause high utilization on both switches.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The standby switch is processing HSRP hellos for all VLANs, causing CPU spikes.

    Why this is correct

    Each VLAN configured for HSRP creates a separate HSRP group, and the standby switch must process multicast hello packets (normally sent every 3 seconds) for every one of those groups. With hundreds of VLANs, the cumulative volume of hello packets—each requiring CPU interrupt handling, state-machine updates, and authentication checks—can saturate the control plane and manifest as CPU spikes. This makes HSRP hello processing the most plausible cause of standby CPU utilization in a large L3-access design.

  • ✗

    The standby switch is forwarding all broadcast traffic due to a misconfigured STP root.

    Why it's wrong here

    A misconfigured STP root would alter the spanning-tree topology, potentially causing inefficient paths or even transient loops, but it does not force any single switch to forward 'all broadcast traffic.' Broadcast flooding is a normal behavior in every Layer 2 switch, and the root's position only affects the blocking/forwarding state of redundant links—not which switch processes broadcast frames. Sustained high CPU from broadcasts would be caused by a broadcast storm, which would broadly impact all switches, not specifically single out the standby in an HSRP pair.

  • ✗

    The standby switch is performing routing for all VLANs because the active switch failed.

    Why it's wrong here

    If the active HSRP switch failed, the standby would transition to the Active state and begin actively routing/forwarding traffic for the affected VLANs, which could certainly increase CPU utilization. However, the scenario describes the standby switch as still being in the standby role, so it is not performing the routing function for all VLANs; it is merely exchanging hellos and monitoring for active failure. Therefore, this option misinterprets both the HSRP state machine and the cause of the reported CPU spikes.

  • ✗

    The standby switch is processing VTP updates from the distribution layer.

    Why it's wrong here

    VTP (VLAN Trunking Protocol) updates are only transmitted when a VLAN is added, removed, or modified, and they are not periodical; modern campus designs almost universally have VTP disabled or set to transparent mode. Even if VTP were active, the distribution layer would not be repeatedly sending updates that cause sustained CPU overhead solely on the standby switch—such a condition would require continuous configuration changes, which is not indicated. The periodic, per-VLAN HSRP hello load is a far more consistent and scalable explanation.

Visual reference

Switch VLAN 10 Sales (192.168.10.0/24) PC-A PC-B VLAN 20 HR (192.168.20.0/24) PC-C PC-D Router VLANs isolate traffic — inter-VLAN routing requires a Layer 3 device

Go deeper

Related to this question

About these practice questions

Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.