mediumMultiple Choice
350-401 Practice Question: Runs the following command on Switch SW1: SW1#…
A network engineer runs the following command on Switch SW1:
SW1# show spanning-tree vlan 10
VLAN0010 Spanning tree enabled protocol ieee Root ID Priority 32778 Address 0011.2233.4455 Cost 19 Port 1 (GigabitEthernet0/1) Hello Time 2 sec Max Age 20 sec Forward Delay 15 sec
Bridge ID Priority 32778 (priority 32768 sys-id-ext 10) Address 0011.2233.4466 Hello Time 2 sec Max Age 20 sec Forward Delay 15 sec Aging Time 300 sec
Interface Role Sts Cost Prio.Nbr Type
------------------- ---- --- --------- -------- -------------------------------- Gi0/1 Root FWD 19 128.1 P2p Gi0/2 Altn BLK 19 128.2 P2p Gi0/3 Desg FWD 19 128.3 P2p
Based on this output, what can be concluded?
⚠ Common exam trap
Cisco often tests the distinction between port roles (Root, Designated, Alternate, Backup) and port states (FWD, BLK), where candidates mistakenly assume that any port in a blocking state is a Backup port or that a Designated port must be on the root bridge, when in fact Alternate ports block to prevent loops on non-root bridges.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Gi0/2 is in blocking state due to loop prevention.
The output shows Gi0/2 is in the Alternate (Altn) role with a Blocking (BLK) state. In Rapid PVST+ (IEEE 802.1w), an alternate port provides a backup path to the root bridge and is placed in a blocking state to prevent Layer 2 loops. Since SW1 is not the root bridge (its Bridge ID priority 32778 is equal to the Root ID priority, but its MAC address 0011.2233.4466 is higher than the root's 0011.2233.4455), Gi0/2 is blocking as a loop-prevention mechanism.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
SW1 is the root bridge for VLAN 10.
Why it's wrong here
SW1 cannot be the root bridge for VLAN 10 because the root bridge election is decided by the lowest bridge ID, and bridge IDs are compared first by priority and then by MAC address. In this topology, both SW1 and the actual root bridge have the same priority of 32778, so the switch with the lower MAC address, 0011.2233.4455, wins that election. Since SW1's MAC address is 0011.2233.4466, which is higher, SW1 is not the root bridge; instead, SW1 has a root port toward the true root and a blocking alternate port, neither of which would exist on the root bridge.
- ✓
Gi0/2 is in blocking state due to loop prevention.
Why this is correct
Gi0/2 is correctly placed in blocking state because Spanning Tree Protocol designates it as an alternate port, which functions as a redundant path to the root bridge that is less optimal than the root port. This blocking state is intentional loop prevention; if Gi0/2 were allowed to forward, it would create a Layer 2 forwarding loop in the switched topology. The alternate port role is typical in networks with redundant links and does not indicate a failure or misconfiguration.
- ✗
Gi0/3 is a root port.
Why it's wrong here
Gi0/3 is not a root port because its role in the spanning tree is designated, meaning SW1 is the designated bridge for the segment connected to that interface and is responsible for forwarding BPDUs to that segment. A root port, by contrast, is the single port on a switch that provides the shortest path to the root bridge, and it always remains in forwarding state. Since Gi0/3 has a designated role, it does not satisfy the requirement of being the port with the lowest root path cost, and the actual root port on SW1 is a different interface.
- ✗
The root bridge has a higher priority than SW1.
Why it's wrong here
The claim that the root bridge has a higher priority than SW1 is incorrect because both switches use the same bridge priority value of 32768 plus the VLAN 10 extended system ID, resulting in 32778. In STP, a numerically lower priority is considered better, so a higher numeric priority would actually make a switch less likely to become the root bridge. Since the priorities are equal, the root bridge is determined by the lower MAC address, and the root bridge's MAC address (0011.2233.4455) is lower than SW1's, not its priority.
Visual reference
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
About these practice questions
One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.