Courseiva
hardMultiple Choice

350-401 Practice Question: Runs the following command on Switch SW2: SW2#…

A network engineer runs the following command on Switch SW2:

SW2# show spanning-tree vlan 10

VLAN0010 Spanning tree enabled protocol ieee Root ID Priority 32778 Address aabb.cc00.0100 Cost 19 Port 1 (GigabitEthernet0/1) Hello Time 2 sec Max Age 20 sec Forward Delay 15 sec

Bridge ID Priority 32778 (priority 32768 sys-id-ext 10) Address aabb.cc00.0200 Hello Time 2 sec Max Age 20 sec Forward Delay 15 sec Aging Time 300 sec

Interface           Role Sts Cost      Prio.Nbr Type

------------------- ---- --- --------- -------- -------------------------------- Gi0/1 Root FWD 19 128.1 P2p Gi0/2 Altn BLK 19 128.2 P2p Gi0/3 Desg FWD 19 128.3 P2p

Based on this output, what can be concluded?

⚠ Common exam trap

Cisco often tests the distinction between the Root ID and Bridge ID fields in 'show spanning-tree' output, causing candidates to mistakenly think the local switch is the root when they see its own priority, without checking the MAC address or root port status.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The root bridge for VLAN 10 has MAC address aabb.cc00.0100.

The output shows that the Root ID has MAC address aabb.cc00.0100, while the Bridge ID (SW2 itself) has MAC address aabb.cc00.0200. Since SW2 is not the root bridge (its Bridge ID differs from the Root ID), the root bridge for VLAN 10 must be the switch with MAC address aabb.cc00.0100. The Root ID field always identifies the root bridge in the spanning tree.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    SW2 is the root bridge for VLAN 10.

    Why it's wrong here

    SW2 cannot be the root bridge for VLAN 10 because it has a root port (Gi0/1); a root bridge has no root port and all of its ports are designated. The Root ID in the output shows a specific MAC address (aabb.cc00.0100) as the root, which would be SW2's own MAC if SW2 were root. Since the Bridge ID for SW2 would differ, SW2 is a non-root switch forwarding toward that root.

  • ✓

    The root bridge for VLAN 10 has MAC address aabb.cc00.0100.

    Why this is correct

    The Root ID field in the spanning-tree output announces the root bridge's identifier, and it lists aabb.cc00.0100 as the root MAC for VLAN 10. STP elects the root based on the lowest bridge ID, and this MAC belongs to whichever switch has won that election for this VLAN. Therefore the root bridge for VLAN 10 is the switch with that MAC address, not the local switch.

  • ✗

    Port Gi0/2 is in forwarding state.

    Why it's wrong here

    Port Gi0/2 is labeled 'Altn BLK' in the output, meaning it is an alternate port in the blocking state. Alternate ports are backups to the root port and are deliberately placed in blocking to prevent L2 loops, receiving more-superior BPDUs from another neighbor. They do not forward traffic unless the root port fails, so Gi0/2 is not currently forwarding.

  • ✗

    The STP priority for VLAN 10 is 32768.

    Why it's wrong here

    The STP priority for VLAN 10 is displayed as 32778, not 32768, because the bridge ID priority field carries both the configurable base priority (32768) and the extended system ID of 10 for VLAN 10. On PVST+ switches, the 12-bit extended system ID is appended to the 4-bit priority, so the effective numeric priority becomes base + VLAN number. Saying 32768 ignores that VLAN component and misreads the bridge ID that STP uses for root election.

Visual reference

SW1 Root Bridge SW2 SW3 BLK DP DP RP RP STP blocks one link to prevent loops DP = Designated Port RP = Root Port BLK = Blocked

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.