mediumMultiple Choice
350-401 Practice Question: Interface GigabitEthernet0/1 spanning-tree…
interface GigabitEthernet0/1 spanning-tree portfast spanning-tree bpduguard enable
end
What is the effect of this configuration?
⚠ Common exam trap
Cisco often tests the misconception that BPDUguard ignores BPDUs or that PortFast still goes through STP states, but the key trap is that BPDUguard error-disables the port upon BPDU reception, not just ignores or blocks it.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The port will immediately transition to forwarding state and will be error-disabled if a BPDU is received.
The `spanning-tree portfast` command causes the port to immediately transition to the forwarding state, bypassing the listening and learning states. The `spanning-tree bpduguard enable` command places the port in an error-disabled state if any BPDU is received, as BPDU reception on a PortFast-enabled port indicates an unauthorized switch connection, which could cause a bridging loop.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The port will immediately transition to forwarding state and will be error-disabled if a BPDU is received.
Why this is correct
Enabling PortFast on a switchport causes it to bypass the STP listening and learning states and transition directly to forwarding, which is appropriate for host-facing access ports. If BPDU Guard is also enabled on that port, any received BPDU—which should never arrive from an end host—is treated as a misconfiguration, and the port is immediately placed into the error-disabled state. This protects the access domain from accidental loops or rogue switch connections, and the port stays in error-disable until manual intervention or an errdisable recovery timer is configured.
- ✗
The port will go through normal STP states and will be error-disabled if a BPDU is received.
Why it's wrong here
This option incorrectly assumes PortFast preserves the usual STP state machine, but PortFast's entire purpose is to eliminate the 15-second listening and 15-second learning delays by skipping straight to forwarding. A normal STP port would indeed transition through blocking, listening, learning, and forwarding over many seconds, and BPDU Guard would still error-disable it upon receiving a BPDU. However, because PortFast is configured, the port does not go through normal states; the combination described here is not what PortFast does.
- ✗
The port will immediately transition to forwarding and ignore any BPDUs received.
Why it's wrong here
PortFast unconditionally forwards, but it does not cause BPDUs to be ignored—BPDU Guard actually inspects every BPDU arriving on that port. If a BPDU is received, the correct reaction is to move the port to error-disabled mode, not to silently discard the BPDU. Ignoring BPDUs is the behavior of BPDU Filtering, a separate feature that disables STP processing and can actually hide real topology loops, which is why BPDU Guard is the safer and more common access-port safeguard.
- ✗
The port will remain in blocking state until a BPDU is received.
Why it's wrong here
PortFast never places a port into blocking; instead, it flips the port directly into the forwarding state immediately on link-up. A port would remain in blocking only in the normal STP listening/discarding process, and BPDU Guard's response to an unexpected BPDU is to error-disable the port, not to revert to blocking. Since the scenario enables PortFast, the expected behavior is immediate forwarding, and any claim that blocking persists until a BPDU arrives is simply incompatible with PortFast's operational semantics.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.