Courseiva
hardMultiple Choice

350-401 Practice Question: An engineer is configuring a new access switch…

An engineer is configuring a new access switch that connects to two distribution switches via trunk links. The distribution switches are configured with Rapid PVST+ and are both running as root bridges for different VLANs. The engineer wants to ensure that the access switch does not become the root bridge for any VLAN, even if the distribution switches fail. The engineer also wants to prevent any unauthorized switch from becoming root. What configuration should the engineer apply on the access switch?

⚠ Common exam trap

Cisco often tests the distinction between Root Guard and BPDU Guard, where candidates mistakenly apply BPDU Guard (which shuts down ports receiving any BPDU) instead of Root Guard (which specifically protects the root bridge election) on trunk links.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure 'spanning-tree vlan 1-4094 priority 61440' and enable Root Guard on the uplink ports.

Setting the spanning-tree priority to 61440 (the highest possible value) ensures the access switch will never become the root bridge, even if the current root bridges fail. Enabling Root Guard on the uplink ports prevents any unauthorized switch from becoming root by placing the port into a root-inconsistent state if a superior BPDU is received, thus protecting the root bridge election.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Configure 'spanning-tree vlan 1-4094 priority 61440' and enable Root Guard on the uplink ports.

    Why this is correct

    Setting the bridge priority to 61440, the maximum valid value, makes this switch the least preferred candidate in the root bridge election, so it can never assume the root role. Enabling Root Guard on the uplink ports monitors incoming BPDUs and places any port receiving a superior BPDU into a root-inconsistent state, blocking that path and preserving the current root. Together, these actions ensure the switch stays as a non-root and remains resilient against an unauthorized switch attempting to claim root.

  • ✗

    Configure 'spanning-tree vlan 1-4094 priority 0' and enable BPDU Guard on the uplink ports.

    Why it's wrong here

    A priority of 0 gives the switch the lowest possible bridge ID, making it the top-priority candidate to become the root bridge, which directly violates the goal of never becoming root. BPDU Guard is meant for edge/access ports that should never receive BPDUs; applying it to uplink trunks causes those links to be error-disabled whenever the distribution switch sends normal BPDUs, resulting in a loss of upstream connectivity. This configuration is therefore fundamentally wrong for protecting the spanning-tree topology.

  • ✗

    Configure 'spanning-tree vlan 1-4094 priority 4096' and enable Loop Guard on the uplink ports.

    Why it's wrong here

    Priority 4096 is still a relatively low value and would place this switch high in the root election order; if the current root fails or is removed, this switch could easily be elected as root. Loop Guard does not influence root election at all—it only detects unidirectional links by blocking a port that stops receiving BPDUs. Consequently, the switch remains vulnerable to becoming root, and the loop protection provided is irrelevant to the stated requirement.

  • ✗

    Configure 'spanning-tree vlan 1-4094 priority 61440' and enable BPDU Guard on the uplink ports.

    Why it's wrong here

    While priority 61440 correctly prevents the switch from being selected as root in normal circumstances, pairing it with BPDU Guard is a mistake. BPDU Guard aggressively disables any port that receives a BPDU, and since uplink trunks constantly exchange BPDUs with distribution switches, those ports will immediately enter an error-disabled state, severing the switch's path to the root. Root Guard, not BPDU Guard, should be used on trunks because it selectively blocks only superior BPDUs instead of all BPDUs, preserving normal spanning-tree operation.

Visual reference

SW1 Root Bridge SW2 SW3 BLK DP DP RP RP STP blocks one link to prevent loops DP = Designated Port RP = Root Port BLK = Blocked

About these practice questions

This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on 350-401

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A network engineer is configuring a new switch that will be used as an access layer switch. The switch connects to two distribution switches via trunk links. The engineer wants to ensure that the access switch does not become the root bridge for any VLAN. The engineer also wants to provide redundancy so that if one uplink fails, the other uplink takes over quickly. The engineer is using Rapid PVST+. What configuration should the engineer apply on the access switch?

easy
  • ✓ A.Configure 'spanning-tree vlan vlan-list priority 61440' on the access switch.
  • B.Configure 'spanning-tree vlan vlan-list priority 0' on the access switch.
  • C.Enable UplinkFast on the access switch to provide fast failover.
  • D.Enable PortFast on the trunk ports to speed up convergence.

Why A: Setting the spanning-tree priority to 61440 (which is 0xF000 in hex) makes the switch a very unlikely root bridge candidate. In Rapid PVST+, the bridge priority is a 4-bit value (0-15) multiplied by 4096, so 61440 corresponds to priority 15 — the highest possible value. This ensures the access switch will never become the root bridge for any VLAN, while Rapid PVST+ provides fast failover (sub-second convergence) via its alternate/backup port mechanism without needing UplinkFast.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.