Courseiva
mediumMultiple Choice

350-401 Practice Question: Is troubleshooting a Layer 2 loop that occurred…

A network engineer is troubleshooting a Layer 2 loop that occurred in a network using Rapid PVST+. The network has three switches: SW1 (root), SW2, and SW3. The engineer examines the topology and finds that SW2 and SW3 are connected via a link that is not supposed to be there. The engineer suspects that an unauthorized switch was connected to the network, causing the loop. The engineer wants to prevent such loops in the future by configuring a feature that will disable any port that receives a BPDU from an unauthorized switch. Which feature should the engineer configure on the access ports?

⚠ Common exam trap

Cisco often tests the distinction between BPDU Guard and Root Guard, where candidates mistakenly choose Root Guard because they think it protects against unauthorized switches, but Root Guard only prevents a port from becoming root, not from receiving BPDUs and causing loops.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable BPDU Guard on all access ports.

BPDU Guard is the correct feature because it immediately error-disables a port when a BPDU is received, preventing loops from unauthorized switches. Since the engineer wants to protect access ports from receiving BPDUs (which should never occur on a properly configured access port), BPDU Guard directly addresses the scenario of an unauthorized switch being connected and sending BPDUs.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Enable BPDU Guard on all access ports.

    Why this is correct

    BPDU Guard is the correct choice because it actively shuts down the port by placing it into an errdisable state whenever any BPDU is received on an access port. Since access ports should never receive BPDUs from an end host, a received BPDU indicates an unauthorized switch attempting to participate in spanning tree, and BPDU Guard immediately blocks that port to preserve the intended STP topology and prevent potential loops.

  • ✗

    Enable Loop Guard on all access ports.

    Why it's wrong here

    Loop Guard is incorrect because it is designed to detect the absence of BPDUs on a port that is expected to receive them, typically a root port or designated port, and then transition the port to a loop-inconsistent state. It does not take action on receiving a BPDU; rather, it prevents alternate paths from forwarding when BPDUs are lost due to unidirectional link failures, so it cannot block an unauthorized switch that actively sends BPDUs.

  • ✗

    Enable Root Guard on all access ports.

    Why it's wrong here

    Root Guard is incorrect because it only protects the placement of the root bridge by placing a port into a root-inconsistent state when a superior BPDU is received, preventing that port from becoming a root port. The port remains administratively up and still processes BPDUs; it simply stops forwarding on that port while the superior BPDU is present, which does not disable the port or permanently block an unauthorized switch from causing a loop.

  • ✗

    Enable UDLD on all access ports.

    Why it's wrong here

    UDLD is incorrect because it addresses physical unidirectional links by exchanging protocol frames with the neighbor and, upon a missing acknowledgment, either errdisables the interface or reports an undetermined state. It does not examine BPDUs and has no mechanism to detect or prevent a rogue switch from injecting BPDUs into the spanning tree, so it is irrelevant to the scenario of an unauthorized switch causing a loop.

Visual reference

SW1 Root Bridge SW2 SW3 BLK DP DP RP RP STP blocks one link to prevent loops DP = Designated Port RP = Root Port BLK = Blocked

About these practice questions

Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.