Courseiva
Network Assurance →hardMultiple Select

350-401 Network Assurance Practice Question

Which THREE are common causes of high CPU utilization on a Cisco Catalyst switch? (Choose three.)

⚠ Common exam trap

Cisco often tests the distinction between control plane (CPU-processed) and data plane (ASIC-switched) traffic; the trap here is assuming hardware switching tasks consume CPU cycles, when in fact they are offloaded to dedicated hardware.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Broadcast storms

Broadcast storms (A) are a classic cause of high CPU utilization on a Catalyst switch because flooded broadcast frames are punted to the CPU for processing and replication to all ports in the VLAN, overwhelming the control plane. Frequent STP topology changes (D) drive high CPU because each TCN forces the switch to recompute the spanning-tree topology, flush MAC address entries, and process BPDUs, consuming significant control-plane cycles. ACL logging with the 'log' keyword (E) is correct because every matching packet is punted to the CPU to generate a syslog message, and a high volume of matches can saturate the CPU. Excessive hardware switching of packets (B) is not a cause of high CPU since hardware (ASIC) switching is designed to forward packets at wire speed without involving the CPU. Low memory conditions (C) affect memory, not CPU utilization, and are not a common cause of high CPU on a Catalyst switch.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Broadcast storms

    Why this is correct

    A broadcast storm floods every port with endlessly circulating frames, forcing the switch CPU to process enormous volumes of broadcast traffic and replicate frames across the broadcast domain. This software-path processing load, rather than normal hardware switching, is what drives control-plane CPU utilisation upward.

  • ✗

    Excessive hardware switching of packets

    Why it's wrong here

    Hardware switching happens in ASICs on the switching fabric, not the route processor, so it does not raise CPU. It is tempting because heavy traffic intuitively suggests processor strain, and would be the answer where packets are punted to the CPU for software forwarding.

  • ✗

    Low memory conditions

    Why it's wrong here

    Low memory triggers allocation failures and process restarts, but memory exhaustion is tracked separately from CPU load and is not a listed cause of sustained high CPU. It is tempting because resource starvation broadly degrades a switch, and would be correct where the question asked about memory-related faults.

  • ✓

    Frequent STP topology changes

    Why this is correct

    Each STP topology change triggers recalculation, flushing MAC address tables and generating TCN BPDUs processed by the CPU. Frequent flapping or unstable links therefore cause repeated reconvergence, a well-known driver of high CPU on Catalyst switches.

  • ✓

    ACL logging with 'log' keyword

    Why this is correct

    ACL logging with the log keyword punts matching packets to the switch's CPU for syslog generation, so high traffic volumes hitting logged entries drive CPU utilisation up sharply. This is a recognised control-plane cause of elevated Catalyst switch CPU.

Visual reference

SW1 Root Bridge SW2 SW3 BLK DP DP RP RP STP blocks one link to prevent loops DP = Designated Port RP = Root Port BLK = Blocked

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.