220-1101 Networking Practice Question
A technician connects a new workstation to a managed switch port that is configured with PortFast and BPDU guard. The workstation obtains an IP address via DHCP and can ping its own IP address, but it cannot ping any other devices on the local network, including the default gateway. The link light on both the NIC and switch port is solid green. On the switch, the port status shows 'errdisable' with the reason 'BPDU guard'. Which of the following is the MOST likely cause of this issue?
⚠ Common exam trap
CompTIA often tests the misconception that BPDU guard only applies to switches or that a workstation cannot generate BPDUs, but the trap is that any device (including a workstation with certain NIC drivers or virtualization software) can send BPDUs, triggering the errdisable state.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The workstation's NIC is running Spanning Tree Protocol, which the switch's BPDU guard detected and shut down the port.
BPDU guard is a security feature that disables a PortFast-enabled port if it receives any Bridge Protocol Data Unit (BPDU). A workstation NIC should never send BPDUs, but some NICs or their drivers (e.g., when teaming or virtualization software is active) may inadvertently run Spanning Tree Protocol (STP) and generate BPDUs. When the switch receives a BPDU on a BPDU guard-protected port, it immediately places the port into errdisable state, blocking all traffic except the link light remains solid. This explains why the workstation can obtain an IP (DHCP traffic occurred before the port was disabled) but cannot ping any other devices after the port is errdisabled.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The workstation's firewall is blocking traffic.
Why it's wrong here
Firewalls operate at OSI Layer 3/4 (or higher), filtering packets based on IP addresses, ports, and protocols. They cannot generate or influence Layer 2 bridge protocol data units (BPDUs) that Spanning Tree Protocol uses, nor would they cause a switch to administratively disable a port via errdisable. The errdisable state specifically results from a switch-level protection mechanism, like BPDU guard, which detects an unexpected BPDU on a port configured with PortFast, not from packet filtering on the host. Additionally, a firewall only affects traffic originating or terminating at the host, while BPDU guard triggers on incoming BPDUs regardless of the host's firewall settings.
- ✓
The workstation's NIC is running Spanning Tree Protocol, which the switch's BPDU guard detected and shut down the port.
Why this is correct
Certain network interface cards, especially those with teaming or virtualization features, may have the Spanning Tree Protocol enabled at the driver level by default. A switch port configured with PortFast expects an end device (like a workstation) and assumes no BPDUs will be received. When BPDU guard is also enabled on that port, the switch immediately places the port into errdisable state upon receiving any BPDU, halting all traffic. This behavior is a deliberate protection from loops caused by misconfigured devices, but a workstation NIC generating BPDUs inadvertently triggers it.
- ✗
The switch port is configured as an access port in the wrong VLAN.
Why it's wrong here
An access port configured in the wrong VLAN would still be administratively up and operational; the workstation would simply be in a different broadcast domain than expected, potentially preventing communication with servers or the default gateway. This would not cause the switch port to enter errdisable, which is a disabled state triggered by security or error conditions like BPDU guard, UDLD, or port security violations. The port would remain active, and issues would manifest as Layer 3 connectivity problems, not as a physically blocked port. Additionally, a VLAN mismatch wouldn't generate BPDUs or violate spanning-tree rules.
- ✗
The workstation's NIC has a static IP address that conflicts with another device.
Why it's wrong here
An IP address conflict occurs at Layer 3 when two hosts use the same IP address, causing address resolution confusion and intermittent reachability. This is an IP-level issue that does not generate any Layer 2 control frames such as BPDUs. Switch port errdisable due to BPDU guard is triggered only at Layer 2 by the receipt of a BPDU on a PortFast-enabled port, regardless of IP configuration. Therefore, while an IP conflict might disrupt network services, it cannot place the physical switch port into an error-disabled state.
Visual reference
Go deeper
Related to this question
About these practice questions
This 220-1101 question is part of Courseiva's 896-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1101 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1101 exam.