Topic 07 Practice Test 3 covers Discovery, EtherChannel, and Rapid PVST+ for Cisco Certified Network Associate 200-301 CCNA and maps to objectives 2.3–2.5. For broader exam preparation, review the Cisco CCNA 200-301 Exam Dumps. Every option includes focused technical reasoning explaining both the networking concept and its fit to the scenario.
Question 1
Cobalt’s documentation asks for Cisco’s proprietary Layer 2 neighbor discovery protocol used to advertise device and interface information to directly connected peers. Which is it? Choose ONE.
- LLDP
- CDP
- LACP
- RSTP
Correct Answer: B
Correct Answer
Answer B is correct because Cisco Discovery Protocol (CDP) is Cisco-proprietary and advertises identity, platform, and port information to directly connected Cisco neighbors. At Cobalt, Cisco discovery verification uses this result. The CDP result at Cobalt therefore meets the acceptance criterion. At Cobalt, the Cisco discovery state is observable afterward.
Incorrect Answers
Answer A is incorrect because Link Layer Discovery Protocol (LLDP) is an IEEE vendor-neutral discovery protocol and is preferable in multivendor environments, but it is not Cisco’s proprietary mechanism. At Cobalt, Cisco discovery verification uses this result. The LLDP result at Cobalt therefore misses the acceptance criterion. At Cobalt, the Cisco discovery state is observable afterward.
Answer C is incorrect because Link Aggregation Control Protocol (LACP) negotiates EtherChannel membership and does not perform general neighbor discovery. At Cobalt, Cisco discovery verification uses this result. The LACP result at Cobalt therefore misses the acceptance criterion. At Cobalt, the Cisco discovery state is observable afterward.
Answer D is incorrect because Rapid Spanning Tree Protocol (RSTP) prevents Layer 2 loops and elects spanning-tree roles; it is not used to inventory adjacent devices. At Cobalt, Cisco discovery verification uses this result. The RSTP result at Cobalt therefore misses the acceptance criterion. At Cobalt, the Cisco discovery state is observable afterward.
Question 2
Falcon’s design standard calls for IEEE 802.1AB discovery across Cisco and non-Cisco devices. Which protocol satisfies that requirement? Choose ONE.
- DTP
- CDP
- LLDP
- PAgP
Correct Answer: C
Correct Answer
Answer C is correct because LLDP is the IEEE 802.1AB standards-based neighbor discovery protocol and is designed to exchange device and port information across vendor boundaries. At Falcon, multivendor discovery verification uses this result. The LLDP result at Falcon therefore meets the acceptance criterion. At Falcon, the multivendor discovery state is observable afterward.
Incorrect Answers
Answer B is incorrect because CDP is useful between Cisco devices but is Cisco-proprietary, so it is not the standards-based choice required for a multivendor link. At Falcon, multivendor discovery verification uses this result. The CDP result at Falcon therefore misses the acceptance criterion. At Falcon, the multivendor discovery state is observable afterward.
Answer A is incorrect because Dynamic Trunking Protocol (DTP) negotiates switchport trunking and does not advertise general neighbor inventory information. At Falcon, multivendor discovery verification uses this result. The DTP result at Falcon therefore misses the acceptance criterion. At Falcon, the multivendor discovery state is observable afterward.
Answer D is incorrect because Port Aggregation Protocol (PAgP) is a Cisco-proprietary EtherChannel negotiation protocol rather than a general discovery protocol. At Falcon, multivendor discovery verification uses this result. The PAgP result at Falcon therefore misses the acceptance criterion. At Falcon, the multivendor discovery state is observable afterward.
Question 3
Ion’s audit requires detailed CDP information rather than the concise neighbor table. Which command provides expanded per-neighbor data? Choose ONE.
- show etherchannel summary
- show spanning-tree
- show lldp traffic
- show cdp neighbors detail
Correct Answer: D
Correct Answer
Answer D is correct because `show cdp neighbors detail` expands CDP neighbor information and commonly includes management addressing plus platform, interface, and capability details. At Ion, CDP detail verification uses this result. The show cdp result at Ion therefore meets the acceptance criterion. At Ion, the CDP detail state is observable afterward.
Incorrect Answers
Answer C is incorrect because `show lldp traffic` focuses on LLDP message counters and does not provide the requested detailed CDP neighbor record. At Ion, CDP detail verification uses this result. The show lldp result at Ion therefore misses the acceptance criterion. At Ion, the CDP detail state is observable afterward.
Answer A is incorrect because `show etherchannel summary` reports port-channel membership and state, not CDP management addressing for an adjacent device. At Ion, CDP detail verification uses this result. The show etherchannel result at Ion therefore misses the acceptance criterion. At Ion, the CDP detail state is observable afterward.
Answer B is incorrect because `show spanning-tree` reports spanning-tree topology and port roles rather than detailed device discovery information. At Ion, CDP detail verification uses this result. The show spanning-tree result at Ion therefore misses the acceptance criterion. At Ion, the CDP detail state is observable afterward.
Question 4
Orchid’s design review identifies IEEE 802.1AX/802.3ad-style link aggregation negotiation as a requirement. Which Cisco feature matches it? Choose ONE.
- PAgP
- DTP
- CDP
- LACP
Correct Answer: D
Correct Answer
Answer D is correct because LACP is the standards-based Link Aggregation Control Protocol used to negotiate and maintain bundled links in an EtherChannel. At Orchid, LACP standard verification uses this result. The LACP result at Orchid therefore meets the acceptance criterion. At Orchid, the LACP standard state is observable afterward.
Incorrect Answers
Answer A is incorrect because PAgP can negotiate an EtherChannel on Cisco equipment, but it is Cisco-proprietary and therefore does not meet the standards-based requirement. At Orchid, LACP standard verification uses this result. The PAgP result at Orchid therefore misses the acceptance criterion. At Orchid, the LACP standard state is observable afterward.
Answer B is incorrect because DTP negotiates Layer 2 trunk mode and is independent of whether parallel links are bundled into an EtherChannel. At Orchid, LACP standard verification uses this result. The DTP result at Orchid therefore misses the acceptance criterion. At Orchid, the LACP standard state is observable afterward.
Answer C is incorrect because CDP discovers directly connected Cisco devices but does not negotiate aggregate link membership. At Orchid, LACP standard verification uses this result. The CDP result at Orchid therefore misses the acceptance criterion. At Orchid, the LACP standard state is observable afterward.
Question 5
Redwood documents a valid LACP pair where only one side initiates LACP messages. Which mode combination is correct? Choose ONE.
- on on one side and passive on the other
- active on one side and passive on the other
- passive on both sides
- auto on one side and desirable on the other
Correct Answer: B
Correct Answer
Answer B is correct because An LACP active interface initiates negotiation, while a passive interface responds; active/passive is therefore a valid LACP pairing. At Redwood, active passive LACP verification uses this result. The active on result at Redwood therefore meets the acceptance criterion. At Redwood, the active passive LACP state is observable afterward.
Incorrect Answers
Answer C is incorrect because Two passive LACP interfaces wait for the peer to initiate, so negotiation does not begin and the bundle will not form through LACP. At Redwood, active passive LACP verification uses this result. The passive on result at Redwood therefore misses the acceptance criterion. At Redwood, the active passive LACP state is observable afterward.
Answer D is incorrect because `auto` and `desirable` are PAgP modes, not LACP modes, so that pair does not satisfy an LACP requirement. At Redwood, active passive LACP verification uses this result. The auto on result at Redwood therefore misses the acceptance criterion. At Redwood, the active passive LACP state is observable afterward.
Answer A is incorrect because Static `on` does not negotiate with LACP; mixing static-on behavior with LACP passive does not create the intended negotiated bundle. At Redwood, active passive LACP verification uses this result. The on on result at Redwood therefore misses the acceptance criterion. At Redwood, the active passive LACP state is observable afterward.
Question 6
Aster wants to explain why passive/passive does not create an LACP EtherChannel. Which statement is correct? Choose ONE.
- Configure a native VLAN on the port-channel
- Change at least one side to LACP active
- Enable PortFast on all members
- Change both sides to PAgP auto
Correct Answer: B
Correct Answer
Answer B is correct because At least one side must be LACP active so negotiation is initiated; the other side may remain passive and respond. At Aster, passive LACP verification uses this result. The Change at result at Aster therefore meets the acceptance criterion. At Aster, the passive LACP state is observable afterward.
Incorrect Answers
Answer D is incorrect because PAgP auto is a different aggregation protocol and changing both sides to auto would still leave both peers waiting rather than meeting the LACP design. At Aster, passive LACP verification uses this result. The Change both result at Aster therefore misses the acceptance criterion. At Aster, the passive LACP state is observable afterward.
Answer C is incorrect because PortFast affects spanning-tree behavior and does not cause passive LACP peers to initiate link-aggregation negotiation. At Aster, passive LACP verification uses this result. The Enable PortFast result at Aster therefore misses the acceptance criterion. At Aster, the passive LACP state is observable afterward.
Answer A is incorrect because A native VLAN may matter on a trunked port-channel but it has no role in starting LACP negotiation between two passive endpoints. At Aster, passive LACP verification uses this result. The Configure a result at Aster therefore misses the acceptance criterion. At Aster, the passive LACP state is observable afterward.
Question 7
Delta’s change standard requires all physical links in a Layer 2 EtherChannel to be compatible. Which principle is most important when adding another member? Choose ONE.
- Configure independent IP addresses on every Layer 2 member
- Assign a different access VLAN to each member for load balancing
- Give each member a different native VLAN to identify it
- Make the member interface Layer 2 settings consistent with the rest of the bundle
Correct Answer: D
Correct Answer
Answer D is correct because EtherChannel members must have compatible Layer 2 characteristics such as switchport mode and VLAN parameters; inconsistent configuration can prevent or suspend bundling. At Delta, member consistency verification uses this result. The Make the result at Delta therefore meets the acceptance criterion. At Delta, the member consistency state is observable afterward.
Incorrect Answers
Answer C is incorrect because Using different native VLANs on members creates inconsistent trunk behavior and is not a valid way to identify or load-balance EtherChannel links. At Delta, member consistency verification uses this result. The Give each result at Delta therefore misses the acceptance criterion. At Delta, the member consistency state is observable afterward.
Answer B is incorrect because Different access VLANs on members are incompatible with a single logical Layer 2 port-channel and can prevent the interfaces from joining correctly. At Delta, member consistency verification uses this result. The Assign a result at Delta therefore misses the acceptance criterion. At Delta, the member consistency state is observable afterward.
Answer A is incorrect because Layer 2 EtherChannel members do not each receive independent routed IP addresses; Layer 3 addressing belongs on the port-channel interface when building a routed channel. At Delta, member consistency verification uses this result. The Configure independent result at Delta therefore misses the acceptance criterion. At Delta, the member consistency state is observable afterward.
Question 8
Granite wants the aggregate to act as one logical Layer 2 link. Which interface should hold the shared trunk configuration? Choose ONE.
- Every member with intentionally different VLAN lists
- The Port-channel interface
- Only the lowest-numbered physical member
- The switch’s management SVI
Correct Answer: B
Correct Answer
Answer B is correct because The Port-channel is the logical interface for the bundle, so shared Layer 2 trunk policy should be applied consistently to that logical interface rather than creating member mismatches. At Granite, logical port-channel verification uses this result. The The Port-channel result at Granite therefore meets the acceptance criterion. At Granite, the logical port-channel state is observable afterward.
Incorrect Answers
Answer C is incorrect because Applying policy only to one physical link can leave the aggregate members inconsistent and does not represent the bundle as one logical link. At Granite, logical port-channel verification uses this result. The Only the result at Granite therefore misses the acceptance criterion. At Granite, the logical port-channel state is observable afterward.
Answer A is incorrect because Intentionally different VLAN lists defeat member consistency and can prevent correct EtherChannel operation. At Granite, logical port-channel verification uses this result. The Every member result at Granite therefore misses the acceptance criterion. At Granite, the logical port-channel state is observable afterward.
Answer D is incorrect because An SVI provides Layer 3 service for a VLAN and is unrelated to configuring the trunk behavior of the EtherChannel itself. At Granite, logical port-channel verification uses this result. The The switch’s result at Granite therefore misses the acceptance criterion. At Granite, the logical port-channel state is observable afterward.
Question 9
Juniper verifies a Layer 3 EtherChannel design. Which logical interface should carry the IP address after the physical members operate as routed channel members? Choose ONE.
- Configure `no switchport` as appropriate and put the IP address on the Port-channel interface
- Use `switchport trunk native vlan` as the Layer 3 address
- Keep the members as access ports and put the IP address on VLAN 1
- Place a different IP address on every physical member
Correct Answer: A
Correct Answer
Answer A is correct because A routed EtherChannel operates as one logical Layer 3 interface; the port-channel is configured for routed operation and carries the IP address for the aggregate. At Juniper, routed EtherChannel verification uses this result. The Configure no result at Juniper therefore meets the acceptance criterion. At Juniper, the routed EtherChannel state is observable afterward.
Incorrect Answers
Answer D is incorrect because Independent addresses on physical members treat them as separate Layer 3 links rather than one logical EtherChannel and conflict with the intended aggregate interface. At Juniper, routed EtherChannel verification uses this result. The Place a result at Juniper therefore misses the acceptance criterion. At Juniper, the routed EtherChannel state is observable afterward.
Answer C is incorrect because An access-port/VLAN 1 design is Layer 2 switching and does not create the requested routed point-to-point port-channel. At Juniper, routed EtherChannel verification uses this result. The Keep the result at Juniper therefore misses the acceptance criterion. At Juniper, the routed EtherChannel state is observable afterward.
Answer B is incorrect because A native-VLAN command configures 802.1Q trunk behavior and is unrelated to assigning a Layer 3 IP address to a routed EtherChannel. At Juniper, routed EtherChannel verification uses this result. The Use switchport result at Juniper therefore misses the acceptance criterion. At Juniper, the routed EtherChannel state is observable afterward.
Question 10
Mesa’s acceptance evidence must show the Port-channel plus member-state flags in a summary. Which verification command fits? Choose ONE.
- show interfaces trunk
- show spanning-tree root
- show cdp traffic
- show etherchannel summary
Correct Answer: D
Correct Answer
Answer D is correct because `show etherchannel summary` presents port-channel groups, protocols, logical-channel state, and member-interface flags, making it the direct bundle-verification command. At Mesa, EtherChannel summary verification uses this result. The show etherchannel result at Mesa therefore meets the acceptance criterion. At Mesa, the EtherChannel summary state is observable afterward.
Incorrect Answers
Answer A is incorrect because `show interfaces trunk` can show a port-channel if it is trunking, but it does not provide the same member-level EtherChannel negotiation and bundling summary. At Mesa, EtherChannel summary verification uses this result. The show interfaces result at Mesa therefore misses the acceptance criterion. At Mesa, the EtherChannel summary state is observable afterward.
Answer B is incorrect because `show spanning-tree root` focuses on root information and does not identify whether intended physical links are successfully bundled. At Mesa, EtherChannel summary verification uses this result. The show spanning-tree result at Mesa therefore misses the acceptance criterion. At Mesa, the EtherChannel summary state is observable afterward.
Answer C is incorrect because `show cdp traffic` shows discovery-protocol counters rather than EtherChannel member and port-channel state. At Mesa, EtherChannel summary verification uses this result. The show cdp result at Mesa therefore misses the acceptance criterion. At Mesa, the EtherChannel summary state is observable afterward.
Question 11
Pioneer documents the primary criterion Rapid PVST+ uses to select a root bridge. Which answer is correct? Choose ONE.
- The switch with the lowest bridge ID
- The switch with the greatest root-path cost
- The switch with the highest MAC address
- The first switch to boot
Correct Answer: A
Correct Answer
Answer A is correct because Spanning tree elects the root bridge using the lowest bridge ID, which incorporates bridge priority and a MAC-derived component for tie breaking. At Pioneer, root election verification uses this result. The The switch result at Pioneer therefore meets the acceptance criterion. At Pioneer, the root election state is observable afterward.
Incorrect Answers
Answer C is incorrect because A higher MAC address does not win; when priorities tie, the lower bridge identifier component is favored. At Pioneer, root election verification uses this result. The The switch result at Pioneer therefore misses the acceptance criterion. At Pioneer, the root election state is observable afterward.
Answer B is incorrect because Root-path cost is used by non-root switches to select paths toward the elected root, not to elect the root bridge itself. At Pioneer, root election verification uses this result. The The switch result at Pioneer therefore misses the acceptance criterion. At Pioneer, the root election state is observable afterward.
Answer D is incorrect because Boot order does not define the stable root-election rule; bridge ID comparison determines the elected root. At Pioneer, root election verification uses this result. The The first result at Pioneer therefore misses the acceptance criterion. At Pioneer, the root election state is observable afterward.
Question 12
Summit reviews Rapid PVST+ port roles on a non-root switch. How is its root port selected? Choose ONE.
- Every forwarding port becomes a root port
- The port that most recently received a data frame
- The port with the highest interface number
- The port with the lowest root-path cost toward the root
Correct Answer: D
Correct Answer
Answer D is correct because A non-root switch chooses one root port representing its best path to the root bridge; root-path cost is a primary comparison in that selection process. At Summit, root-port selection verification uses this result. The The port result at Summit therefore meets the acceptance criterion. At Summit, the root-port selection state is observable afterward.
Incorrect Answers
Answer C is incorrect because Interface numbering is not the fundamental spanning-tree path-selection rule and a higher number does not automatically become the root port. At Summit, root-port selection verification uses this result. The The port result at Summit therefore misses the acceptance criterion. At Summit, the root-port selection state is observable afterward.
Answer A is incorrect because A switch has one root port per spanning-tree instance, while other forwarding interfaces can be designated ports. At Summit, root-port selection verification uses this result. The Every forwarding result at Summit therefore misses the acceptance criterion. At Summit, the root-port selection state is observable afterward.
Answer B is incorrect because User data arrival timing does not determine the root-port election; BPDUs and spanning-tree path information do. At Summit, root-port selection verification uses this result. The The port result at Summit therefore misses the acceptance criterion. At Summit, the root-port selection state is observable afterward.
Question 13
Beacon’s training notes need the role elected per segment to advertise the superior path toward the root bridge. Which role is it? Choose ONE.
- Designated port
- Root port
- Alternate port
- Disabled port
Correct Answer: A
Correct Answer
Answer A is correct because The designated port is elected for a Layer 2 segment and represents the best path from that segment toward the root; it normally forwards for that segment. At Beacon, designated-port role verification uses this result. The Designated port result at Beacon therefore meets the acceptance criterion. At Beacon, the designated-port role state is observable afterward.
Incorrect Answers
Answer B is incorrect because The root port is selected on each non-root bridge as that switch’s best path to the root, which is a different role from the per-segment designated port. At Beacon, designated-port role verification uses this result. The Root port result at Beacon therefore misses the acceptance criterion. At Beacon, the designated-port role state is observable afterward.
Answer C is incorrect because An alternate port provides a redundant path and normally remains in a discarding role rather than serving as the segment’s forwarding designated port. At Beacon, designated-port role verification uses this result. The Alternate port result at Beacon therefore misses the acceptance criterion. At Beacon, the designated-port role state is observable afterward.
Answer D is incorrect because A disabled port does not participate in spanning-tree forwarding or election for the segment. At Beacon, designated-port role verification uses this result. The Disabled port result at Beacon therefore misses the acceptance criterion. At Beacon, the designated-port role state is observable afterward.
Question 14
Ember documents the Rapid STP role used for a loop-free backup path to the root through another bridge. Which is it? Choose ONE.
- Root port on the root bridge
- Alternate port
- Designated port
- Edge port only
Correct Answer: B
Correct Answer
Answer B is correct because An alternate port provides a redundant path toward the root and normally remains discarding until it is needed, enabling faster convergence when the active path fails. At Ember, alternate-port role verification uses this result. The Alternate port result at Ember therefore meets the acceptance criterion. At Ember, the alternate-port role state is observable afterward.
Incorrect Answers
Answer C is incorrect because A designated port is the selected forwarding port for a segment and is not the normal description of the blocked backup path in this scenario. At Ember, alternate-port role verification uses this result. The Designated port result at Ember therefore misses the acceptance criterion. At Ember, the alternate-port role state is observable afterward.
Answer D is incorrect because Edge/PortFast status describes an endpoint-facing convergence behavior and is not the spanning-tree role for a redundant infrastructure path. At Ember, alternate-port role verification uses this result. The Edge port result at Ember therefore misses the acceptance criterion. At Ember, the alternate-port role state is observable afterward.
Answer A is incorrect because The root bridge has no root port because it is the destination of root paths; therefore this cannot describe the redundant port shown. At Ember, alternate-port role verification uses this result. The Root port result at Ember therefore misses the acceptance criterion. At Ember, the alternate-port role state is observable afterward.
Question 15
Harbor reviews a port transition in Rapid PVST+ and must distinguish its state names from port roles. Which state set is valid? Choose ONE.
- Down, testing, standby
- Active, passive, on
- Blocking, listening, learning, forwarding, disabled
- Discarding, learning, forwarding
Correct Answer: D
Correct Answer
Answer D is correct because Rapid STP consolidates non-forwarding behavior into discarding and uses the operational states discarding, learning, and forwarding. At Harbor, RSTP states verification uses this result. The Discarding, learning, result at Harbor therefore meets the acceptance criterion. At Harbor, the RSTP states state is observable afterward.
Incorrect Answers
Answer C is incorrect because The five-state blocking/listening/learning/forwarding/disabled model is associated with classic 802.1D terminology rather than the simplified Rapid STP state set. At Harbor, RSTP states verification uses this result. The Blocking, listening, result at Harbor therefore misses the acceptance criterion. At Harbor, the RSTP states state is observable afterward.
Answer B is incorrect because Active, passive, and on are link-aggregation negotiation/configuration terms, not Rapid PVST+ port states. At Harbor, RSTP states verification uses this result. The Active, passive, result at Harbor therefore misses the acceptance criterion. At Harbor, the RSTP states state is observable afterward.
Answer A is incorrect because Down, testing, and standby are not the standardized Rapid STP forwarding-state names used to describe convergence. At Harbor, RSTP states verification uses this result. The Down, testing, result at Harbor therefore misses the acceptance criterion. At Harbor, the RSTP states state is observable afterward.
Question 16
Keystone’s access-layer standard designates printer and workstation ports as edge ports. Which Cisco feature provides rapid forwarding for those links? Choose ONE.
- LACP passive
- PortFast
- Loop Guard
- Root Guard
Correct Answer: B
Correct Answer
Answer B is correct because PortFast treats an interface as an edge port and allows it to transition rapidly to forwarding, which is appropriate for ports known to connect only to endpoints. At Keystone, PortFast edge verification uses this result. The PortFast result at Keystone therefore meets the acceptance criterion. At Keystone, the PortFast edge state is observable afterward.
Incorrect Answers
Answer D is incorrect because Root Guard protects root placement by blocking a port that receives superior BPDUs; it does not primarily accelerate endpoint-port forwarding. At Keystone, PortFast edge verification uses this result. The Root Guard result at Keystone therefore misses the acceptance criterion. At Keystone, the PortFast edge state is observable afterward.
Answer C is incorrect because Loop Guard protects against certain unidirectional or missing-BPDU conditions on non-designated paths and is not the edge-port acceleration feature. At Keystone, PortFast edge verification uses this result. The Loop Guard result at Keystone therefore misses the acceptance criterion. At Keystone, the PortFast edge state is observable afterward.
Answer A is incorrect because LACP passive is an EtherChannel negotiation mode and has no role in Rapid PVST+ edge-port convergence. At Keystone, PortFast edge verification uses this result. The LACP passive result at Keystone therefore misses the acceptance criterion. At Keystone, the PortFast edge state is observable afterward.
Question 17
Northstar’s campus standard requires edge ports to fail closed when BPDUs appear. Which feature implements that policy? Choose ONE.
- Root Guard
- BPDU Filter
- BPDU Guard
- Loop Guard
Correct Answer: C
Correct Answer
Answer C is correct because BPDU Guard protects edge/PortFast ports by placing the interface into an error-disabled condition when BPDUs are received, preventing an unexpected switch from joining the topology. At Northstar, BPDU Guard verification uses this result. The BPDU Guard result at Northstar therefore meets the acceptance criterion. At Northstar, the BPDU Guard state is observable afterward.
Incorrect Answers
Answer B is incorrect because BPDU Filter suppresses or filters BPDU transmission/reception depending on how it is configured; it is not the same fail-closed BPDU-reception behavior described. At Northstar, BPDU Guard verification uses this result. The BPDU Filter result at Northstar therefore misses the acceptance criterion. At Northstar, the BPDU Guard state is observable afterward.
Answer A is incorrect because Root Guard puts a port into root-inconsistent when superior BPDUs threaten root placement, rather than generally err-disabling an edge port on any BPDU. At Northstar, BPDU Guard verification uses this result. The Root Guard result at Northstar therefore misses the acceptance criterion. At Northstar, the BPDU Guard state is observable afterward.
Answer D is incorrect because Loop Guard protects against a blocked/root path incorrectly transitioning because expected BPDUs stop arriving, not against a new switch sending a BPDU on an edge port. At Northstar, BPDU Guard verification uses this result. The Loop Guard result at Northstar therefore misses the acceptance criterion. At Northstar, the BPDU Guard state is observable afterward.
Question 18
Quartz wants to preserve the intended root location while still permitting normal BPDUs on a downstream switch link. Which protection is appropriate? Choose ONE.
- PortFast
- Root Guard
- Loop Guard
- BPDU Guard
Correct Answer: B
Correct Answer
Answer B is correct because Root Guard allows normal spanning-tree participation but places the port in root-inconsistent if superior BPDUs would cause that port to become a path toward an unauthorized root. At Quartz, Root Guard verification uses this result. The Root Guard result at Quartz therefore meets the acceptance criterion. At Quartz, the Root Guard state is observable afterward.
Incorrect Answers
Answer D is incorrect because BPDU Guard is normally used to protect edge ports and reacts to BPDU receipt by err-disabling the interface rather than enforcing root placement on a downstream switch link. At Quartz, Root Guard verification uses this result. The BPDU Guard result at Quartz therefore misses the acceptance criterion. At Quartz, the Root Guard state is observable afterward.
Answer C is incorrect because Loop Guard protects against loss of expected BPDUs on alternate/root paths; it is not designed to reject a downstream device that advertises a superior root. At Quartz, Root Guard verification uses this result. The Loop Guard result at Quartz therefore misses the acceptance criterion. At Quartz, the Root Guard state is observable afterward.
Answer A is incorrect because PortFast accelerates edge-port forwarding and should not be used as the mechanism for preventing a downstream switch from becoming root. At Quartz, Root Guard verification uses this result. The PortFast result at Quartz therefore misses the acceptance criterion. At Quartz, the Root Guard state is observable afterward.
Question 19
Tundra’s design needs protection against a non-designated/root path erroneously moving to forwarding when BPDU reception ceases. Which feature fits? Choose ONE.
- Root Guard
- BPDU Guard
- PortFast
- Loop Guard
Correct Answer: D
Correct Answer
Answer D is correct because Loop Guard monitors ports that should continue receiving BPDUs and can place them into a loop-inconsistent state rather than allowing an unsafe forwarding transition when BPDUs disappear. At Tundra, Loop Guard verification uses this result. The Loop Guard result at Tundra therefore meets the acceptance criterion. At Tundra, the Loop Guard state is observable afterward.
Incorrect Answers
Answer A is incorrect because Root Guard reacts to superior BPDUs that threaten root placement, which is a different failure condition from losing expected BPDUs on a redundant path. At Tundra, Loop Guard verification uses this result. The Root Guard result at Tundra therefore misses the acceptance criterion. At Tundra, the Loop Guard state is observable afterward.
Answer B is incorrect because BPDU Guard is commonly applied to edge ports and reacts when BPDUs are received, the opposite trigger from the missing-BPDU condition described. At Tundra, Loop Guard verification uses this result. The BPDU Guard result at Tundra therefore misses the acceptance criterion. At Tundra, the Loop Guard state is observable afterward.
Answer C is incorrect because PortFast accelerates edge convergence and does not provide the missing-BPDU protection required for an infrastructure redundancy path. At Tundra, Loop Guard verification uses this result. The PortFast result at Tundra therefore misses the acceptance criterion. At Tundra, the Loop Guard state is observable afterward.
Question 20
Cobalt’s review distinguishes BPDU Filter from BPDU Guard. Which statement best describes why indiscriminate BPDU filtering on network links is risky? Choose ONE.
- It automatically forms an EtherChannel with the neighbor
- Suppressing BPDUs can hide topology information and permit a Layer 2 loop
- It forces the local switch to become the root on every VLAN
- It encrypts BPDUs and breaks CDP only
Correct Answer: B
Correct Answer
Answer B is correct because Spanning tree depends on BPDU exchange to calculate a loop-free topology; suppressing BPDUs on infrastructure links can hide redundant paths and allow forwarding loops. At Cobalt, BPDU Filter verification uses this result. The Suppressing BPDUs result at Cobalt therefore meets the acceptance criterion. At Cobalt, the BPDU Filter state is observable afterward.
Incorrect Answers
Answer C is incorrect because BPDU filtering does not deterministically force a switch to become root; root election still depends on bridge information seen by participating devices. At Cobalt, BPDU Filter verification uses this result. The It forces result at Cobalt therefore misses the acceptance criterion. At Cobalt, the BPDU Filter state is observable afterward.
Answer A is incorrect because BPDU Filter has no EtherChannel negotiation function and cannot form a link-aggregation bundle. At Cobalt, BPDU Filter verification uses this result. The It automatically result at Cobalt therefore misses the acceptance criterion. At Cobalt, the BPDU Filter state is observable afterward.
Answer D is incorrect because BPDU filtering concerns spanning-tree control messages; it does not encrypt BPDUs or operate as a CDP-specific security mechanism. At Cobalt, BPDU Filter verification uses this result. The It encrypts result at Cobalt therefore misses the acceptance criterion. At Cobalt, the BPDU Filter state is observable afterward.