nerdexam
Cisco

352-001 · Question #430

Refer to the exhibit. The server supports 802.1q and is running multiple VLANs on its NIC. Which two Layer 2 features should be applied to the network location identified by a circle? (Choose 2)

The correct answer is D. PortFast trunk F. BPDU guard. A server running 802.1q trunking connects via a trunk port that should use PortFast trunk for fast transition and BPDU guard to protect against unexpected bridge advertisements.

Layer 2 Control Plane

Question

Refer to the exhibit. The server supports 802.1q and is running multiple VLANs on its NIC. Which two Layer 2 features should be applied to the network location identified by a circle? (Choose 2)

Exhibit

352-001 question #430 exhibit

Options

  • APortFast
  • Bloop guard
  • CBPDU filter
  • DPortFast trunk
  • EUDLD
  • FBPDU guard

How the community answered

(26 responses)
  • A
    4% (1)
  • C
    4% (1)
  • D
    85% (22)
  • E
    8% (2)

Why each option

A server running 802.1q trunking connects via a trunk port that should use PortFast trunk for fast transition and BPDU guard to protect against unexpected bridge advertisements.

APortFast

Standard PortFast is intended for access ports connecting to end hosts; it cannot be applied to trunk ports and would not handle 802.1q-tagged traffic correctly.

Bloop guard

Loop guard prevents a non-designated port from transitioning to forwarding when BPDUs stop arriving, which is a protection for switch-to-switch uplinks, not server-facing trunk ports.

CBPDU filter

BPDU filter suppresses BPDU transmission and reception entirely, which can create STP loops and is considered unsafe on user-facing or server-facing ports.

DPortFast trunkCorrect

PortFast trunk allows a trunk port to bypass the STP listening and learning states, enabling the server's 802.1q-tagged VLANs to become active immediately without a 30-second STP delay. Standard PortFast cannot be applied to trunk ports, making PortFast trunk the correct feature for this interface type.

EUDLD

UDLD detects unidirectional link failures on fiber or copper links and is primarily used on switch-to-switch uplinks, not on a server connection where STP loop protection is the concern.

FBPDU guardCorrect

BPDU guard shuts down the port if any BPDU is received, protecting the STP topology from a misconfigured or rogue device claiming to be a bridge on a port that should only connect to a server.

Concept tested: PortFast trunk and BPDU guard on 802.1q server ports

Source: https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/lanswitch/configuration/xe-16/b_lsw_xe_16_cg/configuring_optional_spanning_tree_features.html

Topics

#PortFast trunk#BPDU guard#802.1q trunking#STP port security

Community Discussion

No community discussion yet for this question.

Full 352-001 Practice