nerdexam
Cisco

352-001 · Question #454

Refer to the exhibit. Which two Layer 2 features should be applied to the network location identified by a circle? (Choose two)

The correct answer is B. PortFast F. BPDU guard. PortFast and BPDU guard are applied together on access ports facing end hosts to enable immediate forwarding and prevent unauthorized switch connections.

Layer 2 Control Plane

Question

Refer to the exhibit. Which two Layer 2 features should be applied to the network location identified by a circle? (Choose two)

Options

  • AUDLC
  • BPortFast
  • CPortFast trunk
  • DBPDU filter
  • Eloop guard
  • FBPDU guard

How the community answered

(51 responses)
  • B
    86% (44)
  • C
    2% (1)
  • D
    8% (4)
  • E
    4% (2)

Why each option

PortFast and BPDU guard are applied together on access ports facing end hosts to enable immediate forwarding and prevent unauthorized switch connections.

AUDLC

UDLD detects unidirectional link failures on fiber and copper uplinks between switches; it is not applicable to access ports connecting end devices.

BPortFastCorrect

PortFast bypasses the STP listening and learning states on a port connected to an end device, allowing it to transition directly to forwarding and eliminating unnecessary 30-second delays for hosts that will never introduce a bridging loop.

CPortFast trunk

PortFast trunk is designed for trunk ports on servers or hypervisors that must carry multiple VLANs without STP delays, not for standard access ports facing end hosts.

DBPDU filter

BPDU filter silently discards BPDUs in both directions, which can mask topology issues and create loops; BPDU guard is the safe, recommended alternative for access ports.

Eloop guard

Loop guard protects root and designated ports on switch-to-switch links from going into a designated role due to a unidirectional failure; it is not intended for end-device access ports.

FBPDU guardCorrect

BPDU guard complements PortFast by placing the port in err-disabled state the moment any BPDU is received, protecting the STP topology from unauthorized switches or hubs plugged into what should be an end-device-only port.

Concept tested: STP PortFast and BPDU guard on end-host access ports

Source: https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst9300/software/release/17-x/configuration_guide/lyr2/b_173_lyr2_9300_cg/configuring_optional_spanning_tree_features.html

Topics

#PortFast#BPDU guard#STP#access port

Community Discussion

No community discussion yet for this question.

Full 352-001 Practice