Where is it best to deploy the root guard?

IT Exam Items RepositoryCategory: CCNP ENCOR v9Where is it best to deploy the root guard?

Where is it best to deploy the root guard?

  • Only access ports.
  • Ports that connect to switches that are root bridge.
  • All ports connecting switches.
  • Ports that connect to switches that should not be the root bridge.

Explanation: Root guard is a critical security feature used in Spanning Tree Protocol (STP) to prevent unauthorized or rogue switches from becoming the root bridge and disrupting the network hierarchy. It is best deployed toward ports that connect to switches that should not be the root bridge, as this allows administrators to strictly enforce the intended placement of the root bridge across the campus design. When a port with root guard enabled receives a superior BPDU—one indicating a better bridge ID than the current root—the switch ignores the BPDU and places the interface into a root-inconsistent state, effectively blocking all data traffic to prevent the topology from changing. This mechanism ensures that even if a network attacker or a misconfigured device attempts to claim the root role, the primary traffic paths remain stable and predictable, protecting the network from potential man-in-the-middle attacks or loop-induced downtime.

Related exam: Modules 1 – 7: Checkpoint Exam: Network Switching Answers (CCNP ENCOR v9)