What core protective capabilities does BPDU Guard provide when securing spanning tree topologies against unauthorized network switches and malicious loops? Furthermore, why is automatically disabling edge ports that receive unexpected bridge protocol data units the single most effective way to preserve Layer 2 architectural stability and enforce robust access-layer security?