20+ practice questions focused on ACLs and CoPP — one of the most tested topics on the ENCOR 350-401 exam. Each question includes a detailed explanation so you learn why the right answer is correct.
Start ACLs and CoPP PracticeA network engineer is troubleshooting an issue where SSH access to a Cisco router from a specific management subnet (10.10.10.0/24) is intermittently failing. The router has a CoPP policy applied to the control plane. The engineer checks the CoPP statistics and sees that packets from the management subnet are being dropped by the control-plane service-policy. Which configuration change should the engineer make to allow SSH from the management subnet while still protecting the control plane?
Explanation: The correct answer adds an ACL entry to permit SSH from the management subnet before the deny statement, ensuring that SSH traffic is matched by the CoPP policy and not dropped. Option B is incorrect because removing the deny statement would leave the control plane unprotected. Option C is incorrect because increasing the police rate might not resolve the issue if the traffic is being dropped by an ACL deny. Option D is incorrect because removing the CoPP policy entirely removes all protection.
An enterprise network uses a Cisco Catalyst 9300 switch as a distribution layer device. The network team notices that ICMP echo requests from a monitoring server (192.168.1.100) to the switch's management IP are being dropped intermittently. The switch has a CoPP policy that includes a class-map matching ICMP traffic. The engineer checks the CoPP statistics and sees that ICMP packets from the monitoring server are being dropped by the policy. What is the most likely cause of this issue?
Explanation: The correct answer is that the CoPP policy is policing ICMP traffic to a rate that is too low for the monitoring server's traffic. Option B is incorrect because the ACL is not mentioned as blocking ICMP. Option C is incorrect because the monitoring server is not the source of the issue; it is the target. Option D is incorrect because the switch's CPU is not necessarily overloaded; the drops are due to CoPP policing.
A network engineer is configuring CoPP on a Cisco ASR 1000 router to protect the control plane from excessive traffic. The engineer wants to allow BGP traffic from a specific peer (10.0.0.1) while rate-limiting all other BGP traffic. The engineer creates an ACL that permits TCP port 179 from host 10.0.0.1 and denies all other BGP traffic. The CoPP class-map matches this ACL. However, after applying the policy, BGP sessions from other peers are still being established. What is the most likely reason?
Explanation: The correct answer is that the ACL only matches traffic from the specific peer, but CoPP class-maps match traffic based on the ACL; if the ACL denies other BGP traffic, CoPP will not match it, and it will be processed by the default class, which may permit it. Option B is incorrect because the ACL order is not the issue. Option C is incorrect because BGP uses TCP port 179, not UDP. Option D is incorrect because CoPP does not affect routing protocol sessions directly; it only polices traffic to the control plane.
A network engineer is troubleshooting a connectivity issue between two VLANs on a Cisco Catalyst 3850 switch. The switch has an ACL applied to VLAN 10 that permits traffic from VLAN 20 to VLAN 10, but denies all other traffic. Hosts in VLAN 20 can ping hosts in VLAN 10, but not vice versa. The engineer checks the ACL and finds that it is applied inbound on VLAN 10. What is the most likely cause of the issue?
Explanation: The correct answer is that the ACL is applied inbound on VLAN 10, so it filters traffic entering VLAN 10; traffic from VLAN 20 to VLAN 10 is permitted, but traffic from VLAN 10 to VLAN 20 is not affected by this ACL. Option B is incorrect because the ACL is applied inbound, not outbound. Option C is incorrect because the ACL is applied to the VLAN, not the SVI. Option D is incorrect because the ACL does not affect routing between VLANs; it only filters traffic.
A network engineer is configuring CoPP on a Cisco Nexus 9000 switch to protect the control plane from a potential DoS attack. The engineer creates a class-map that matches traffic with a specific DSCP value (AF41) and applies a police rate of 10 Mbps. After applying the policy, the engineer notices that legitimate traffic with DSCP AF41 is being dropped even though the traffic rate is only 5 Mbps. What is the most likely cause?
Explanation: The correct answer is that the CoPP policy is using a conform-action of drop, which drops all traffic that matches the class, regardless of rate. Option B is incorrect because the police rate is not exceeded. Option C is incorrect because DSCP AF41 is a valid value. Option D is incorrect because CoPP does not require a specific queue; it uses policing.
+15 more ACLs and CoPP questions available
Practice all ACLs and CoPP questions1. Baseline your knowledge
Start with 10 questions to gauge your current understanding of ACLs and CoPP. This tells you whether you need a concept refresher or just practice.
2. Review every explanation
For each question — right or wrong — read the full explanation. Understanding why an answer is correct is more valuable than knowing the answer itself.
3. Focus on exam traps
ACLs and CoPP questions on the 350-401 frequently use trap wording. Look for subtle differences in answers that test your precision, not just general knowledge.
4. Reach 80% consistently
Do repeated sessions until you score 80%+ three times in a row. Then move to mixed-mode practice to test cross-topic recall under realistic conditions.
The exact number varies per candidate. ACLs and CoPP is tested as part of the ENCOR 350-401 blueprint. Practicing with targeted ACLs and CoPP questions ensures you can handle any format or difficulty that appears.
Yes. Courseiva provides free 350-401 practice questions across all exam topics and domains. The platform includes topic-based practice, mock exams, missed-question review, bookmarked questions, and readiness tracking — no account required.
Difficulty is subjective, but ACLs and CoPP is a high-priority exam concept tested in multiple ways — direct recall, scenario analysis, and command-output interpretation. Consistent practice is the best way to build confidence.
Launch a full ACLs and CoPP practice session with instant scoring and detailed explanations.
Start ACLs and CoPP Practice →