Courseiva
Security →mediumMultiple Choice

CCNP Security Practice Question

A network administrator is configuring Control Plane Policing (CoPP) on a Cisco IOS XE router that peers BGP with two ISPs and is managed over SSH. The administrator needs to protect the route processor from excessive BGP and SSH traffic without breaking the existing sessions. Which action should be taken when applying the CoPP policy?

⚠ Common exam trap

The trap here is assuming CoPP is applied to physical interfaces like a normal QoS policy, when it must be attached to the control-plane interface.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Apply the policy-map to the control-plane interface using the service-policy input command.

CoPP is designed to classify and police traffic destined to the route processor. The policy-map must be attached to the control-plane interface with service-policy input so that only CPU-bound traffic is policed while transit traffic remains unaffected, preserving BGP peering and SSH management access.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Apply the policy-map to the control-plane interface using the service-policy input command.

    Why this is correct

    CoPP policies are applied to the control plane by attaching the policy-map to the control-plane interface with service-policy input. This filters traffic destined to the route processor while allowing transit traffic to pass untouched, which preserves the BGP and SSH sessions.

  • ✗

    Apply the policy-map to the management VRF interface using service-policy input.

    Why it's wrong here

    The management VRF interface only carries management traffic and does not police BGP or other control-plane protocols. Attaching the policy here leaves most route-processor traffic unprotected and fails to meet the requirement of protecting BGP and SSH.

  • ✗

    Apply the policy-map globally with the service-policy command in global configuration mode.

    Why it's wrong here

    Cisco IOS XE does not support attaching a service-policy globally in global configuration mode. CoPP requires the policy to be attached specifically to the control-plane interface, so this syntax would be rejected and no protection would be applied.

  • ✗

    Apply the policy-map to each ISP-facing physical interface with service-policy output.

    Why it's wrong here

    Applying the policy to physical interfaces affects transit and forwarded traffic, not traffic destined to the route processor. This would not protect the control plane from CPU-bound attacks and could disrupt user traffic, which is outside the stated requirement.

About these practice questions

Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.