Courseiva
Security →mediumMultiple Choice

CCNP Security Practice Question

A network administrator is deploying Control Plane Policing (CoPP) on a Cisco IOS XE router that peers BGP with two ISPs. After applying a policer to the control plane, the BGP sessions tear down repeatedly while OSPF adjacencies stay stable. The administrator confirms CPU utilization is low. Which action should be taken to resolve the issue?

⚠ Common exam trap

The trap here is assuming that low CPU utilization proves CoPP is working correctly, when in fact a too-strict policer silently discards essential routing protocol keepalives.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Increase the CIR of the policer class matching BGP traffic and permit the BGP class in the control-plane service policy.

CoPP policies inspect and police traffic punted to the route processor. When a policer for a critical routing protocol is too restrictive, protocol hellos and keepalives are dropped, causing peering failures even though CPU load is low. Adjusting the policer rate and ensuring the protocol class is permitted restores the required control-plane traffic while retaining protection against abuse.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Apply the CoPP policy to the data plane interfaces using the service-policy input command.

    Why it's wrong here

    CoPP is designed to protect the route processor by policing traffic destined to the control plane, and it is attached globally with service-policy input under control-plane configuration. Applying it as an interface input policy changes the scope entirely and would police transit traffic rather than protect the CPU, which does not fix BGP keepalive drops.

  • ✓

    Increase the CIR of the policer class matching BGP traffic and permit the BGP class in the control-plane service policy.

    Why this is correct

    BGP session teardown with low CPU indicates the policer is dropping BGP keepalives before they reach the control plane. Raising the committed information rate for the BGP class and explicitly permitting that class in the control-plane policy allows the protocol traffic to pass at the required rate, restoring adjacency stability without disabling CoPP for other traffic.

  • ✗

    Disable CEF switching on the router so BGP packets are process-switched and bypass the policer.

    Why it's wrong here

    Disabling Cisco Express Forwarding degrades forwarding performance dramatically and does not exempt control-plane traffic from CoPP. Process-switched packets still traverse the control-plane path and remain subject to policing. This approach would harm overall router performance while leaving the BGP flapping problem unresolved.

  • ✗

    Enable NetFlow on the WAN interfaces and export records to a collector for BGP traffic analysis.

    Why it's wrong here

    NetFlow provides visibility into traffic flows but does not change how the control-plane policer treats BGP packets. Exporting flow records cannot prevent the policer from dropping keepalives, so the BGP sessions would continue to flap. This action addresses monitoring, not the actual cause of the drops in the CoPP policy.

Visual reference

R1 R2 R3 R4 10 100 10 100 OSPF picks R1→R2→R4 (cost 20) over R1→R3→R4 (cost 200)

Quick reference

Routing Protocol Comparison

ProtocolMetricMax HopsAlgorithmType
RIP v2Hop count15Bellman-FordDistance vector
OSPFCost (bandwidth)UnlimitedDijkstra (SPF)Link state
EIGRPComposite metricUnlimitedDUALHybrid
IS-ISCostUnlimitedDijkstraLink state
BGPPolicy / attributesUnlimitedPath vectorPath vector

RIP's 15-hop limit makes it unsuitable for large networks. OSPF and EIGRP dominate modern enterprise deployments.

About these practice questions

One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.