CCNP Security Practice Question
A network administrator is deploying Control Plane Policing (CoPP) on a Cisco IOS XE router that peers BGP with two ISPs. After applying a policer to the control plane, the BGP sessions tear down repeatedly while OSPF adjacencies stay stable. The administrator confirms CPU utilization is low. Which action should be taken to resolve the issue?
⚠ Common exam trap
The trap here is assuming that low CPU utilization proves CoPP is working correctly, when in fact a too-strict policer silently discards essential routing protocol keepalives.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Increase the CIR of the policer class matching BGP traffic and permit the BGP class in the control-plane service policy.
CoPP policies inspect and police traffic punted to the route processor. When a policer for a critical routing protocol is too restrictive, protocol hellos and keepalives are dropped, causing peering failures even though CPU load is low. Adjusting the policer rate and ensuring the protocol class is permitted restores the required control-plane traffic while retaining protection against abuse.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Apply the CoPP policy to the data plane interfaces using the service-policy input command.
Why it's wrong here
CoPP is designed to protect the route processor by policing traffic destined to the control plane, and it is attached globally with service-policy input under control-plane configuration. Applying it as an interface input policy changes the scope entirely and would police transit traffic rather than protect the CPU, which does not fix BGP keepalive drops.
- ✓
Increase the CIR of the policer class matching BGP traffic and permit the BGP class in the control-plane service policy.
Why this is correct
BGP session teardown with low CPU indicates the policer is dropping BGP keepalives before they reach the control plane. Raising the committed information rate for the BGP class and explicitly permitting that class in the control-plane policy allows the protocol traffic to pass at the required rate, restoring adjacency stability without disabling CoPP for other traffic.
- ✗
Disable CEF switching on the router so BGP packets are process-switched and bypass the policer.
Why it's wrong here
Disabling Cisco Express Forwarding degrades forwarding performance dramatically and does not exempt control-plane traffic from CoPP. Process-switched packets still traverse the control-plane path and remain subject to policing. This approach would harm overall router performance while leaving the BGP flapping problem unresolved.
- ✗
Enable NetFlow on the WAN interfaces and export records to a collector for BGP traffic analysis.
Why it's wrong here
NetFlow provides visibility into traffic flows but does not change how the control-plane policer treats BGP packets. Exporting flow records cannot prevent the policer from dropping keepalives, so the BGP sessions would continue to flap. This action addresses monitoring, not the actual cause of the drops in the CoPP policy.
Visual reference
Quick reference
Routing Protocol Comparison
| Protocol | Metric | Max Hops | Algorithm | Type |
|---|---|---|---|---|
| RIP v2 | Hop count | 15 | Bellman-Ford | Distance vector |
| OSPF | Cost (bandwidth) | Unlimited | Dijkstra (SPF) | Link state |
| EIGRP | Composite metric | Unlimited | DUAL | Hybrid |
| IS-IS | Cost | Unlimited | Dijkstra | Link state |
| BGP | Policy / attributes | Unlimited | Path vector | Path vector |
RIP's 15-hop limit makes it unsuitable for large networks. OSPF and EIGRP dominate modern enterprise deployments.
About these practice questions
One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.