CCNP Security Practice Question
A network administrator must protect the control plane of a Cisco IOS XE router that peers BGP with an ISP. The requirement is to rate-limit specifically ARP and IPv4 TTL-expired packets destined to the route processor while allowing all other transit traffic to be forwarded normally. Which CoPP implementation step is required to achieve this?
⚠ Common exam trap
The trap here is attaching the control-plane service policy to an interface instead of globally, which would police forwarded traffic rather than packets punted to the route processor.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create an ACL matching ARP and TTL-expired traffic, reference it in a class-map of type control-plane, define a policy-map with police actions, and attach it with service-policy type control-plane in global configuration.
CoPP uses MQC with a class-map of type control-plane to identify traffic punted to the route processor, a policy-map to police that class, and a global service-policy type control-plane attachment. Matching ARP and TTL-expired packets with an ACL inside the class-map isolates exactly the traffic to be rate-limited, while transit traffic continues to be forwarded in hardware and is never inspected by CoPP.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable Control Plane Protection with a port-filter policy that drops ARP and TTL-expired packets before they reach the route processor.
Why it's wrong here
Control Plane Protection (CPPr) includes host, transit, and CEF-exception subinterfaces, and a port-filter can block specific protocols, but the requirement is to rate-limit rather than drop. Dropping ARP could disrupt neighbor discovery, and TTL-expired packets are legitimate control traffic. CoPP with policing provides the granular rate limiting the scenario demands, not an outright port-filter drop.
- ✗
Apply an ACL directly to the BGP peer interface inbound to deny ARP and TTL-expired packets, then rely on uRPF to drop remaining control-plane traffic.
Why it's wrong here
Denying ARP on the interface would break neighbor resolution and does not selectively police control-plane traffic. uRPF validates source addresses but does not rate-limit ARP or TTL-expired packets destined to the route processor. This approach also affects all ingress traffic on that interface rather than only packets punted to the control plane, so it does not meet the requirement.
- ✗
Configure an MQC service policy with service-policy type control-plane on the BGP-facing interface to rate-limit ARP and TTL-expired packets.
Why it's wrong here
CoPP is attached globally using service-policy type control-plane, not on a physical interface. Interface-level service policies apply to forwarded traffic, not to the control-plane punt path. Even if the class matched ARP and TTL-expired packets, attaching it to the interface would not police traffic destined to the route processor, so the requirement would not be satisfied.
- ✓
Create an ACL matching ARP and TTL-expired traffic, reference it in a class-map of type control-plane, define a policy-map with police actions, and attach it with service-policy type control-plane in global configuration.
Why this is correct
CoPP on IOS XE requires classifying control-plane-bound traffic with a class-map of type control-plane, then applying policing in a policy-map that is attached globally with service-policy type control-plane. An ACL matching ARP and TTL-expired packets provides the specific match, and transit traffic is unaffected because CoPP only inspects packets punted to the route processor.
Visual reference
About these practice questions
One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.