Courseiva
Security →hardMultiple Choice

CCNP Security Practice Question

A network administrator must protect the control plane of a Cisco IOS XE router that peers BGP with an ISP. The requirement is to rate-limit specifically ARP and IPv4 TTL-expired packets destined to the route processor while allowing all other transit traffic to be forwarded normally. Which CoPP implementation step is required to achieve this?

⚠ Common exam trap

The trap here is attaching the control-plane service policy to an interface instead of globally, which would police forwarded traffic rather than packets punted to the route processor.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create an ACL matching ARP and TTL-expired traffic, reference it in a class-map of type control-plane, define a policy-map with police actions, and attach it with service-policy type control-plane in global configuration.

CoPP uses MQC with a class-map of type control-plane to identify traffic punted to the route processor, a policy-map to police that class, and a global service-policy type control-plane attachment. Matching ARP and TTL-expired packets with an ACL inside the class-map isolates exactly the traffic to be rate-limited, while transit traffic continues to be forwarded in hardware and is never inspected by CoPP.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable Control Plane Protection with a port-filter policy that drops ARP and TTL-expired packets before they reach the route processor.

    Why it's wrong here

    Control Plane Protection (CPPr) includes host, transit, and CEF-exception subinterfaces, and a port-filter can block specific protocols, but the requirement is to rate-limit rather than drop. Dropping ARP could disrupt neighbor discovery, and TTL-expired packets are legitimate control traffic. CoPP with policing provides the granular rate limiting the scenario demands, not an outright port-filter drop.

  • ✗

    Apply an ACL directly to the BGP peer interface inbound to deny ARP and TTL-expired packets, then rely on uRPF to drop remaining control-plane traffic.

    Why it's wrong here

    Denying ARP on the interface would break neighbor resolution and does not selectively police control-plane traffic. uRPF validates source addresses but does not rate-limit ARP or TTL-expired packets destined to the route processor. This approach also affects all ingress traffic on that interface rather than only packets punted to the control plane, so it does not meet the requirement.

  • ✗

    Configure an MQC service policy with service-policy type control-plane on the BGP-facing interface to rate-limit ARP and TTL-expired packets.

    Why it's wrong here

    CoPP is attached globally using service-policy type control-plane, not on a physical interface. Interface-level service policies apply to forwarded traffic, not to the control-plane punt path. Even if the class matched ARP and TTL-expired packets, attaching it to the interface would not police traffic destined to the route processor, so the requirement would not be satisfied.

  • ✓

    Create an ACL matching ARP and TTL-expired traffic, reference it in a class-map of type control-plane, define a policy-map with police actions, and attach it with service-policy type control-plane in global configuration.

    Why this is correct

    CoPP on IOS XE requires classifying control-plane-bound traffic with a class-map of type control-plane, then applying policing in a policy-map that is attached globally with service-policy type control-plane. An ACL matching ARP and TTL-expired packets provides the specific match, and transit traffic is unaffected because CoPP only inspects packets punted to the route processor.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.