Courseiva
Security →mediumMultiple Choice

CCNP Security Practice Question

A network engineer configures Control Plane Policing on a Cisco IOS XE router acting as the BGP speaker for an ISP edge. The policy must protect the route processor from CPU exhaustion while still allowing BGP keepalives, SSH management, and SNMP polling from the NOC. Which CoPP design element is required to ensure BGP, SSH, and SNMP traffic is matched and rate-limited separately from transit traffic?

⚠ Common exam trap

Candidates often confuse interface-level QoS policing with control-plane policing, when only a policy attached under control-plane configuration mode protects the route processor.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A class-map that matches traffic with the 'control-plane' keyword and a policy-map applied with 'service-policy input' under the control-plane configuration mode.

CoPP protects the route processor by classifying traffic destined to the control plane and applying policers through an MQC policy attached under control-plane configuration mode. This allows BGP keepalives, SSH, and SNMP to be individually matched and rate-limited so that a flood of any one protocol cannot exhaust CPU resources while transit traffic is unaffected.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    An access list applied outbound on all interfaces using 'ip access-group' to block unwanted traffic before it reaches the route processor.

    Why it's wrong here

    Outbound ACLs on interfaces filter traffic leaving the device, not traffic destined to the route processor. They cannot rate-limit legitimate BGP, SSH, or SNMP traffic, and they do not provide the granular policer behavior that CoPP offers. Using an outbound ACL would also risk blocking transit traffic that customers depend on.

  • ✗

    An MQC policy attached to the WAN interface with 'service-policy input' so that all inbound traffic including BGP and SSH is policed at the interface level.

    Why it's wrong here

    Attaching the policy to the interface polices all inbound traffic, including transit packets that should be forwarded normally. Control plane protection is specifically about traffic destined to the route processor, not transit traffic. Interface-level policing would also drop legitimate customer traffic and does not isolate CPU-bound protocols like the CoPP feature is designed to do.

  • ✗

    A route-map with 'match ip next-hop' applied to the BGP neighbor to limit the number of prefixes received from each peer.

    Why it's wrong here

    A route-map with next-hop matching is used for BGP policy manipulation, such as filtering or modifying attributes, not for protecting the CPU from high-rate control-plane traffic. It does not police SSH or SNMP and has no effect on the packet rate delivered to the route processor. This mechanism is unrelated to CoPP functionality.

  • ✓

    A class-map that matches traffic with the 'control-plane' keyword and a policy-map applied with 'service-policy input' under the control-plane configuration mode.

    Why this is correct

    CoPP on IOS XE requires a class-map to identify control-plane-destined traffic, typically using an ACL or 'match protocol', and a policy-map that assigns a policer. The policy-map is attached to the control-plane with 'service-policy input', which is exactly how BGP, SSH, and SNMP destined to the route processor are rate-limited without affecting transit forwarding.

About these practice questions

This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.