CCNP Security Practice Question
A network engineer is configuring Control Plane Policing (CoPP) on a Cisco IOS XE router that runs BGP, SSH management, and SNMP monitoring. After applying a new CoPP policy, BGP sessions flap intermittently while SSH and SNMP continue to work. The engineer wants to confirm which traffic class is being dropped. Which action should the engineer take?
⚠ Common exam trap
The trap here is troubleshooting the BGP neighbor state instead of inspecting the CoPP policy-map counters that actually reveal which traffic class is being policed and dropped.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Review CoPP class-map and policy-map statistics with show policy-map control-plane to identify the class with drops.
CoPP applies a policy-map to the control plane and maintains per-class statistics. Because SSH and SNMP still function while BGP flaps, the BGP class is likely exceeding its configured rate. Viewing the control-plane policy-map counters shows which class has drops, pinpointing the class that needs a higher rate or burst value.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Run show ip bgp summary to check the BGP neighbor state and reset the sessions.
Why it's wrong here
The show ip bgp summary command shows neighbor states and prefix counts but does not report CoPP class drops. Resetting sessions would not identify the policing issue and could worsen the flapping, so this action does not confirm which traffic class is being dropped.
- ✗
Capture traffic on the control plane interface using an Embedded Packet Capture with a BGP filter.
Why it's wrong here
Embedded Packet Capture can capture packets but does not directly show which CoPP class is dropping them. It would require correlating captures with policy configuration and lacks the per-class drop counters that immediately identify the offending class, making it inefficient for this troubleshooting goal.
- ✗
Enable debug ip ssh and debug snmp packets to compare with BGP debugs.
Why it's wrong here
Debugging SSH and SNMP does not expose CoPP policing counters and can generate significant CPU load on a production router. This approach would not reliably identify which control-plane class is dropping packets and risks impacting the very protocols that are currently working.
- ✓
Review CoPP class-map and policy-map statistics with show policy-map control-plane to identify the class with drops.
Why this is correct
The show policy-map control-plane command displays per-class packet and byte counters, including dropped packets, for the control plane policy. Since BGP is flapping while SSH and SNMP work, inspecting these counters reveals which class is exceeding its rate and dropping traffic, directly identifying the misconfigured class.
About these practice questions
One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.