CCNP Security Practice Question
A network engineer is configuring Control Plane Policing (CoPP) on a Cisco IOS XE router that runs BGP, SSH management, and SNMP. After applying a CoPP policy, BGP peering drops intermittently during route churn, but SSH and SNMP remain reachable. Which action should be taken to correct the issue while preserving control plane protection?
⚠ Common exam trap
The trap here is assuming that CoPP failures require disabling the policy, when the correct fix is to tune the specific class policer that is dropping legitimate traffic.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Increase the policer rate for the BGP class-map in the CoPP policy.
CoPP policers are applied per class, so a too-low rate for the BGP class causes legitimate BGP traffic to be dropped during churn while other classes remain unaffected. Raising the BGP policer rate restores BGP stability without removing control plane protection, whereas disabling CoPP or altering class-maps would either expose the router or misclassify traffic.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Increase the policer rate for the BGP class-map in the CoPP policy.
Why this is correct
BGP peering drops during route churn because the policer for the BGP class is too aggressive and is dropping legitimate control plane traffic. Adjusting the rate for the BGP class preserves protection for other traffic while allowing BGP keepalives and updates to pass. SSH and SNMP are unaffected because their classes have separate policers, so the fix should target the BGP class specifically.
- ✗
Change the BGP class-map match to include only SSH and SNMP traffic.
Why it's wrong here
Modifying the BGP class-map to match SSH and SNMP would misclassify management traffic and remove BGP traffic from its intended policer, which breaks the policy design. It would not address BGP drops and would cause management traffic to be policed by the wrong class. Class-maps must accurately match the traffic they are intended to control.
- ✗
Remove the CoPP policy from the control plane and reapply it after convergence.
Why it's wrong here
Removing CoPP entirely disables control plane protection and exposes the router to DoS attacks during the very period of route churn when the control plane is most vulnerable. This does not correct the underlying policer configuration and is not a valid long-term fix. The scenario requires preserving protection while fixing the BGP drop.
- ✗
Disable BGP route churn by setting the BGP scanner interval to a higher value.
Why it's wrong here
The BGP scanner interval affects how often BGP walks the routing table for next-hop validation and does not control the rate of BGP updates during churn. Changing it will not prevent CoPP from dropping BGP packets and may delay convergence. The root cause is the policer rate, not the scanner timer.
About these practice questions
One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.