CCNP Security Practice Question
A network engineer is deploying Control Plane Policing on a Cisco IOS-XE router that runs OSPF, BGP, and SSH management. The engineer wants to rate-limit routing protocol traffic while ensuring that SSH management traffic is never dropped, even during a routing protocol flood. The router uses a single physical interface for all control plane traffic. Which CoPP design approach best meets these requirements?
⚠ Common exam trap
The trap here is assuming that SSH management traffic is automatically exempt from CoPP because it is TCP-based, when in fact all control plane traffic is subject to the policy-map.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create separate class-maps for OSPF, BGP, and SSH, then apply individual policers to each class in the policy-map, with SSH assigned a higher rate or set to conform-action transmit.
Separate class-maps for OSPF, BGP, and SSH allow individual policing actions. Assigning SSH a higher rate or conform-action transmit ensures management access is preserved during routing protocol floods. This granular CoPP design protects both routing stability and administrative access, which is the core goal of control plane policing.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Create separate class-maps for OSPF, BGP, and SSH, then apply individual policers to each class in the policy-map, with SSH assigned a higher rate or set to conform-action transmit.
Why this is correct
Creating separate class-maps allows the engineer to apply distinct policers to each traffic type. By giving SSH a higher rate limit or configuring it to always transmit, management access is protected. OSPF and BGP can be rate-limited independently to prevent control plane overload. This granular approach is the recommended CoPP design for protecting critical management traffic.
- ✗
Use a single class-map for OSPF and BGP, and rely on SSH being exempt because it is TCP-based and not subject to CoPP.
Why it's wrong here
CoPP applies to all traffic destined to the control plane, including TCP-based SSH. There is no automatic exemption for TCP traffic. Without a separate class-map for SSH, management packets compete with routing protocol packets and may be dropped during floods. This design fails to meet the requirement of never dropping SSH.
- ✗
Configure CoPP only on the management interface and leave the data interfaces unprotected.
Why it's wrong here
CoPP is applied globally to the control plane, not per-interface. The control plane receives traffic from all interfaces, including data interfaces. Configuring CoPP only on a management interface would leave the router vulnerable to control plane attacks from data ports. This approach does not protect routing protocols or SSH from floods on other interfaces.
- ✗
Apply a single class-map matching all control plane traffic and set a single policer with a high rate limit.
Why it's wrong here
A single class-map matching all control plane traffic cannot differentiate between routing protocol packets and SSH management packets. During a routing protocol flood, the high rate limit may still be exceeded, and SSH packets would be dropped indiscriminately along with routing packets. This approach lacks the granularity needed to protect management access while controlling routing protocol load.
Visual reference
Quick reference
Routing Protocol Comparison
| Protocol | Metric | Max Hops | Algorithm | Type |
|---|---|---|---|---|
| RIP v2 | Hop count | 15 | Bellman-Ford | Distance vector |
| OSPF | Cost (bandwidth) | Unlimited | Dijkstra (SPF) | Link state |
| EIGRP | Composite metric | Unlimited | DUAL | Hybrid |
| IS-IS | Cost | Unlimited | Dijkstra | Link state |
| BGP | Policy / attributes | Unlimited | Path vector | Path vector |
RIP's 15-hop limit makes it unsuitable for large networks. OSPF and EIGRP dominate modern enterprise deployments.
About these practice questions
This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.