Courseiva
Security →hardMultiple Choice

CCNP Security Practice Question

A network engineer is implementing Control Plane Policing (CoPP) on a Cisco IOS XE router to protect the route processor from excessive control-plane traffic. The engineer wants to rate-limit ARP and DHCP snooping-related traffic destined to the control plane while allowing routing protocol traffic without restriction. Which CoPP component must the engineer configure to classify and match this traffic before applying the policy?

⚠ Common exam trap

Test-takers frequently confuse CoPP with ACL-based control-plane filtering, when CoPP specifically requires class maps and a policy map applied via service-policy on the control-plane interface.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A class map that matches traffic using ACLs and/or match protocol commands.

CoPP relies on the modular QoS CLI, where class maps classify control-plane traffic, policy maps apply policing actions, and the service-policy is attached to the control-plane interface. To rate-limit ARP and DHCP snooping traffic while leaving routing protocols unrestricted, the engineer must create class maps that match those specific protocols and reference them in a policy map, which is then applied to the control plane.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    A policy map that references the control-plane host and matches all IP traffic by default.

    Why it's wrong here

    A policy map defines actions but still requires class maps to identify the specific traffic. Matching all IP traffic by default would police all control-plane traffic indiscriminately, including routing protocols, which the scenario says must not be restricted. The classification step must occur in class maps before the policy map is applied.

  • ✗

    An access list applied directly to the control-plane interface with the ip access-group command.

    Why it's wrong here

    Applying an ACL to the control-plane interface filters traffic but does not perform rate limiting or policing. CoPP requires a policy map with police actions, applied via service-policy. An ACL alone cannot rate-limit ARP or DHCP snooping traffic destined to the route processor.

  • ✓

    A class map that matches traffic using ACLs and/or match protocol commands.

    Why this is correct

    CoPP uses a modular QoS CLI structure: class maps define the traffic to be matched, policy maps define the actions, and the service-policy is applied to the control-plane interface. To rate-limit ARP and DHCP snooping traffic, the engineer must first create class maps that identify those protocols using ACLs or match protocol statements, then reference them in a policy map.

  • ✗

    A route map applied to the control-plane interface with the service-policy command.

    Why it's wrong here

    Route maps are used for route redistribution, policy-based routing, and BGP attribute manipulation, not for classifying control-plane traffic in CoPP. The control-plane interface accepts a service-policy that references a policy map, not a route map. Using a route map here would not match ARP or DHCP snooping packets for policing.

Visual reference

Client DHCP Server 1 Discover (broadcast) 2 Offer (IP: 192.168.1.10) 3 Request (I accept) 4 Acknowledge (lease confirmed) DORA — the four-step DHCP lease process

Quick reference

Routing Protocol Comparison

ProtocolMetricMax HopsAlgorithmType
RIP v2Hop count15Bellman-FordDistance vector
OSPFCost (bandwidth)UnlimitedDijkstra (SPF)Link state
EIGRPComposite metricUnlimitedDUALHybrid
IS-ISCostUnlimitedDijkstraLink state
BGPPolicy / attributesUnlimitedPath vectorPath vector

RIP's 15-hop limit makes it unsuitable for large networks. OSPF and EIGRP dominate modern enterprise deployments.

About these practice questions

This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.