mediumMultiple Choice
CCNP Practice Question: Examine the following CoPP configuration on a…
Examine the following CoPP configuration on a Cisco IOS-XE router: ``` class-map match-all CONTROL-PLANE match access-group name COPP-ACL ! policy-map COPP-POLICY
class CONTROL-PLANE
police 1000000 200000 conform-action transmit exceed-action drop ! control-plane service-policy input COPP-POLICY ``` What is the effect of this configuration?
⚠ Common exam trap
Cisco often tests the distinction between matching all control-plane traffic versus matching only traffic that hits a specific ACL, and candidates mistakenly assume the class-map applies to all control-plane traffic without reading the `match access-group` line.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Traffic matching the ACL is rate-limited to 1 Mbps; traffic exceeding the rate is dropped.
The CoPP configuration uses a `police` command with a committed information rate (CIR) of 1,000,000 bits per second (1 Mbps) and a burst size of 200,000 bytes. Traffic that matches the class-map (via the named ACL) is subject to this policer; conforming traffic is transmitted, while exceeding traffic is dropped. This effectively rate-limits the matched control-plane traffic to 1 Mbps.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Traffic matching the ACL is rate-limited to 1 Mbps; traffic exceeding the rate is dropped.
Why this is correct
This answer is correct because the class-map references an access control list (ACL) that selects specific control-plane traffic, and the police command in the policy-map enforces a committed information rate (CIR) of 1 Mbps. When a packet matches the ACL, it is evaluated by the token bucket; conforming traffic is transmitted, while non-conforming (excess) traffic is dropped due to the configured exceed-action drop. This rate limiting is therefore applied narrowly to only the ACL-matched subset of control-plane traffic, not to all traffic or any other class.
- ✗
All control plane traffic is rate-limited to 1 Mbps.
Why it's wrong here
This answer is incorrect because the policy-map does not apply to all control-plane traffic; it only applies to traffic that matches the class-map, which in turn references a specific ACL. Control-plane traffic that does not match that ACL (e.g., routing protocol packets, ICMP, or other management traffic) is not evaluated by the police command and will not be rate-limited. The term 'all control plane traffic' is much broader than what the configuration actually selects, so the rate limit is scoped to a defined subset rather than the entire control plane.
- ✗
Traffic exceeding 1 Mbps is marked down but still transmitted.
Why it's wrong here
This answer is incorrect because the exceed-action configured in the police command is 'drop', not a marking action such as set precedence or set qos-group. When traffic exceeds the 1 Mbps CIR, the router immediately drops the excess packets rather than marking and forwarding them. Marking down and still transmitting would require an action like 'exceed-action set precedence ...' or 'set discard-class', neither of which is specified in this policy-map.
- ✗
The policy-map is applied to the data plane, not the control plane.
Why it's wrong here
This answer is incorrect because the configuration snippet shows the service-policy statement applied inside the 'control-plane' configuration section, not under an interface or a data-plane construct. In Cisco IOS/IOS-XE, entering the 'control-plane' section and applying a policy-map there explicitly directs the policy to inspect and rate-limit traffic destined for the route processor (the control plane). A data-plane application would instead use 'service-policy' on an interface in the 'interface' configuration mode, which is not the case here.
Visual reference
About these practice questions
One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.