Courseiva
mediumMultiple Choice

CCNP Practice Question: Examine the following CoPP configuration on a…

Examine the following CoPP configuration on a Cisco IOS-XE router: ``` class-map match-all CONTROL-PLANE match access-group name COPP-ACL ! policy-map COPP-POLICY

class CONTROL-PLANE

police 1000000 200000 conform-action transmit exceed-action drop ! control-plane service-policy input COPP-POLICY ``` What is the effect of this configuration?

⚠ Common exam trap

Cisco often tests the distinction between matching all control-plane traffic versus matching only traffic that hits a specific ACL, and candidates mistakenly assume the class-map applies to all control-plane traffic without reading the `match access-group` line.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Traffic matching the ACL is rate-limited to 1 Mbps; traffic exceeding the rate is dropped.

The CoPP configuration uses a `police` command with a committed information rate (CIR) of 1,000,000 bits per second (1 Mbps) and a burst size of 200,000 bytes. Traffic that matches the class-map (via the named ACL) is subject to this policer; conforming traffic is transmitted, while exceeding traffic is dropped. This effectively rate-limits the matched control-plane traffic to 1 Mbps.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Traffic matching the ACL is rate-limited to 1 Mbps; traffic exceeding the rate is dropped.

    Why this is correct

    This answer is correct because the class-map references an access control list (ACL) that selects specific control-plane traffic, and the police command in the policy-map enforces a committed information rate (CIR) of 1 Mbps. When a packet matches the ACL, it is evaluated by the token bucket; conforming traffic is transmitted, while non-conforming (excess) traffic is dropped due to the configured exceed-action drop. This rate limiting is therefore applied narrowly to only the ACL-matched subset of control-plane traffic, not to all traffic or any other class.

  • ✗

    All control plane traffic is rate-limited to 1 Mbps.

    Why it's wrong here

    This answer is incorrect because the policy-map does not apply to all control-plane traffic; it only applies to traffic that matches the class-map, which in turn references a specific ACL. Control-plane traffic that does not match that ACL (e.g., routing protocol packets, ICMP, or other management traffic) is not evaluated by the police command and will not be rate-limited. The term 'all control plane traffic' is much broader than what the configuration actually selects, so the rate limit is scoped to a defined subset rather than the entire control plane.

  • ✗

    Traffic exceeding 1 Mbps is marked down but still transmitted.

    Why it's wrong here

    This answer is incorrect because the exceed-action configured in the police command is 'drop', not a marking action such as set precedence or set qos-group. When traffic exceeds the 1 Mbps CIR, the router immediately drops the excess packets rather than marking and forwarding them. Marking down and still transmitting would require an action like 'exceed-action set precedence ...' or 'set discard-class', neither of which is specified in this policy-map.

  • ✗

    The policy-map is applied to the data plane, not the control plane.

    Why it's wrong here

    This answer is incorrect because the configuration snippet shows the service-policy statement applied inside the 'control-plane' configuration section, not under an interface or a data-plane construct. In Cisco IOS/IOS-XE, entering the 'control-plane' section and applying a policy-map there explicitly directs the policy to inspect and rate-limit traffic destined for the route processor (the control plane). A data-plane application would instead use 'service-policy' on an interface in the 'interface' configuration mode, which is not the case here.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.