Courseiva
mediumMultiple Choice

CCNP Practice Question: Consider the following configuration: class-map…

Consider the following configuration:

class-map match-all HTTP match protocol http

policy-map QOS

class HTTP

police 2000000 1500 3000 conform-action transmit exceed-action drop

interface GigabitEthernet0/1

service-policy input QOS

What is the effect of this configuration?

⚠ Common exam trap

Cisco often tests the distinction between policing and shaping, and the trap here is that candidates confuse 'police' with 'shape' or assume that 'police' cannot be applied in the input direction, when in fact policing is commonly used on input interfaces.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

HTTP traffic is policed to an average rate of 2 Mbps; packets that exceed the rate are dropped, while conforming packets are transmitted.

The 'police' command in the policy-map enforces a traffic policer on HTTP traffic matched by the class-map. The parameters '2000000' (2 Mbps) define the committed information rate (CIR), '1500' is the normal burst (Bc), and '3000' is the excess burst (Be). Conforming packets are transmitted, while packets exceeding the rate are dropped, which is the standard behavior of a policer in the input direction.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    HTTP traffic is policed to an average rate of 2 Mbps; packets that exceed the rate are dropped, while conforming packets are transmitted.

    Why this is correct

    Policing enforces a 2 Mbps average rate using a token bucket; every arriving HTTP packet is evaluated against that bucket. Packets that find enough tokens are transmitted unchanged because of the conform-action transmit clause, while packets that exceed the bucket depth trigger the exceed-action drop and are discarded immediately. Policing does not buffer, so excess traffic is dropped rather than delayed.

  • ✗

    HTTP traffic is shaped to an average rate of 2 Mbps; excess packets are buffered.

    Why it's wrong here

    Shaping, unlike policing, applies a 2 Mbps rate by queueing excess packets in a buffer and releasing them later, which smooths bursts but adds latency. The configuration shown uses the police command, not a shape or GTS command, so there is no buffering mechanism; excess packets are handled by an immediate exceed-action rather than queued for delayed transmission.

  • ✗

    The police command will mark HTTP packets with a DSCP value of 0 if they exceed the rate.

    Why it's wrong here

    The exceed-action in this police clause is explicitly 'drop', so out-of-profile packets are discarded, never forwarded. A marking action would require a different conform/exceed action such as set-dscp-transmit, and even then it would set a configured DSCP value, not automatically zero, but the question's configuration has no such clause, making the statement factually incorrect.

  • ✗

    The configuration is invalid because 'police' cannot be used in a 'service-policy input' direction.

    Why it's wrong here

    The police command is valid in a service-policy applied in the input direction; QoS policing is commonly used inbound to enforce ingress rate limits before packets enter the network. Cisco IOS allows police in both input and output policies, provided the platform and interface support it, so the configuration is not invalid for direction. The actual effect is the policing behavior described earlier, not an error.

About these practice questions

Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.