300-410 Infrastructure Security Practice Question
A network administrator is deploying Control Plane Policing (CoPP) on a Cisco IOS XE router to protect the route processor from excessive control-plane traffic. After applying the CoPP policy, the administrator notices that OSPF adjacencies are flapping and that SNMP polling from the management station is failing. The administrator wants to correct the CoPP policy without disabling protection entirely. Which two actions should the administrator take? (Choose two.)
⚠ Common exam trap
The trap here is assuming that removing CoPP or applying it elsewhere will fix protocol issues, when the real fix is correcting classification and rate limits.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Increase the rate limit or mark the OSPF and SNMP traffic as conforming in the class maps.
CoPP failures for specific protocols usually stem from either incorrect classification or insufficient rate limits. Verifying that class maps match OSPF and SNMP traffic ensures they are placed in the correct class, and increasing the rate limit or adjusting the conform action for those classes allows legitimate traffic to pass. Together these correct the symptoms while preserving control-plane protection.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Increase the rate limit or mark the OSPF and SNMP traffic as conforming in the class maps.
Why this is correct
If OSPF and SNMP packets are being dropped or delayed, the policer rate for those classes is likely too low. Increasing the rate limit or adjusting the conform action to transmit allows legitimate control-plane traffic to pass while still policing other traffic. This directly addresses the flapping adjacencies and failed SNMP polls without removing CoPP protection.
- ✗
Apply the CoPP policy to all interfaces instead of the control plane.
Why it's wrong here
CoPP is designed to be applied to the control plane, not to individual interfaces. Applying it to interfaces would not police punted traffic correctly and could interfere with normal data forwarding. The control plane policy is the correct attachment point for protecting the route processor.
- ✗
Remove the CoPP policy from the control plane and rely on interface ACLs instead.
Why it's wrong here
Removing CoPP entirely eliminates the protection against control-plane floods, which is the opposite of the goal. Interface ACLs do not provide the same granular policing of punted traffic and would leave the route processor vulnerable. This action would resolve the symptoms but at an unacceptable security cost.
- ✓
Verify that the class maps correctly match the OSPF and SNMP traffic using the proper access control lists or protocol keywords.
Why this is correct
If the class maps do not correctly identify OSPF and SNMP traffic, those packets may fall into the default class and be policed or dropped. Ensuring the match statements use the correct ACLs or protocol keywords places the traffic in the right class, allowing appropriate treatment. This is a fundamental troubleshooting step when CoPP causes selective protocol failures.
- ✗
Disable CEF switching on the router to reduce control-plane load.
Why it's wrong here
Disabling CEF would severely degrade forwarding performance and is unrelated to CoPP behavior. CoPP operates on punted traffic regardless of CEF, and disabling CEF would not fix the class map or rate limit issues. This action is both ineffective and harmful to the router's overall operation.
Visual reference
Quick reference
Routing Protocol Comparison
| Protocol | Metric | Max Hops | Algorithm | Type |
|---|---|---|---|---|
| RIP v2 | Hop count | 15 | Bellman-Ford | Distance vector |
| OSPF | Cost (bandwidth) | Unlimited | Dijkstra (SPF) | Link state |
| EIGRP | Composite metric | Unlimited | DUAL | Hybrid |
| IS-IS | Cost | Unlimited | Dijkstra | Link state |
| BGP | Policy / attributes | Unlimited | Path vector | Path vector |
RIP's 15-hop limit makes it unsuitable for large networks. OSPF and EIGRP dominate modern enterprise deployments.
Go deeper
Related to this question
About these practice questions
One of 1,401 original 300-410 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.