Courseiva
Infrastructure Security →hardMultiple Choice

300-410 Infrastructure Security Practice Question

A network engineer is implementing Control Plane Policing (CoPP) on a Cisco IOS XE router to protect against route processor overload. The engineer creates a class map matching OSPF and BGP traffic and a policy map that polices this traffic to 1 Mbps with a burst of 2000 bytes. After applying the policy map to the control plane, the engineer notices that OSPF adjacencies flap intermittently. Which action should the engineer take to resolve the flapping?

⚠ Common exam trap

The trap here is assuming that any control plane policing is beneficial, without considering that overly aggressive rate limits can disrupt legitimate routing protocol operations.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Increase the policed rate and burst size to accommodate legitimate routing protocol traffic.

CoPP policies that are too restrictive can drop legitimate control plane traffic, causing routing protocol adjacencies to flap. In this scenario, the policer rate of 1 Mbps is insufficient for OSPF and BGP traffic, leading to intermittent OSPF drops. Increasing the policed rate and burst size allows normal routing updates to pass while still providing protection against excessive traffic.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Disable OSPF authentication to reduce packet size and processing overhead.

    Why it's wrong here

    OSPF authentication does not significantly affect packet size or processing overhead in a way that would cause flapping due to CoPP. Disabling authentication would weaken security and not solve the policer dropping packets. The flapping is due to the policer rate, not authentication. The correct fix is to adjust CoPP parameters.

  • ✗

    Configure a higher priority queue for OSPF traffic in the policy map.

    Why it's wrong here

    CoPP uses policing, not queuing, to rate-limit traffic. Priority queuing is not a feature of CoPP policy maps. While prioritization could help, the immediate issue is that the policer rate is too low, causing drops. Increasing the policed rate and burst size directly addresses the drops and resolves the flapping.

  • ✗

    Apply the policy map to all interfaces instead of the control plane.

    Why it's wrong here

    CoPP is specifically applied to the control plane to protect the route processor. Applying the policy to interfaces would affect data plane traffic and not protect the control plane. Moreover, it would not address the OSPF flapping caused by the policer dropping legitimate OSPF packets. The correct action is to adjust the policer parameters.

  • ✓

    Increase the policed rate and burst size to accommodate legitimate routing protocol traffic.

    Why this is correct

    Intermittent OSPF adjacency flapping indicates that legitimate OSPF packets are being dropped due to the policer rate being too low. Increasing the rate and burst size allows the routing protocol traffic to pass without being policed, stabilizing the adjacencies. CoPP policies must be tuned to permit normal control plane traffic while still protecting against attacks.

Visual reference

R1 R2 R3 R4 10 100 10 100 OSPF picks R1→R2→R4 (cost 20) over R1→R3→R4 (cost 200)

Quick reference

Routing Protocol Comparison

ProtocolMetricMax HopsAlgorithmType
RIP v2Hop count15Bellman-FordDistance vector
OSPFCost (bandwidth)UnlimitedDijkstra (SPF)Link state
EIGRPComposite metricUnlimitedDUALHybrid
IS-ISCostUnlimitedDijkstraLink state
BGPPolicy / attributesUnlimitedPath vectorPath vector

RIP's 15-hop limit makes it unsuitable for large networks. OSPF and EIGRP dominate modern enterprise deployments.

About these practice questions

Courseiva writes every 300-410 question from scratch — 1,401 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.