hardMultiple Choice
300-410 Practice Question: An engineer configures Control Plane Policing…
An engineer configures Control Plane Policing (CoPP) with a policy that denies all traffic in class-default. After applying the policy, BGP sessions to the router fail. What is the most likely explanation?
⚠ Common exam trap
The trap is assuming class-default always permits unmatched traffic; candidates forget that an explicit drop action overrides the implicit permit, causing control-plane protocol failures.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The class-default has an explicit 'drop' action, which overrides the implicit permit and drops all unmatched traffic, including BGP packets.
In a CoPP policy-map, class-default normally has an implicit permit, but if an explicit drop action is configured, it overrides that implicit behavior and drops all traffic not matched by earlier classes. BGP packets (TCP 179) that are not explicitly matched by a permit class therefore fall into class-default and are dropped, causing session failures. This is the most likely explanation given the described configuration.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The class-default has an explicit 'drop' action, which overrides the implicit permit and drops all unmatched traffic, including BGP packets.
Why this is correct
CoPP class-default carries an implicit permit, so configuring an explicit drop overrides it and discards every packet not matched by an earlier class. BGP keepalives and updates arrive unmatched, so the sessions to the router fail. The stem's deny-all class-default is therefore the direct cause.
- ✗
The CoPP policy was applied to the wrong interface, so BGP packets are dropped by the interface ACL.
Why it's wrong here
CoPP attaches to the control plane via a global service-policy, not to interfaces; interface attachment is invalid and BGP still fails because class-default drops the session packets. Interface ACLs are the tool for filtering transit data traffic, not control-plane policing.
- ✗
The BGP packets are matched by another class with a 'drop' action, but the class-default is irrelevant.
Why it's wrong here
CoPP evaluates classes in order, so a match in an earlier class with a drop action discards BGP before class-default is consulted; class-default's deny is not the cause. It is tempting to blame the explicit deny-all, but the real fault is the earlier class matching BGP traffic.
- ✗
The CoPP policy uses 'rate-limit' in bps instead of pps, causing BGP packets to be dropped due to rate limiting.
Why it's wrong here
CoPP matches on packets per second, not bandwidth, so a bps rate-limit argument is rejected by the parser and the policy fails to load, leaving no policing applied at all. Rate-limiting in bps belongs to interface CAR policies, where bandwidth shaping is the intended mechanism.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 300-410 question from scratch — 1,401 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.