hardMultiple Choice
300-410 Practice Question: An engineer configures Control Plane Policing…
An engineer configures Control Plane Policing (CoPP) on a router. After applying the policy, OSPF neighbors go down. The engineer checks the policy and sees that OSPF packets are not explicitly matched. Which is the most likely explanation?
⚠ Common exam trap
Cisco often tests the concept that class-default in CoPP can be set to 'drop', and candidates may overlook that OSPF or other routing protocols are not explicitly matched, leading to neighbor loss.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The class-default is set to 'drop', and OSPF packets fall into class-default because they are not matched by any other class.
When Control Plane Policing (CoPP) is configured, traffic is classified into classes based on match criteria. If OSPF packets are not explicitly matched by any configured class, they fall into the default class (class-default). If the policy-map sets class-default to 'drop', all unmatched traffic, including OSPF hello packets (which use IP protocol 89), will be dropped. This causes OSPF neighbors to go down because the router stops receiving or sending OSPF control packets.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The class-default is set to 'drop', and OSPF packets fall into class-default because they are not matched by any other class.
Why this is correct
In Cisco CoPP, the control-plane policy processes packets by matching them against the configured classes in order. Since OSPF (IP protocol 89) is not matched by any higher-priority class in this scenario, it is classified into class-default. If class-default is set to 'drop,' all OSPF hello, database descriptor, link-state, and other control packets are silently discarded, preventing the router from maintaining or forming OSPF adjacency. This direct classification into a drop class is the definitive cause of OSPF neighbor loss.
- ✗
The CoPP policy uses 'police' in bps, but OSPF packets are small and exceed the rate limit.
Why it's wrong here
The claim that a bps-based police action would be exceeded by OSPF traffic is incorrect because OSPF hello packets are extremely small, typically under 100 bytes, and are transmitted at low frequency (every 10 seconds on broadcast links). Even a modest bps rate, such as 1000 bps, accommodates thousands of OSPF packets per second. For the police to cause neighbor loss, the rate would have to be set to a negligible value, which is not a normal configuration. The actual problem is not rate limiting but the class-default drop action.
- ✗
The CoPP policy is applied to the input direction, but OSPF packets are processed in the output direction.
Why it's wrong here
This option misapplies the directional concept of CoPP. OSPF packets are sent to the router's control plane as packets received inbound from neighbors, so an input direction policy is exactly where they are processed. CoPP can indeed be applied in the input direction for ingress control traffic and in the output direction for locally generated or forwarded traffic, but OSPF router-to-router packets are ingress. Thus, applying the policy to input is correct and does not explain the loss.
- ✗
The CoPP policy uses 'police' in pps, but OSPF hello packets are sent every 10 seconds, so they are not rate-limited.
Why it's wrong here
This option incorrectly analyzes the effect of a pps-based police on OSPF. While OSPF hellos are indeed sent every 10 seconds, the rate limit in pps applies to the average allowed packets per second; a very low pps value (e.g., 1 pps) still allows sporadic packets. However, OSPF adjacencies require not only hellos but also database description and link-state updates, which could occur in bursts and potentially exceed a tight pps limit. Even so, the far more likely cause is the class-default drop, not the pps police action.
Visual reference
Quick reference
Routing Protocol Comparison
| Protocol | Metric | Max Hops | Algorithm | Type |
|---|---|---|---|---|
| RIP v2 | Hop count | 15 | Bellman-Ford | Distance vector |
| OSPF | Cost (bandwidth) | Unlimited | Dijkstra (SPF) | Link state |
| EIGRP | Composite metric | Unlimited | DUAL | Hybrid |
| IS-IS | Cost | Unlimited | Dijkstra | Link state |
| BGP | Policy / attributes | Unlimited | Path vector | Path vector |
RIP's 15-hop limit makes it unsuitable for large networks. OSPF and EIGRP dominate modern enterprise deployments.
Go deeper
Related to this question
About these practice questions
This 300-410 question is part of Courseiva's 1,401-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.