Courseiva
hardMultiple Choice

300-410 Practice Question: An engineer configures Control Plane Policing…

An engineer configures Control Plane Policing (CoPP) on a router. After applying the policy, OSPF neighbors go down. The engineer checks the policy and sees that OSPF packets are not explicitly matched. Which is the most likely explanation?

⚠ Common exam trap

Cisco often tests the concept that class-default in CoPP can be set to 'drop', and candidates may overlook that OSPF or other routing protocols are not explicitly matched, leading to neighbor loss.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The class-default is set to 'drop', and OSPF packets fall into class-default because they are not matched by any other class.

When Control Plane Policing (CoPP) is configured, traffic is classified into classes based on match criteria. If OSPF packets are not explicitly matched by any configured class, they fall into the default class (class-default). If the policy-map sets class-default to 'drop', all unmatched traffic, including OSPF hello packets (which use IP protocol 89), will be dropped. This causes OSPF neighbors to go down because the router stops receiving or sending OSPF control packets.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The class-default is set to 'drop', and OSPF packets fall into class-default because they are not matched by any other class.

    Why this is correct

    In Cisco CoPP, the control-plane policy processes packets by matching them against the configured classes in order. Since OSPF (IP protocol 89) is not matched by any higher-priority class in this scenario, it is classified into class-default. If class-default is set to 'drop,' all OSPF hello, database descriptor, link-state, and other control packets are silently discarded, preventing the router from maintaining or forming OSPF adjacency. This direct classification into a drop class is the definitive cause of OSPF neighbor loss.

  • ✗

    The CoPP policy uses 'police' in bps, but OSPF packets are small and exceed the rate limit.

    Why it's wrong here

    The claim that a bps-based police action would be exceeded by OSPF traffic is incorrect because OSPF hello packets are extremely small, typically under 100 bytes, and are transmitted at low frequency (every 10 seconds on broadcast links). Even a modest bps rate, such as 1000 bps, accommodates thousands of OSPF packets per second. For the police to cause neighbor loss, the rate would have to be set to a negligible value, which is not a normal configuration. The actual problem is not rate limiting but the class-default drop action.

  • ✗

    The CoPP policy is applied to the input direction, but OSPF packets are processed in the output direction.

    Why it's wrong here

    This option misapplies the directional concept of CoPP. OSPF packets are sent to the router's control plane as packets received inbound from neighbors, so an input direction policy is exactly where they are processed. CoPP can indeed be applied in the input direction for ingress control traffic and in the output direction for locally generated or forwarded traffic, but OSPF router-to-router packets are ingress. Thus, applying the policy to input is correct and does not explain the loss.

  • ✗

    The CoPP policy uses 'police' in pps, but OSPF hello packets are sent every 10 seconds, so they are not rate-limited.

    Why it's wrong here

    This option incorrectly analyzes the effect of a pps-based police on OSPF. While OSPF hellos are indeed sent every 10 seconds, the rate limit in pps applies to the average allowed packets per second; a very low pps value (e.g., 1 pps) still allows sporadic packets. However, OSPF adjacencies require not only hellos but also database description and link-state updates, which could occur in bursts and potentially exceed a tight pps limit. Even so, the far more likely cause is the class-default drop, not the pps police action.

Visual reference

R1 R2 R3 R4 10 100 10 100 OSPF picks R1→R2→R4 (cost 20) over R1→R3→R4 (cost 200)

Quick reference

Routing Protocol Comparison

ProtocolMetricMax HopsAlgorithmType
RIP v2Hop count15Bellman-FordDistance vector
OSPFCost (bandwidth)UnlimitedDijkstra (SPF)Link state
EIGRPComposite metricUnlimitedDUALHybrid
IS-ISCostUnlimitedDijkstraLink state
BGPPolicy / attributesUnlimitedPath vectorPath vector

RIP's 15-hop limit makes it unsuitable for large networks. OSPF and EIGRP dominate modern enterprise deployments.

About these practice questions

This 300-410 question is part of Courseiva's 1,401-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.