350-401 Security Practice Question
A network administrator is configuring Control Plane Policing (CoPP) on a Cisco IOS XE router that runs BGP, SSH, and SNMP. The administrator needs to verify which traffic classes are being matched and how many packets are being dropped by the policy. Which command should be used to display the CoPP policy statistics and class-map information?
⚠ Common exam trap
Watch out — candidates often confuse interface-level policy statistics with control plane policy statistics, or assuming that show class-map displays counters when it only shows match criteria.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
show policy-map control-plane
The show policy-map control-plane command is specifically designed to display the CoPP policy configuration and per-class statistics, including matched and dropped packets. It allows the administrator to verify which traffic classes are being matched and how many packets are being dropped by the policy. The other commands either show only class-map definitions or interface-level policy statistics, which are not relevant to the control plane.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
show policy-map interface
Why it's wrong here
The show policy-map interface command displays policy-map statistics for interfaces, not for the control plane. CoPP applies to the control plane, so this command would not show the relevant statistics for the control plane policy and would not help verify CoPP drops.
- ✗
show class-map
Why it's wrong here
The show class-map command only displays the configured class-map definitions, such as match criteria, but does not show any statistics or whether the policy is actively dropping packets. It cannot confirm which traffic classes are being matched in the control plane or how many packets are being dropped.
- ✓
show policy-map control-plane
Why this is correct
This command displays the Control Plane policy-map configuration and the per-class packet statistics, including matched and dropped packets. It directly shows which traffic classes are being matched and how many packets are being dropped, which is exactly what the administrator needs to verify CoPP operation.
- ✗
show control-plane host open-ports
Why it's wrong here
This command lists open ports on the control plane host, which is unrelated to CoPP policy statistics. It does not show class-map matches or dropped packet counts for the CoPP policy, so it cannot verify which traffic classes are being policed or how many packets are dropped.
Go deeper
Related to this question
Learn chapter
EIGRP: Basics and Advanced Configuration
Key term
Control Plane Protection
Control Plane Protection (CoPP) is a security feature on Cisco routers and switches that filters traffic destined to the device's control plane to prevent attacks and ensure stability.
Key term
Control Plane Policing
Control Plane Policing is a Cisco security feature that protects a router or switch by rate-limiting the traffic that the device's processor must handle, preventing it from being overwhelmed.
About these practice questions
One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.