350-401 Security Practice Question
A network administrator is configuring Control Plane Policing (CoPP) on a Cisco IOS XE router that peers BGP with two ISPs and runs SSH for management. The administrator wants to ensure that a sudden flood of BGP updates from a misbehaving peer does not starve the SSH management plane, while still allowing legitimate BGP traffic. Which CoPP configuration approach best meets this requirement?
⚠ Common exam trap
The trap here is assuming that combining related control-plane protocols into one class simplifies CoPP without sacrificing protection for management traffic.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Define separate class-maps for BGP and SSH, assign each to its own policy-map class with independent policers, then apply the policy-map globally with the service-policy command under control-plane.
Effective CoPP design uses granular classification so that different control-plane protocols are policed independently. BGP and SSH have very different traffic profiles, so placing them in separate classes with separate policers lets the administrator tightly limit BGP while reserving bandwidth for SSH. The policy-map must then be attached under the control-plane configuration to affect traffic punted to the route processor.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Apply an ACL that denies TCP port 179 from the ISP peer addresses directly to the BGP router process using the neighbor command.
Why it's wrong here
Using the neighbor command with an ACL filters BGP peering sessions but does not police the aggregate rate of control-plane traffic. It also cannot protect SSH because it only affects BGP neighbor relationships. This approach does not address the underlying issue of protecting the route processor from a flood of control-plane packets, and it would break legitimate BGP peering if misapplied.
- ✗
Define a class-map matching BGP (TCP port 179) and SSH (TCP port 22) in a single class, then apply a single policer with a low rate to that combined class.
Why it's wrong here
Combining BGP and SSH into one class means both protocols share the same policer. A BGP flood could exhaust the shared rate and cause SSH packets to be dropped, which directly defeats the goal of protecting management access. CoPP best practice is to separate control-plane protocols into distinct classes so each can be policed independently with rates tailored to its expected traffic profile.
- ✓
Define separate class-maps for BGP and SSH, assign each to its own policy-map class with independent policers, then apply the policy-map globally with the service-policy command under control-plane.
Why this is correct
Separating BGP and SSH into distinct classes with independent policers allows the administrator to rate-limit BGP traffic tightly while guaranteeing SSH a separate, protected bandwidth allocation. Applying the policy-map globally under the control-plane configuration mode enforces policing on all control-plane traffic destined to the route processor, satisfying the requirement to prevent BGP floods from starving management access.
- ✗
Configure a QoS policy-map with a priority queue for SSH and apply it outbound on the ISP-facing interfaces.
Why it's wrong here
A QoS policy applied outbound on data interfaces affects transit traffic, not traffic destined to the route processor itself. Control-plane traffic is handled by the control-plane policer, not by interface-level QoS. Additionally, priority queuing outbound on ISP links does not protect the CPU from a BGP flood, so this configuration would not prevent SSH from being starved.
Go deeper
Related to this question
Learn chapter
SDN Controllers and Cisco ACI
Key term
Control Plane Policing
Control Plane Policing is a Cisco security feature that protects a router or switch by rate-limiting the traffic that the device's processor must handle, preventing it from being overwhelmed.
Key term
Control Plane Protection
Control Plane Protection (CoPP) is a security feature on Cisco routers and switches that filters traffic destined to the device's control plane to prevent attacks and ensure stability.
About these practice questions
Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.