Courseiva
Security →mediumMultiple Choice

350-401 Security Practice Question

A network administrator is deploying Control Plane Policing (CoPP) on a Cisco IOS XE router that runs BGP, OSPF, and SSH management. The administrator wants to protect the route processor from excessive control-plane traffic while still allowing legitimate routing protocol and management traffic. The administrator creates a class map that matches BGP, OSPF, and SSH traffic and applies a police action with a committed information rate. Which additional configuration element is required to complete the CoPP implementation?

⚠ Common exam trap

The trap here is assuming that applying a policy map to physical interfaces protects the control plane, when CoPP specifically requires attachment under control-plane configuration mode.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Apply the policy map to the control plane using the service-policy input command under control-plane configuration mode.

CoPP is implemented by defining class maps to identify control-plane traffic, a policy map to apply actions such as police, and then attaching the policy map to the control plane with service-policy input under control-plane configuration mode. Without that attachment, the policy is never applied to control-plane traffic, so the route processor remains vulnerable to excessive protocol or management packets.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure a route map that matches the control-plane protocols and reference it in the policy map.

    Why it's wrong here

    Route maps are used for routing policy decisions, not for classifying control-plane traffic for CoPP. CoPP classification uses class maps with match statements such as match access-group or match protocol, so a route map is not the required element.

  • ✗

    Apply the policy map to all physical interfaces using the service-policy input command under interface configuration mode.

    Why it's wrong here

    Applying the policy map to physical interfaces affects transit data-plane traffic, not traffic destined to the route processor. CoPP specifically targets control-plane traffic, so interface-level application would not protect the CPU from routing protocol or management floods.

  • ✓

    Apply the policy map to the control plane using the service-policy input command under control-plane configuration mode.

    Why this is correct

    CoPP requires a policy map to be attached to the control plane with service-policy input under control-plane configuration mode. Without this attachment, the class maps and policy map exist but are not enforced on control-plane traffic, leaving the route processor unprotected.

  • ✗

    Enable NetFlow on the router to export control-plane traffic statistics to a collector.

    Why it's wrong here

    NetFlow provides traffic visibility and accounting but does not enforce policing or protect the control plane. While it can help monitor traffic patterns, it is not a required configuration element for CoPP and does not rate-limit control-plane packets.

Visual reference

R1 R2 R3 R4 10 100 10 100 OSPF picks R1→R2→R4 (cost 20) over R1→R3→R4 (cost 200)

Quick reference

Routing Protocol Comparison

ProtocolMetricMax HopsAlgorithmType
RIP v2Hop count15Bellman-FordDistance vector
OSPFCost (bandwidth)UnlimitedDijkstra (SPF)Link state
EIGRPComposite metricUnlimitedDUALHybrid
IS-ISCostUnlimitedDijkstraLink state
BGPPolicy / attributesUnlimitedPath vectorPath vector

RIP's 15-hop limit makes it unsuitable for large networks. OSPF and EIGRP dominate modern enterprise deployments.

Go deeper

Related to this question

About these practice questions

One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.