Courseiva
Security →hardMultiple Choice

350-401 Security Practice Question

A network administrator is implementing Control Plane Policing (CoPP) on a Cisco ASR 1000 router to protect against DoS attacks. The router has a management plane that must remain accessible via SSH and SNMP, and a control plane that must process BGP and OSPF routing updates. The administrator applies a CoPP policy that rate-limits all traffic destined to the control plane to 1000 pps, except for traffic from trusted management subnets. After applying the policy, BGP sessions flap intermittently. What is the most likely cause?

⚠ Common exam trap

The trap here is assuming that a single rate limit for all control plane traffic is safe, without considering the specific needs of routing protocols like BGP.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The CoPP policy is rate-limiting BGP keepalives and updates, causing session timeouts.

CoPP policies must be carefully designed to avoid throttling critical control plane protocols. A blanket rate limit of 1000 pps may be insufficient for BGP, especially if there are many peers or frequent updates. BGP keepalives are sent every 60 seconds by default, but updates and other messages can burst. If the policer drops these, sessions can flap. The correct approach is to create granular class-maps that match BGP and other routing protocols, and assign appropriate rates or exempt them from policing.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The CoPP policy is rate-limiting BGP keepalives and updates, causing session timeouts.

    Why this is correct

    CoPP policies that apply a blanket rate limit to all control plane traffic can inadvertently throttle essential routing protocol messages like BGP keepalives and updates. If the rate limit is too low or not exempting BGP, sessions may flap due to missed keepalives or delayed updates. The policy must be fine-tuned to allow sufficient bandwidth for routing protocols.

  • ✗

    The CoPP policy is applied to the data plane instead of the control plane, causing routing updates to be dropped.

    Why it's wrong here

    CoPP is applied to the control plane by definition; applying it to the data plane would not affect control plane traffic. The scenario indicates that CoPP was applied to protect the control plane, so the policy is in the correct location. The flapping is due to rate limiting of BGP traffic, not misapplication.

  • ✗

    The CoPP policy is incorrectly classifying SSH traffic as BGP, leading to rate limiting of SSH.

    Why it's wrong here

    Misclassification would affect SSH access, not BGP sessions. The scenario states that SSH must remain accessible; if SSH were rate-limited, the symptom would be SSH connection issues, not BGP flapping. The problem described is specifically BGP session instability, pointing to BGP traffic being policed.

  • ✗

    The CoPP policy is dropping SNMP traps, causing BGP to lose its peer state.

    Why it's wrong here

    SNMP traps are management plane traffic and have no direct impact on BGP session state. BGP sessions are maintained by keepalive messages and TCP connections. Dropping SNMP traps would affect monitoring but not cause BGP flapping. The issue is more likely related to control plane traffic associated with BGP itself.

Visual reference

R1 R2 R3 R4 10 100 10 100 OSPF picks R1→R2→R4 (cost 20) over R1→R3→R4 (cost 200)

Quick reference

Routing Protocol Comparison

ProtocolMetricMax HopsAlgorithmType
RIP v2Hop count15Bellman-FordDistance vector
OSPFCost (bandwidth)UnlimitedDijkstra (SPF)Link state
EIGRPComposite metricUnlimitedDUALHybrid
IS-ISCostUnlimitedDijkstraLink state
BGPPolicy / attributesUnlimitedPath vectorPath vector

RIP's 15-hop limit makes it unsuitable for large networks. OSPF and EIGRP dominate modern enterprise deployments.

Go deeper

Related to this question

About these practice questions

One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.