350-401 Security Practice Question
Network Topology
A network engineer applies the above CoPP policy on a router. The router has BGP peers, SSH management, and SNMP monitoring. After applying this policy, which traffic will be affected?
⚠ Common exam trap
Cisco often tests the misconception that CoPP affects data plane traffic or that only management protocols like SSH are impacted, when in fact control plane policing targets all control plane packets, including routing protocol keepalives.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
BGP sessions may flap due to dropped keepalives.
The CoPP policy applies to control plane traffic, not data plane traffic. BGP keepalives are control plane packets; if the policy drops or rate-limits them, BGP sessions may time out and flap. The correct answer is A because BGP keepalives are essential for maintaining neighbor adjacency, and dropping them directly causes session instability.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
BGP sessions may flap due to dropped keepalives.
Why this is correct
BGP keepalives are sent periodically (typically every 60 seconds) and matched by the CoPP BGP class because they are control-plane TCP traffic to/from port 179. If the policer's committed rate is exceeded—even briefly—the excess keepalives are dropped. After a few missed keepalives, the BGP hold timer (default 180 seconds) expires, causing the peer session to flap. The same policer can also drop BGP route updates, which may cause instability beyond just keepalives.
- ✗
Data plane traffic will be dropped.
Why it's wrong here
Data plane traffic is traffic forwarded through the router from one interface to another, never destined to the router itself. CoPP operates on the control plane, which is the path to the routing processor (RP), and does not police transit forwarding in hardware (e.g., CEF/ASIC lookups). Therefore, user data packets that simply pass through the router are not inspected or rate-limited by this CoPP policy. Its entire effect is confined to traffic addressed to the router's own IP addresses or protocol management traffic.
- ✗
Only SSH sessions will be rate-limited.
Why it's wrong here
The CoPP policy uses a class-map that identifies multiple control-plane protocols; SSH is merely one of them. In addition to SSH, the policy typically classifies BGP, SNMP, OSPF, EIGRP, ICMP to the router, and similar management protocols. Setting a police per class or a single aggregate policer across all classes means SSH is not the only traffic rate-limited. Thus, it is incorrect to say 'only SSH' will be rate-limited; every matched protocol is subject to the same applied policing.
- ✗
SNMP and SSH will be unaffected because they are explicitly permitted.
Why it's wrong here
In CoPP configuration, the MQC action 'permit' (or 'transmit') within a police statement does not mean exempt from rate limiting. The policer's conform-action transmit simply sends packets that are within the committed burst; any excess exceeds the policer and triggers the exceed-action (typically drop). SNMP and SSH traffic classified as control-plane and matched are therefore subject to the policer's committed rate and burst. If the traffic rate surpasses that threshold, even 'explicitly permitted' packets are dropped, so the traffic can be affected and rates may be throttled.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.