Courseiva
Security →mediumMultiple Choice

350-401 Security Practice Question

Network Topology
Access-list for CoPP!Class-mapPolicy-mapApply to control-planeRefer to the exhibit.ip access-list extended COPP_ACLclass-map match-all COPP_CLASSmatch access-group name COPP_ACLpolicy-map COPP_POLICYclass COPP_CLASSpolice cir 8000 bc 1500conform-action transmitexceed-action dropcontrol-planeservice-policy input COPP_POLICY

A network engineer applies the above CoPP policy on a router. The router has BGP peers, SSH management, and SNMP monitoring. After applying this policy, which traffic will be affected?

⚠ Common exam trap

Cisco often tests the misconception that CoPP affects data plane traffic or that only management protocols like SSH are impacted, when in fact control plane policing targets all control plane packets, including routing protocol keepalives.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

BGP sessions may flap due to dropped keepalives.

The CoPP policy applies to control plane traffic, not data plane traffic. BGP keepalives are control plane packets; if the policy drops or rate-limits them, BGP sessions may time out and flap. The correct answer is A because BGP keepalives are essential for maintaining neighbor adjacency, and dropping them directly causes session instability.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    BGP sessions may flap due to dropped keepalives.

    Why this is correct

    BGP keepalives are sent periodically (typically every 60 seconds) and matched by the CoPP BGP class because they are control-plane TCP traffic to/from port 179. If the policer's committed rate is exceeded—even briefly—the excess keepalives are dropped. After a few missed keepalives, the BGP hold timer (default 180 seconds) expires, causing the peer session to flap. The same policer can also drop BGP route updates, which may cause instability beyond just keepalives.

  • ✗

    Data plane traffic will be dropped.

    Why it's wrong here

    Data plane traffic is traffic forwarded through the router from one interface to another, never destined to the router itself. CoPP operates on the control plane, which is the path to the routing processor (RP), and does not police transit forwarding in hardware (e.g., CEF/ASIC lookups). Therefore, user data packets that simply pass through the router are not inspected or rate-limited by this CoPP policy. Its entire effect is confined to traffic addressed to the router's own IP addresses or protocol management traffic.

  • ✗

    Only SSH sessions will be rate-limited.

    Why it's wrong here

    The CoPP policy uses a class-map that identifies multiple control-plane protocols; SSH is merely one of them. In addition to SSH, the policy typically classifies BGP, SNMP, OSPF, EIGRP, ICMP to the router, and similar management protocols. Setting a police per class or a single aggregate policer across all classes means SSH is not the only traffic rate-limited. Thus, it is incorrect to say 'only SSH' will be rate-limited; every matched protocol is subject to the same applied policing.

  • ✗

    SNMP and SSH will be unaffected because they are explicitly permitted.

    Why it's wrong here

    In CoPP configuration, the MQC action 'permit' (or 'transmit') within a police statement does not mean exempt from rate limiting. The policer's conform-action transmit simply sends packets that are within the committed burst; any excess exceeds the policer and triggers the exceed-action (typically drop). SNMP and SSH traffic classified as control-plane and matched are therefore subject to the policer's committed rate and burst. If the traffic rate surpasses that threshold, even 'explicitly permitted' packets are dropped, so the traffic can be affected and rates may be throttled.

About these practice questions

Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.