350-401 Security Practice Question
A network engineer configures Control Plane Policing on a Cisco IOS XE router acting as the BGP speaker for an ISP edge. The policy must protect the route processor from CPU exhaustion while still allowing BGP keepalives, SSH management, and SNMP polling from the NOC. Which CoPP design element is required to ensure BGP, SSH, and SNMP traffic is matched and rate-limited separately from transit traffic?
⚠ Common exam trap
Candidates often confuse interface-level QoS policing with control-plane policing, when only a policy attached under control-plane configuration mode protects the route processor.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A class-map that matches traffic with the 'control-plane' keyword and a policy-map applied with 'service-policy input' under the control-plane configuration mode.
CoPP protects the route processor by classifying traffic destined to the control plane and applying policers through an MQC policy attached under control-plane configuration mode. This allows BGP keepalives, SSH, and SNMP to be individually matched and rate-limited so that a flood of any one protocol cannot exhaust CPU resources while transit traffic is unaffected.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
An access list applied outbound on all interfaces using 'ip access-group' to block unwanted traffic before it reaches the route processor.
Why it's wrong here
Outbound ACLs on interfaces filter traffic leaving the device, not traffic destined to the route processor. They cannot rate-limit legitimate BGP, SSH, or SNMP traffic, and they do not provide the granular policer behavior that CoPP offers. Using an outbound ACL would also risk blocking transit traffic that customers depend on.
- ✗
An MQC policy attached to the WAN interface with 'service-policy input' so that all inbound traffic including BGP and SSH is policed at the interface level.
Why it's wrong here
Attaching the policy to the interface polices all inbound traffic, including transit packets that should be forwarded normally. Control plane protection is specifically about traffic destined to the route processor, not transit traffic. Interface-level policing would also drop legitimate customer traffic and does not isolate CPU-bound protocols like the CoPP feature is designed to do.
- ✗
A route-map with 'match ip next-hop' applied to the BGP neighbor to limit the number of prefixes received from each peer.
Why it's wrong here
A route-map with next-hop matching is used for BGP policy manipulation, such as filtering or modifying attributes, not for protecting the CPU from high-rate control-plane traffic. It does not police SSH or SNMP and has no effect on the packet rate delivered to the route processor. This mechanism is unrelated to CoPP functionality.
- ✓
A class-map that matches traffic with the 'control-plane' keyword and a policy-map applied with 'service-policy input' under the control-plane configuration mode.
Why this is correct
CoPP on IOS XE requires a class-map to identify control-plane-destined traffic, typically using an ACL or 'match protocol', and a policy-map that assigns a policer. The policy-map is attached to the control-plane with 'service-policy input', which is exactly how BGP, SSH, and SNMP destined to the route processor are rate-limited without affecting transit forwarding.
Go deeper
Related to this question
Learn chapter
VLANs and Spanning Tree Protocol Concepts
Key term
Control Plane Protection
Control Plane Protection (CoPP) is a security feature on Cisco routers and switches that filters traffic destined to the device's control plane to prevent attacks and ensure stability.
Key term
Control Plane Policing
Control Plane Policing is a Cisco security feature that protects a router or switch by rate-limiting the traffic that the device's processor must handle, preventing it from being overwhelmed.
About these practice questions
This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.