350-401 Security Practice Question
A network engineer is configuring Control Plane Policing (CoPP) on a Cisco IOS-XE router that also runs OSPF, BGP, and SSH management. The engineer needs to protect the control plane while ensuring that routing protocol traffic and management sessions are not disrupted. Which CoPP design approach best meets these requirements?
⚠ Common exam trap
The trap here is assuming a single conservative CoPP policer is sufficient, when it actually throttles legitimate routing and management traffic along with attacks.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create multiple granular classes (for example, routing protocols, management, and exception traffic) and apply class-specific policers, while ensuring control plane traffic is not dropped by the default class.
CoPP protects the route processor by classifying and policing traffic destined to the control plane. Granular classes allow routing protocols and management traffic to receive enough bandwidth, while the default class should be configured not to drop so that legitimate unclassified traffic survives. This design balances protection with operational stability for OSPF, BGP, and SSH.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure a CoPP policy that only rate-limits ICMP and Telnet, leaving all other control plane traffic unclassified and unpolished.
Why it's wrong here
Limiting the policy to ICMP and Telnet leaves OSPF, BGP, SSH, SNMP, and other control plane protocols completely unprotected, so a flood of those protocols could overwhelm the CPU. It also fails to provide a default class that handles unmatched traffic, meaning the policy does not comprehensively protect the control plane as required.
- ✗
Apply a single CoPP policy that classifies all control plane traffic into one class and rate-limits it to a conservative value.
Why it's wrong here
A single conservative class would throttle legitimate OSPF hello packets, BGP keepalives, and SSH sessions along with any attack traffic, causing protocol adjacency resets and dropped management connections. CoPP is most effective when traffic is separated into granular classes so that critical protocols receive sufficient bandwidth while suspicious or non-essential traffic is tightly policed.
- ✗
Apply the CoPP policy to all data plane interfaces in the inbound direction, which will indirectly protect the control plane.
Why it's wrong here
CoPP is applied globally to the control plane using the service-policy input command under control-plane configuration, not to individual data plane interfaces. Applying a policy inbound on data interfaces would police transit traffic, not traffic destined to the router itself, so it would not protect the control plane CPU from protocol floods or management attacks.
- ✓
Create multiple granular classes (for example, routing protocols, management, and exception traffic) and apply class-specific policers, while ensuring control plane traffic is not dropped by the default class.
Why this is correct
Granular classification lets the engineer allocate adequate bandwidth to OSPF, BGP, and SSH while policing less critical or malicious traffic more aggressively. The default class should be configured to not drop, or to drop only after all classified traffic is serviced, so that unclassified but legitimate control plane packets are not silently discarded and routing or management sessions remain stable.
Visual reference
Quick reference
Routing Protocol Comparison
| Protocol | Metric | Max Hops | Algorithm | Type |
|---|---|---|---|---|
| RIP v2 | Hop count | 15 | Bellman-Ford | Distance vector |
| OSPF | Cost (bandwidth) | Unlimited | Dijkstra (SPF) | Link state |
| EIGRP | Composite metric | Unlimited | DUAL | Hybrid |
| IS-IS | Cost | Unlimited | Dijkstra | Link state |
| BGP | Policy / attributes | Unlimited | Path vector | Path vector |
RIP's 15-hop limit makes it unsuitable for large networks. OSPF and EIGRP dominate modern enterprise deployments.
Go deeper
Related to this question
Learn chapter
SDN Controllers and Cisco ACI
Key term
Control Plane Policing
Control Plane Policing is a Cisco security feature that protects a router or switch by rate-limiting the traffic that the device's processor must handle, preventing it from being overwhelmed.
Key term
Control Plane Protection
Control Plane Protection (CoPP) is a security feature on Cisco routers and switches that filters traffic destined to the device's control plane to prevent attacks and ensure stability.
About these practice questions
Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.