350-401 Security Practice Question
A network engineer is configuring Control Plane Policing (CoPP) on a Cisco IOS XE router to protect the route processor from excessive traffic. The router has management SSH access, BGP peering, and SNMP monitoring. After applying a CoPP policy, the engineer notices that BGP sessions flap intermittently, but SSH and SNMP remain stable. Which action should the engineer take to resolve the BGP flapping while maintaining control plane protection?
⚠ Common exam trap
The trap here is assuming that any CoPP issue requires disabling the policy entirely, rather than tuning the specific class that is causing drops.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Increase the rate limit for the BGP class in the CoPP policy.
When CoPP policers are too strict, protocols like BGP may experience drops leading to session flaps. Since SSH and SNMP are stable, the issue is isolated to the BGP class. Increasing the rate limit for that class allows BGP to operate within acceptable thresholds while still protecting the route processor. This maintains overall control plane security without sacrificing routing stability.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Remove the CoPP policy from the control plane interface.
Why it's wrong here
Removing the CoPP policy entirely would eliminate control plane protection, leaving the router vulnerable to DoS attacks. While it might stop BGP flapping, it defeats the purpose of deploying CoPP. The scenario requires maintaining control plane protection, so this action is not appropriate. A more granular adjustment is needed instead of disabling the feature.
- ✗
Reclassify BGP traffic into the SNMP class to share its rate limit.
Why it's wrong here
Reclassifying BGP into the SNMP class would cause BGP and SNMP to compete for the same policer, potentially causing SNMP instability and still not guaranteeing sufficient bandwidth for BGP. It also misrepresents the traffic type, complicating troubleshooting. The correct approach is to adjust the BGP class specifically, not merge it with an unrelated protocol class.
- ✓
Increase the rate limit for the BGP class in the CoPP policy.
Why this is correct
BGP flapping indicates that BGP control plane traffic is being dropped due to an overly restrictive policer. Increasing the rate limit for the BGP class allows legitimate BGP keepalives and updates to pass while still protecting the route processor from excessive BGP traffic. This is the targeted fix because SSH and SNMP are stable, confirming that only the BGP class needs adjustment.
- ✗
Enable QoS pre-classify on the BGP neighbor interface.
Why it's wrong here
QoS pre-classify is used for tunnel interfaces to copy the original packet header for classification before encryption. It does not affect CoPP policing of control plane traffic. Enabling it on a BGP neighbor interface would not resolve BGP flapping caused by CoPP drops. This option misunderstands the function of QoS pre-classify and its relevance to control plane policing.
Visual reference
Go deeper
Related to this question
Learn chapter
Network Monitoring and Troubleshooting Tools
Key term
Control Plane Policing
Control Plane Policing is a Cisco security feature that protects a router or switch by rate-limiting the traffic that the device's processor must handle, preventing it from being overwhelmed.
Key term
Control Plane Protection
Control Plane Protection (CoPP) is a security feature on Cisco routers and switches that filters traffic destined to the device's control plane to prevent attacks and ensure stability.
About these practice questions
One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.