Courseiva
Security →hardMultiple Choice

350-401 Security Practice Question

A network engineer is configuring Control Plane Policing (CoPP) on a Cisco IOS XE router to protect against excessive ARP traffic. The engineer applies the following policy:

policy-map COPP-POLICY

class ARP-CLASS

police 8000 conform-action transmit exceed-action drop

After applying the service-policy to the control-plane, the engineer notices that legitimate ARP requests are being dropped during peak hours. Which action should the engineer take to resolve this issue while maintaining protection?

⚠ Common exam trap

The trap here is thinking that any drop means the policy is too strict and should be disabled, rather than tuning the rate to match legitimate traffic patterns.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Increase the police rate to a higher value that accommodates peak ARP traffic while still limiting excessive bursts.

CoPP police rates must be tuned to allow legitimate control-plane traffic while blocking excess. A rate of 8000 bps is insufficient for ARP during peak hours, so increasing the rate to a realistic peak value resolves drops while preserving protection. Changing exceed-action to transmit removes protection, moving the policy to the data plane is ineffective, and splitting classes without raising the rate does not fix the underlying issue.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Add a class-map that matches ARP replies and apply a separate police rate to that class.

    Why it's wrong here

    Separating ARP replies into a different class does not address the root cause: the overall ARP police rate is too low. Legitimate ARP requests are being dropped, so simply splitting classes without increasing the aggregate rate for ARP traffic would still result in drops. The rate must be increased to accommodate peak loads.

  • ✓

    Increase the police rate to a higher value that accommodates peak ARP traffic while still limiting excessive bursts.

    Why this is correct

    The police rate of 8000 bps is too low for peak ARP traffic, causing legitimate ARP requests to be dropped. Increasing the rate to a value that matches normal peak traffic while still providing an upper bound protects the control plane without dropping legitimate traffic. This is the correct tuning approach for CoPP.

  • ✗

    Remove the service-policy from the control-plane and apply it to the data plane instead.

    Why it's wrong here

    CoPP is designed to police traffic destined to the control plane (the route processor). Applying the policy to the data plane would not protect the control plane and would affect transit traffic instead. The issue is with the policing rate, not the attachment point, so moving it would not solve the problem.

  • ✗

    Change the exceed-action to transmit so that all ARP packets are allowed through.

    Why it's wrong here

    Setting exceed-action to transmit effectively disables policing for that class, allowing unlimited ARP traffic and defeating the purpose of CoPP. This would remove protection against ARP floods, which is not acceptable when the goal is to maintain protection while resolving drops of legitimate traffic.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

Go deeper

Related to this question

About these practice questions

Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.