350-401 Security Practice Question
A network engineer is configuring Control Plane Policing (CoPP) on a Cisco IOS XE router. The router has management SSH access, SNMP monitoring, and BGP peering. After applying the CoPP policy shown in the exhibit, the engineer notices that SNMP polling from the management station fails, while SSH and BGP remain operational. Which action should be taken to restore SNMP polling while maintaining control plane protection?
⚠ Common exam trap
The trap here is assuming that increasing the default policer rate or removing CoPP is acceptable, rather than adding the missing classification for SNMP.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Add a class-map that matches SNMP traffic (UDP port 161) and include it in the CoPP policy with an appropriate policer rate.
CoPP policies must explicitly classify and police all desired control plane traffic. If SNMP is not classified, it falls into the default class, which typically has a low rate and may drop legitimate SNMP. Adding a dedicated class-map for SNMP with an appropriate policer restores connectivity while preserving protection.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Increase the policer rate for the default class to allow all unmatched traffic, including SNMP.
Why it's wrong here
Increasing the default class policer rate may allow SNMP but also permits other unwanted traffic, potentially overwhelming the control plane. It does not specifically identify SNMP, so it is not a targeted solution. The default class should have a low rate to protect the control plane from unclassified traffic.
- ✗
Remove the CoPP policy from the control plane and reapply it after verifying SNMP connectivity.
Why it's wrong here
Removing CoPP entirely disables control plane protection, leaving the router vulnerable to DoS attacks. The goal is to restore SNMP without sacrificing security. This action would temporarily fix SNMP but violates the requirement to maintain control plane protection, and it does not address the missing SNMP classification.
- ✗
Configure an ACL to permit SNMP traffic and apply it to the management interface instead of the control plane.
Why it's wrong here
Applying an ACL to the management interface does not affect CoPP, which operates on the control plane path. SNMP packets would still be subject to CoPP and could be dropped if not explicitly classified. This does not resolve the CoPP classification issue and may introduce additional complexity.
- ✓
Add a class-map that matches SNMP traffic (UDP port 161) and include it in the CoPP policy with an appropriate policer rate.
Why this is correct
The CoPP policy likely does not have a class-map for SNMP, so SNMP packets fall into the default class and may be dropped by the default policer. Adding a specific class-map for SNMP (UDP 161) with a suitable policer ensures SNMP traffic is permitted at the required rate while still protecting the control plane from excessive SNMP traffic.
Go deeper
Related to this question
Learn chapter
Network Monitoring and Troubleshooting Tools
Key term
Control Plane Protection
Control Plane Protection (CoPP) is a security feature on Cisco routers and switches that filters traffic destined to the device's control plane to prevent attacks and ensure stability.
Key term
Control Plane Policing
Control Plane Policing is a Cisco security feature that protects a router or switch by rate-limiting the traffic that the device's processor must handle, preventing it from being overwhelmed.
About these practice questions
Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.