Courseiva
Security →hardMultiple Choice

350-401 Security Practice Question

A network engineer is configuring Control Plane Policing (CoPP) on a Cisco IOS XE router that runs BGP, SSH management, and SNMP. After applying a CoPP policy, BGP peering drops intermittently during route churn, but SSH and SNMP remain reachable. Which action should be taken to correct the issue while preserving control plane protection?

⚠ Common exam trap

The trap here is assuming that CoPP failures require disabling the policy, when the correct fix is to tune the specific class policer that is dropping legitimate traffic.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Increase the policer rate for the BGP class-map in the CoPP policy.

CoPP policers are applied per class, so a too-low rate for the BGP class causes legitimate BGP traffic to be dropped during churn while other classes remain unaffected. Raising the BGP policer rate restores BGP stability without removing control plane protection, whereas disabling CoPP or altering class-maps would either expose the router or misclassify traffic.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Increase the policer rate for the BGP class-map in the CoPP policy.

    Why this is correct

    BGP peering drops during route churn because the policer for the BGP class is too aggressive and is dropping legitimate control plane traffic. Adjusting the rate for the BGP class preserves protection for other traffic while allowing BGP keepalives and updates to pass. SSH and SNMP are unaffected because their classes have separate policers, so the fix should target the BGP class specifically.

  • ✗

    Change the BGP class-map match to include only SSH and SNMP traffic.

    Why it's wrong here

    Modifying the BGP class-map to match SSH and SNMP would misclassify management traffic and remove BGP traffic from its intended policer, which breaks the policy design. It would not address BGP drops and would cause management traffic to be policed by the wrong class. Class-maps must accurately match the traffic they are intended to control.

  • ✗

    Remove the CoPP policy from the control plane and reapply it after convergence.

    Why it's wrong here

    Removing CoPP entirely disables control plane protection and exposes the router to DoS attacks during the very period of route churn when the control plane is most vulnerable. This does not correct the underlying policer configuration and is not a valid long-term fix. The scenario requires preserving protection while fixing the BGP drop.

  • ✗

    Disable BGP route churn by setting the BGP scanner interval to a higher value.

    Why it's wrong here

    The BGP scanner interval affects how often BGP walks the routing table for next-hop validation and does not control the rate of BGP updates during churn. Changing it will not prevent CoPP from dropping BGP packets and may delay convergence. The root cause is the policer rate, not the scanner timer.

Go deeper

Related to this question

About these practice questions

One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.