350-401 Infrastructure Practice Question
A network engineer is deploying a new Cisco Catalyst 9000 switch stack and wants to protect the control plane from excessive ARP traffic that could overwhelm the CPU during a broadcast storm. The engineer needs to limit the rate of ARP packets sent to the CPU to 500 packets per second and drop the excess. Which feature should be configured on the switch?
⚠ Common exam trap
The trap here is assuming that storm control or DAI can rate-limit ARP traffic to the CPU, when they actually operate at the data plane or for security validation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Control Plane Policing (CoPP) with a class-map matching ARP
Control Plane Policing (CoPP) is designed to protect the CPU by rate-limiting traffic destined to the control plane. In this scenario, the engineer needs to limit ARP packets to 500 pps, which is exactly what CoPP can do by matching ARP in a class-map and applying a policer. Other features like storm control or DAI do not provide this granular control-plane protection.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Dynamic ARP Inspection (DAI) on all VLANs
Why it's wrong here
DAI validates ARP packets against the DHCP snooping binding database to prevent ARP spoofing, but it does not rate-limit ARP traffic to the CPU. It is a security feature, not a control-plane rate-limiting mechanism. Thus, it does not address the excessive ARP traffic issue described.
- ✓
Control Plane Policing (CoPP) with a class-map matching ARP
Why this is correct
CoPP allows the engineer to police traffic destined to the control plane, including ARP packets. By creating a class-map that matches ARP and a policy-map that sets a rate limit of 500 pps with a drop action, the switch CPU is protected from excessive ARP. This is the correct feature for rate-limiting control-plane traffic.
- ✗
IP Source Guard on all access ports
Why it's wrong here
IP Source Guard filters IP traffic based on the DHCP snooping binding table to prevent IP spoofing. It does not inspect or rate-limit ARP packets, and it operates on data-plane traffic. Therefore, it cannot limit ARP packets destined to the CPU.
- ✗
Storm control configured on all access ports
Why it's wrong here
Storm control limits broadcast, multicast, or unknown unicast traffic on a per-port basis, but it does not specifically target traffic destined to the CPU. It operates at the data plane and cannot granularly police ARP packets sent to the control plane. Therefore, it does not meet the requirement of limiting ARP to the CPU.
Go deeper
Related to this question
Learn chapter
SDN Controllers and Cisco ACI
Key term
Control Plane Policing
Control Plane Policing is a Cisco security feature that protects a router or switch by rate-limiting the traffic that the device's processor must handle, preventing it from being overwhelmed.
Key term
Control Plane Protection
Control Plane Protection (CoPP) is a security feature on Cisco routers and switches that filters traffic destined to the device's control plane to prevent attacks and ensure stability.
About these practice questions
Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.