Courseiva
Security →mediumMultiple Choice

350-401 Security Practice Question

A network engineer is deploying Control Plane Policing (CoPP) on a Cisco IOS XE router that runs BGP, OSPF, and SSH management. The engineer applies a CoPP policy-map to the control plane with a class that matches BGP traffic and sets police rate 8000 conform-action transmit exceed-action drop. After applying the policy, BGP sessions intermittently flap during route convergence. Which action should the engineer take to resolve the issue while maintaining control plane protection?

⚠ Common exam trap

The trap here is assuming that any control plane drops must be caused by an attack rather than by an undersized policer that drops legitimate routing protocol traffic.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Increase the police rate for the BGP class or change the exceed-action to transmit, after verifying the offered rate.

BGP session flapping immediately after applying a policer that drops exceeded traffic points to legitimate BGP control packets being dropped because the configured rate is too low for convergence bursts. The correct remediation is to right-size the policer for the BGP class, either by raising the rate or by permitting excess traffic, after confirming the actual offered rate from the control plane.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Apply the CoPP policy to all router interfaces as an input service policy instead of to the control plane.

    Why it's wrong here

    CoPP is specifically applied to the control plane through the control-plane host configuration, not as an interface input policy. Applying it as an interface service policy would police transit traffic, not the traffic destined to the router's own control plane, and would not solve the BGP punt drops. The BGP class must remain attached to the control plane.

  • ✗

    Remove the CoPP policy from the control plane interface and rely on interface ACLs instead.

    Why it's wrong here

    Removing CoPP entirely eliminates the control plane protection that the design requires and does not address the root cause, which is an undersized policer for BGP. Interface ACLs do not police traffic punted to the control plane in the same way. The engineer should tune the policer rather than discard the protection mechanism.

  • ✓

    Increase the police rate for the BGP class or change the exceed-action to transmit, after verifying the offered rate.

    Why this is correct

    The intermittent BGP flaps during convergence indicate that legitimate BGP control traffic is exceeding the 8,000 pps police rate and being dropped by the exceed-action. Increasing the police rate or changing the exceed-action to transmit for the BGP class restores session stability while still policing other control plane traffic. Verification of the offered rate is essential to size the policer correctly.

  • ✗

    Change the CoPP policy to use priority queuing instead of policing for the BGP class.

    Why it's wrong here

    Control Plane Policing on IOS XE uses the modular QoS CLI policy-map with police actions; priority queuing is not a valid action for the control plane policy in this context. Replacing policing with a queueing construct would not preserve the intended rate-limiting behavior and is not supported for the punt path in this manner.

Visual reference

R1 R2 R3 R4 10 100 10 100 OSPF picks R1→R2→R4 (cost 20) over R1→R3→R4 (cost 200)

Quick reference

Routing Protocol Comparison

ProtocolMetricMax HopsAlgorithmType
RIP v2Hop count15Bellman-FordDistance vector
OSPFCost (bandwidth)UnlimitedDijkstra (SPF)Link state
EIGRPComposite metricUnlimitedDUALHybrid
IS-ISCostUnlimitedDijkstraLink state
BGPPolicy / attributesUnlimitedPath vectorPath vector

RIP's 15-hop limit makes it unsuitable for large networks. OSPF and EIGRP dominate modern enterprise deployments.

Go deeper

Related to this question

About these practice questions

Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.