350-401 Security Practice Question
A network engineer is deploying Control Plane Policing (CoPP) on a Cisco IOS XE router that runs BGP, OSPF, and SSH management. The engineer applies a CoPP policy-map to the control plane with a class that matches BGP traffic and sets police rate 8000 conform-action transmit exceed-action drop. After applying the policy, BGP sessions intermittently flap during route convergence. Which action should the engineer take to resolve the issue while maintaining control plane protection?
⚠ Common exam trap
The trap here is assuming that any control plane drops must be caused by an attack rather than by an undersized policer that drops legitimate routing protocol traffic.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Increase the police rate for the BGP class or change the exceed-action to transmit, after verifying the offered rate.
BGP session flapping immediately after applying a policer that drops exceeded traffic points to legitimate BGP control packets being dropped because the configured rate is too low for convergence bursts. The correct remediation is to right-size the policer for the BGP class, either by raising the rate or by permitting excess traffic, after confirming the actual offered rate from the control plane.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Apply the CoPP policy to all router interfaces as an input service policy instead of to the control plane.
Why it's wrong here
CoPP is specifically applied to the control plane through the control-plane host configuration, not as an interface input policy. Applying it as an interface service policy would police transit traffic, not the traffic destined to the router's own control plane, and would not solve the BGP punt drops. The BGP class must remain attached to the control plane.
- ✗
Remove the CoPP policy from the control plane interface and rely on interface ACLs instead.
Why it's wrong here
Removing CoPP entirely eliminates the control plane protection that the design requires and does not address the root cause, which is an undersized policer for BGP. Interface ACLs do not police traffic punted to the control plane in the same way. The engineer should tune the policer rather than discard the protection mechanism.
- ✓
Increase the police rate for the BGP class or change the exceed-action to transmit, after verifying the offered rate.
Why this is correct
The intermittent BGP flaps during convergence indicate that legitimate BGP control traffic is exceeding the 8,000 pps police rate and being dropped by the exceed-action. Increasing the police rate or changing the exceed-action to transmit for the BGP class restores session stability while still policing other control plane traffic. Verification of the offered rate is essential to size the policer correctly.
- ✗
Change the CoPP policy to use priority queuing instead of policing for the BGP class.
Why it's wrong here
Control Plane Policing on IOS XE uses the modular QoS CLI policy-map with police actions; priority queuing is not a valid action for the control plane policy in this context. Replacing policing with a queueing construct would not preserve the intended rate-limiting behavior and is not supported for the punt path in this manner.
Visual reference
Quick reference
Routing Protocol Comparison
| Protocol | Metric | Max Hops | Algorithm | Type |
|---|---|---|---|---|
| RIP v2 | Hop count | 15 | Bellman-Ford | Distance vector |
| OSPF | Cost (bandwidth) | Unlimited | Dijkstra (SPF) | Link state |
| EIGRP | Composite metric | Unlimited | DUAL | Hybrid |
| IS-IS | Cost | Unlimited | Dijkstra | Link state |
| BGP | Policy / attributes | Unlimited | Path vector | Path vector |
RIP's 15-hop limit makes it unsuitable for large networks. OSPF and EIGRP dominate modern enterprise deployments.
Go deeper
Related to this question
Learn chapter
SDN Controllers and Cisco ACI
Key term
Control Plane Policing
Control Plane Policing is a Cisco security feature that protects a router or switch by rate-limiting the traffic that the device's processor must handle, preventing it from being overwhelmed.
Key term
Control Plane Protection
Control Plane Protection (CoPP) is a security feature on Cisco routers and switches that filters traffic destined to the device's control plane to prevent attacks and ensure stability.
About these practice questions
Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.