Courseiva
Security →hardMultiple Choice

350-401 Security Practice Question

A network engineer is deploying Control Plane Policing (CoPP) on a Cisco IOS XE router. The router runs BGP, OSPF, SSH management, and SNMP. After applying a CoPP policy that rate-limits all control-plane traffic to 1000 pps, BGP sessions flap and OSPF adjacencies reset during peak traffic. Which action should the engineer take to resolve the problem while maintaining control-plane protection?

⚠ Common exam trap

The trap here is treating CoPP as a single-rate mechanism and either removing it or inflating the global limit instead of using granular per-protocol classification, which is the intended design.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create separate class-maps for BGP, OSPF, SSH, and SNMP, and apply protocol-specific rate limits within the policy-map.

CoPP uses a modular QoS CLI (MQC) structure with class-maps to identify traffic types and a policy-map to apply policers per class. A single policer for all control-plane traffic causes legitimate routing protocol updates to compete with management and monitoring traffic, leading to drops and session resets. The correct solution is to define separate class-maps for BGP, OSPF, SSH, and SNMP, then assign differentiated rate limits in the policy-map. This preserves control-plane protection while ensuring routing protocols receive adequate bandwidth.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Create separate class-maps for BGP, OSPF, SSH, and SNMP, and apply protocol-specific rate limits within the policy-map.

    Why this is correct

    CoPP works by classifying traffic into distinct classes and applying individual policers. Creating separate class-maps for each protocol allows the engineer to set appropriate rates for BGP and OSPF while still policing SSH and SNMP. This targeted approach protects the control plane without starving routing protocols, resolving the flapping while maintaining security.

  • ✗

    Enable Control Plane Protection (CPPr) with the aggregate option to automatically prioritize routing protocols.

    Why it's wrong here

    CPPr provides additional control-plane protection mechanisms such as port-filtering and queue-thresholding, but the aggregate option does not automatically prioritize routing protocols over other traffic. It still requires granular classification to distinguish BGP and OSPF from SSH and SNMP. Simply enabling CPPr aggregate would not resolve the flapping caused by a single policer applied to all traffic.

  • ✗

    Increase the global CoPP rate limit to 5000 pps to accommodate all control-plane protocols.

    Why it's wrong here

    Raising the global rate limit may temporarily stop the flapping, but it defeats the purpose of CoPP by allowing excessive traffic that could overwhelm the control plane during an attack. It also does not distinguish between legitimate routing protocol traffic and malicious traffic. A blanket increase is not a targeted fix and leaves the control plane vulnerable to abuse.

  • ✗

    Remove the CoPP policy from the control plane and rely on QoS policies on data interfaces instead.

    Why it's wrong here

    Removing CoPP eliminates control-plane protection entirely, leaving the router vulnerable to DoS attacks targeting the CPU. Interface QoS policies operate on data-plane traffic and do not police traffic destined to the control plane. This approach fails to meet the requirement of maintaining control-plane protection while fixing the routing protocol issue.

Visual reference

R1 R2 R3 R4 10 100 10 100 OSPF picks R1→R2→R4 (cost 20) over R1→R3→R4 (cost 200)

Quick reference

Routing Protocol Comparison

ProtocolMetricMax HopsAlgorithmType
RIP v2Hop count15Bellman-FordDistance vector
OSPFCost (bandwidth)UnlimitedDijkstra (SPF)Link state
EIGRPComposite metricUnlimitedDUALHybrid
IS-ISCostUnlimitedDijkstraLink state
BGPPolicy / attributesUnlimitedPath vectorPath vector

RIP's 15-hop limit makes it unsuitable for large networks. OSPF and EIGRP dominate modern enterprise deployments.

Go deeper

Related to this question

About these practice questions

Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.