350-401 Security Practice Question
A network engineer is deploying Control Plane Policing on a Cisco IOS XE router that runs BGP, SSH management, and SNMP monitoring. The engineer must ensure that BGP keepalives are never dropped even during a control-plane flood, while SSH and SNMP traffic should be rate-limited. Which CoPP configuration element accomplishes this requirement?
⚠ Common exam trap
The trap here is assuming that every class in a CoPP policy-map must have a police action, when in fact a class without a police action passes traffic unconditionally.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a class-map matching BGP traffic and reference it in the control-plane policy-map without applying any police action.
CoPP works by classifying control-plane traffic and applying actions, most commonly 'police'. Any class that has no police action is effectively passed without rate limiting, which is exactly what is needed for BGP keepalives that must never be dropped. SSH and SNMP classes can then receive 'police' actions with appropriate conform/exceed handling. This design isolates critical routing protocol traffic from the effects of a control-plane flood.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create a class-map matching BGP traffic with a 'police' action and assign it to the control-plane policy-map.
Why it's wrong here
Applying a police action to BGP traffic would rate-limit or drop BGP packets once the configured rate is exceeded, which directly violates the requirement that keepalives must never be dropped. Policing BGP is appropriate only when you want to cap its bandwidth, not when you need guaranteed delivery during a flood. A 'police' action cannot exempt traffic from drops.
- ✗
Create a class-map matching BGP traffic and apply a 'police' action with a conform-action of 'transmit' and an exceed-action of 'transmit'.
Why it's wrong here
Configuring both conform and exceed actions to transmit effectively disables policing for that class, but the engineer should instead use a class that bypasses policing entirely, such as a match-any class with no police action or a 'police cir percent 100' with transmit actions. While functionally similar, the cleaner and exam-correct approach is to leave the class without a police action so it is not rate-limited.
- ✗
Create a class-map matching BGP traffic and apply a 'police' action with a very high committed information rate (CIR).
Why it's wrong here
Even a high CIR police action still drops traffic that exceeds the configured rate, so a sufficiently large flood can still starve BGP keepalives. The requirement is absolute: keepalives must never be dropped. Raising the CIR only delays the problem and does not provide the unconditional pass-through that a priority or 'police cir percent 100' style exemption would need.
- ✓
Create a class-map matching BGP traffic and reference it in the control-plane policy-map without applying any police action.
Why this is correct
Classes in a control-plane policy-map that have no police action applied are not rate-limited, so matching BGP traffic and simply referencing it in the policy-map exempts BGP from CoPP policing. The engineer can then apply 'police' actions to SSH and SNMP classes. This satisfies the requirement that BGP keepalives are never dropped while still rate-limiting other control-plane traffic.
Quick reference
Routing Protocol Comparison
| Protocol | Metric | Max Hops | Algorithm | Type |
|---|---|---|---|---|
| RIP v2 | Hop count | 15 | Bellman-Ford | Distance vector |
| OSPF | Cost (bandwidth) | Unlimited | Dijkstra (SPF) | Link state |
| EIGRP | Composite metric | Unlimited | DUAL | Hybrid |
| IS-IS | Cost | Unlimited | Dijkstra | Link state |
| BGP | Policy / attributes | Unlimited | Path vector | Path vector |
RIP's 15-hop limit makes it unsuitable for large networks. OSPF and EIGRP dominate modern enterprise deployments.
Go deeper
Related to this question
Learn chapter
EIGRP: Basics and Advanced Configuration
Key term
Control Plane Protection
Control Plane Protection (CoPP) is a security feature on Cisco routers and switches that filters traffic destined to the device's control plane to prevent attacks and ensure stability.
Key term
Control Plane Policing
Control Plane Policing is a Cisco security feature that protects a router or switch by rate-limiting the traffic that the device's processor must handle, preventing it from being overwhelmed.
About these practice questions
One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.