Courseiva
Security →mediumMultiple Choice

350-401 Security Practice Question

A network engineer is deploying Control Plane Policing on a Cisco IOS XE router that runs BGP, SSH management, and SNMP monitoring. The engineer must ensure that BGP keepalives are never dropped even during a control-plane flood, while SSH and SNMP traffic should be rate-limited. Which CoPP configuration element accomplishes this requirement?

⚠ Common exam trap

The trap here is assuming that every class in a CoPP policy-map must have a police action, when in fact a class without a police action passes traffic unconditionally.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a class-map matching BGP traffic and reference it in the control-plane policy-map without applying any police action.

CoPP works by classifying control-plane traffic and applying actions, most commonly 'police'. Any class that has no police action is effectively passed without rate limiting, which is exactly what is needed for BGP keepalives that must never be dropped. SSH and SNMP classes can then receive 'police' actions with appropriate conform/exceed handling. This design isolates critical routing protocol traffic from the effects of a control-plane flood.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create a class-map matching BGP traffic with a 'police' action and assign it to the control-plane policy-map.

    Why it's wrong here

    Applying a police action to BGP traffic would rate-limit or drop BGP packets once the configured rate is exceeded, which directly violates the requirement that keepalives must never be dropped. Policing BGP is appropriate only when you want to cap its bandwidth, not when you need guaranteed delivery during a flood. A 'police' action cannot exempt traffic from drops.

  • ✗

    Create a class-map matching BGP traffic and apply a 'police' action with a conform-action of 'transmit' and an exceed-action of 'transmit'.

    Why it's wrong here

    Configuring both conform and exceed actions to transmit effectively disables policing for that class, but the engineer should instead use a class that bypasses policing entirely, such as a match-any class with no police action or a 'police cir percent 100' with transmit actions. While functionally similar, the cleaner and exam-correct approach is to leave the class without a police action so it is not rate-limited.

  • ✗

    Create a class-map matching BGP traffic and apply a 'police' action with a very high committed information rate (CIR).

    Why it's wrong here

    Even a high CIR police action still drops traffic that exceeds the configured rate, so a sufficiently large flood can still starve BGP keepalives. The requirement is absolute: keepalives must never be dropped. Raising the CIR only delays the problem and does not provide the unconditional pass-through that a priority or 'police cir percent 100' style exemption would need.

  • ✓

    Create a class-map matching BGP traffic and reference it in the control-plane policy-map without applying any police action.

    Why this is correct

    Classes in a control-plane policy-map that have no police action applied are not rate-limited, so matching BGP traffic and simply referencing it in the policy-map exempts BGP from CoPP policing. The engineer can then apply 'police' actions to SSH and SNMP classes. This satisfies the requirement that BGP keepalives are never dropped while still rate-limiting other control-plane traffic.

Quick reference

Routing Protocol Comparison

ProtocolMetricMax HopsAlgorithmType
RIP v2Hop count15Bellman-FordDistance vector
OSPFCost (bandwidth)UnlimitedDijkstra (SPF)Link state
EIGRPComposite metricUnlimitedDUALHybrid
IS-ISCostUnlimitedDijkstraLink state
BGPPolicy / attributesUnlimitedPath vectorPath vector

RIP's 15-hop limit makes it unsuitable for large networks. OSPF and EIGRP dominate modern enterprise deployments.

Go deeper

Related to this question

About these practice questions

One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.