Courseiva
Security →hardMultiple Select

350-401 Security Practice Question

A network engineer is implementing Control Plane Policing (CoPP) on a Cisco ASR 1000 router to protect the route processor from excessive traffic. The router runs OSPF, BGP, SSH management, and NTP. The engineer wants to ensure that OSPF hello packets are always prioritized and that SSH traffic from the management subnet is rate-limited. Which two statements about the CoPP configuration are true? (Choose two.)

⚠ Common exam trap

Candidates often confuse CoPP with interface-level QoS by assuming the service-policy is applied to data plane interfaces rather than the control plane.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

CoPP uses a modular QoS CLI policy map applied globally with the 'service-policy' command under control-plane configuration mode.

CoPP uses MQC class maps and policy maps applied under control-plane configuration mode. Class maps reference ACLs to distinguish protocols like OSPF and SSH, allowing differentiated policing and prioritization actions. Applying the policy to physical interfaces or assuming default policies meet custom requirements are common misconceptions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    CoPP is applied to individual data plane interfaces using the 'service-policy input' command on each physical interface.

    Why it's wrong here

    Applying service-policy input on physical interfaces controls data plane traffic, not control plane traffic destined to the route processor. CoPP specifically requires the service-policy to be applied under control-plane configuration mode, which is a distinct configuration hierarchy from interface-level QoS policies.

  • ✓

    CoPP uses a modular QoS CLI policy map applied globally with the 'service-policy' command under control-plane configuration mode.

    Why this is correct

    CoPP is implemented using MQC constructs where a class map matches control plane traffic and a policy map defines policing actions. The policy map is then applied under the control-plane configuration mode using the service-policy command, which directs the policy to the route processor's traffic rather than to data plane interfaces.

  • ✗

    The default CoPP policy that ships with Cisco IOS XE already rate-limits SSH and OSPF traffic without any custom configuration.

    Why it's wrong here

    While some platforms include a default CoPP policy, it is not universally present and does not automatically meet specific organizational requirements for SSH rate-limiting or OSPF prioritization. Custom class maps and policy maps are typically required to define the exact traffic classifications and actions needed for the stated policy.

  • ✓

    CoPP policies can differentiate OSPF and SSH traffic by using ACLs referenced in class maps to match specific protocols and source addresses.

    Why this is correct

    Class maps in CoPP use match statements including 'match access-group' to reference ACLs that identify specific traffic types. An ACL can permit OSPF (IP protocol 89) and SSH (TCP port 22 from the management subnet), allowing the policy map to apply different policing rates to each class.

  • ✗

    CoPP can only police traffic; it cannot mark or prioritize specific control plane protocols such as OSPF.

    Why it's wrong here

    CoPP policy maps can include marking, policing, and other QoS actions within the control plane policy. The policy map supports set commands for DSCP or precedence marking in addition to police statements, enabling prioritization of protocols like OSPF by assigning appropriate marking values before queuing.

Visual reference

R1 R2 R3 R4 10 100 10 100 OSPF picks R1→R2→R4 (cost 20) over R1→R3→R4 (cost 200)

Quick reference

Routing Protocol Comparison

ProtocolMetricMax HopsAlgorithmType
RIP v2Hop count15Bellman-FordDistance vector
OSPFCost (bandwidth)UnlimitedDijkstra (SPF)Link state
EIGRPComposite metricUnlimitedDUALHybrid
IS-ISCostUnlimitedDijkstraLink state
BGPPolicy / attributesUnlimitedPath vectorPath vector

RIP's 15-hop limit makes it unsuitable for large networks. OSPF and EIGRP dominate modern enterprise deployments.

Go deeper

Related to this question

About these practice questions

One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.