350-401 Security Practice Question
A network engineer is implementing Control Plane Policing (CoPP) on a Cisco ASR 1000 router to protect the route processor from excessive traffic. The router runs OSPF, BGP, SSH management, and NTP. The engineer wants to ensure that OSPF hello packets are always prioritized and that SSH traffic from the management subnet is rate-limited. Which two statements about the CoPP configuration are true? (Choose two.)
⚠ Common exam trap
Candidates often confuse CoPP with interface-level QoS by assuming the service-policy is applied to data plane interfaces rather than the control plane.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
CoPP uses a modular QoS CLI policy map applied globally with the 'service-policy' command under control-plane configuration mode.
CoPP uses MQC class maps and policy maps applied under control-plane configuration mode. Class maps reference ACLs to distinguish protocols like OSPF and SSH, allowing differentiated policing and prioritization actions. Applying the policy to physical interfaces or assuming default policies meet custom requirements are common misconceptions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
CoPP is applied to individual data plane interfaces using the 'service-policy input' command on each physical interface.
Why it's wrong here
Applying service-policy input on physical interfaces controls data plane traffic, not control plane traffic destined to the route processor. CoPP specifically requires the service-policy to be applied under control-plane configuration mode, which is a distinct configuration hierarchy from interface-level QoS policies.
- ✓
CoPP uses a modular QoS CLI policy map applied globally with the 'service-policy' command under control-plane configuration mode.
Why this is correct
CoPP is implemented using MQC constructs where a class map matches control plane traffic and a policy map defines policing actions. The policy map is then applied under the control-plane configuration mode using the service-policy command, which directs the policy to the route processor's traffic rather than to data plane interfaces.
- ✗
The default CoPP policy that ships with Cisco IOS XE already rate-limits SSH and OSPF traffic without any custom configuration.
Why it's wrong here
While some platforms include a default CoPP policy, it is not universally present and does not automatically meet specific organizational requirements for SSH rate-limiting or OSPF prioritization. Custom class maps and policy maps are typically required to define the exact traffic classifications and actions needed for the stated policy.
- ✓
CoPP policies can differentiate OSPF and SSH traffic by using ACLs referenced in class maps to match specific protocols and source addresses.
Why this is correct
Class maps in CoPP use match statements including 'match access-group' to reference ACLs that identify specific traffic types. An ACL can permit OSPF (IP protocol 89) and SSH (TCP port 22 from the management subnet), allowing the policy map to apply different policing rates to each class.
- ✗
CoPP can only police traffic; it cannot mark or prioritize specific control plane protocols such as OSPF.
Why it's wrong here
CoPP policy maps can include marking, policing, and other QoS actions within the control plane policy. The policy map supports set commands for DSCP or precedence marking in addition to police statements, enabling prioritization of protocols like OSPF by assigning appropriate marking values before queuing.
Visual reference
Quick reference
Routing Protocol Comparison
| Protocol | Metric | Max Hops | Algorithm | Type |
|---|---|---|---|---|
| RIP v2 | Hop count | 15 | Bellman-Ford | Distance vector |
| OSPF | Cost (bandwidth) | Unlimited | Dijkstra (SPF) | Link state |
| EIGRP | Composite metric | Unlimited | DUAL | Hybrid |
| IS-IS | Cost | Unlimited | Dijkstra | Link state |
| BGP | Policy / attributes | Unlimited | Path vector | Path vector |
RIP's 15-hop limit makes it unsuitable for large networks. OSPF and EIGRP dominate modern enterprise deployments.
Go deeper
Related to this question
Learn chapter
QoS and Network Performance Management
Key term
Control Plane Policing
Control Plane Policing is a Cisco security feature that protects a router or switch by rate-limiting the traffic that the device's processor must handle, preventing it from being overwhelmed.
Key term
Control Plane Protection
Control Plane Protection (CoPP) is a security feature on Cisco routers and switches that filters traffic destined to the device's control plane to prevent attacks and ensure stability.
About these practice questions
One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.