Courseiva
Security →hardMultiple Choice

350-401 Security Practice Question

A network engineer is implementing Control Plane Policing (CoPP) on a Cisco IOS XE router to protect the route processor. The engineer wants to rate-limit ICMP echo requests destined to the router itself while ensuring that transit traffic passing through the router is not affected. Which classification approach should the engineer use in the CoPP policy?

⚠ Common exam trap

A common mix-up: candidates confuse interface-level policing with control-plane policing, when only the control-plane attachment isolates router-bound traffic from transit traffic.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use a class map with match access-group referencing an ACL that permits ICMP echo to the router's interface addresses, then attach the policy map to the control-plane interface.

CoPP works by attaching a service policy to the control-plane interface, which only processes traffic destined to the route processor. Classifying ICMP echo requests to the router's own addresses and policing them there protects the CPU without affecting transit traffic. Interface-level policies or ACLs either affect transit traffic or block rather than rate-limit, so the control-plane attachment with an ACL-based class map is correct.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Apply a policy map with police rate to the management VRF interface only.

    Why it's wrong here

    Restricting the policy to the management VRF interface only polices traffic on that specific interface, leaving ICMP echo requests arriving on other interfaces unprotected. Attackers could still flood router-bound ICMP through data interfaces. CoPP on the control-plane interface covers all punted traffic regardless of ingress interface, which is the correct scope for protecting the route processor in this scenario.

  • ✗

    Match ICMP in a class map applied to the ingress interface with the service-policy command.

    Why it's wrong here

    Applying a service policy directly to a physical interface polices all traffic entering that interface, including transit traffic, not just traffic destined to the route processor. This would rate-limit ICMP echo requests that are merely passing through the router, violating the requirement that transit traffic remain unaffected. CoPP is specifically designed to target control-plane-bound traffic, so an interface-level policy is the wrong tool for this scenario.

  • ✗

    Configure an ingress ACL on all interfaces that denies ICMP echo requests to the router.

    Why it's wrong here

    An ingress ACL that denies ICMP echo requests would drop them entirely rather than rate-limit them, so legitimate management pings would fail. It also requires applying the ACL on every interface, which is operationally heavy and error-prone. The requirement is to rate-limit, not block, and CoPP provides a cleaner, centralized mechanism specifically for control-plane protection without touching transit forwarding paths.

  • ✓

    Use a class map with match access-group referencing an ACL that permits ICMP echo to the router's interface addresses, then attach the policy map to the control-plane interface.

    Why this is correct

    CoPP operates by attaching a service policy to the control-plane interface (control-plane global configuration), which only sees traffic punted to the route processor. Matching ICMP echo requests destined to the router's own addresses in a class map, then applying the policy to control-plane, rate-limits only router-bound ICMP while transit traffic is untouched. This is the standard CoPP design pattern for protecting the route processor.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

Go deeper

Related to this question

About these practice questions

This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.