350-401 Security Practice Question
A network engineer is implementing Control Plane Policing (CoPP) on a Cisco IOS XE router to protect the route processor. The engineer wants to rate-limit ICMP echo requests destined to the router itself while ensuring that transit traffic passing through the router is not affected. Which classification approach should the engineer use in the CoPP policy?
⚠ Common exam trap
A common mix-up: candidates confuse interface-level policing with control-plane policing, when only the control-plane attachment isolates router-bound traffic from transit traffic.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use a class map with match access-group referencing an ACL that permits ICMP echo to the router's interface addresses, then attach the policy map to the control-plane interface.
CoPP works by attaching a service policy to the control-plane interface, which only processes traffic destined to the route processor. Classifying ICMP echo requests to the router's own addresses and policing them there protects the CPU without affecting transit traffic. Interface-level policies or ACLs either affect transit traffic or block rather than rate-limit, so the control-plane attachment with an ACL-based class map is correct.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Apply a policy map with police rate to the management VRF interface only.
Why it's wrong here
Restricting the policy to the management VRF interface only polices traffic on that specific interface, leaving ICMP echo requests arriving on other interfaces unprotected. Attackers could still flood router-bound ICMP through data interfaces. CoPP on the control-plane interface covers all punted traffic regardless of ingress interface, which is the correct scope for protecting the route processor in this scenario.
- ✗
Match ICMP in a class map applied to the ingress interface with the service-policy command.
Why it's wrong here
Applying a service policy directly to a physical interface polices all traffic entering that interface, including transit traffic, not just traffic destined to the route processor. This would rate-limit ICMP echo requests that are merely passing through the router, violating the requirement that transit traffic remain unaffected. CoPP is specifically designed to target control-plane-bound traffic, so an interface-level policy is the wrong tool for this scenario.
- ✗
Configure an ingress ACL on all interfaces that denies ICMP echo requests to the router.
Why it's wrong here
An ingress ACL that denies ICMP echo requests would drop them entirely rather than rate-limit them, so legitimate management pings would fail. It also requires applying the ACL on every interface, which is operationally heavy and error-prone. The requirement is to rate-limit, not block, and CoPP provides a cleaner, centralized mechanism specifically for control-plane protection without touching transit forwarding paths.
- ✓
Use a class map with match access-group referencing an ACL that permits ICMP echo to the router's interface addresses, then attach the policy map to the control-plane interface.
Why this is correct
CoPP operates by attaching a service policy to the control-plane interface (control-plane global configuration), which only sees traffic punted to the route processor. Matching ICMP echo requests destined to the router's own addresses in a class map, then applying the policy to control-plane, rate-limits only router-bound ICMP while transit traffic is untouched. This is the standard CoPP design pattern for protecting the route processor.
Visual reference
Go deeper
Related to this question
Learn chapter
Network Access Control and AAA
Key term
Control Plane Protection
Control Plane Protection (CoPP) is a security feature on Cisco routers and switches that filters traffic destined to the device's control plane to prevent attacks and ensure stability.
Key term
Control Plane Policing
Control Plane Policing is a Cisco security feature that protects a router or switch by rate-limiting the traffic that the device's processor must handle, preventing it from being overwhelmed.
About these practice questions
This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.