350-401 Security Practice Question
A network security engineer is configuring Control Plane Policing (CoPP) on a Cisco ASR 1000 router to protect the route processor from excessive traffic. The engineer wants to rate-limit SSH traffic to 100 kbps with a burst of 8000 bytes, and ensure that any traffic exceeding the rate is dropped. The engineer applies the following policy:
policy-map COPP-POLICY
class SSH-CLASS
police 100000 8000 exceed-action drop
After applying the service-policy to the control plane, the engineer notices that SSH sessions intermittently disconnect during large file transfers over SCP. What is the most likely cause?
⚠ Common exam trap
Watch out — candidates often confuse the units of the police command, assuming the burst is in bits or kilobytes, when it is actually in bytes, leading to an undersized burst for the traffic profile.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The police rate is configured in bits per second, but the burst size is too small for SCP transfers, causing packets to be dropped.
The police command uses bits per second for the rate and bytes for the burst. A 100 kbps rate with an 8000-byte burst is too restrictive for SCP file transfers, which generate bursts of SSH packets larger than 8000 bytes. The policer drops excess packets, causing SSH sessions to disconnect intermittently. Increasing the burst size or rate would resolve the problem.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Control Plane Policing does not support the exceed-action drop keyword; the correct action is transmit.
Why it's wrong here
Control Plane Policing fully supports the exceed-action drop keyword, which is commonly used to discard traffic exceeding the configured rate. The transmit action would allow excess traffic, defeating the purpose of policing. The keyword is valid, so this is not the cause of the disconnects.
- ✗
The service-policy must be applied to the control plane with the input keyword, otherwise SSH traffic is not policed.
Why it's wrong here
When applying a service-policy to the control plane, the input keyword is not used; the policy is applied directly with service-policy input under control-plane configuration, but the syntax is service-policy input policy-name. The absence of the keyword would cause a configuration error, not intermittent drops. The scenario states the policy is applied, so this is not the issue.
- ✗
The police rate is configured in kilobits per second, but the burst size is in kilobytes, causing a mismatch that drops all SSH packets.
Why it's wrong here
The police command interprets the rate as bits per second, not kilobits per second, and the burst as bytes, not kilobytes. There is no unit mismatch that would drop all SSH packets. The issue is that the burst is too small for the traffic pattern, not a unit conversion error, so this explanation is incorrect.
- ✓
The police rate is configured in bits per second, but the burst size is too small for SCP transfers, causing packets to be dropped.
Why this is correct
The police command specifies the rate in bits per second (100000 bps = 100 kbps) and the burst in bytes (8000 bytes). During large SCP transfers, the burst of SSH packets can exceed 8000 bytes, causing the policer to drop packets and disconnect sessions. Increasing the burst size would allow more data before policing, resolving the intermittent drops.
Visual reference
Go deeper
Related to this question
Learn chapter
Route Redistribution and Filtering
Key term
Control Plane Protection
Control Plane Protection (CoPP) is a security feature on Cisco routers and switches that filters traffic destined to the device's control plane to prevent attacks and ensure stability.
Key term
Control Plane Policing
Control Plane Policing is a Cisco security feature that protects a router or switch by rate-limiting the traffic that the device's processor must handle, preventing it from being overwhelmed.
About these practice questions
One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.