Courseiva
Security →hardMultiple Choice

350-401 Security Practice Question

A network security engineer is configuring Control Plane Policing (CoPP) on a Cisco ASR 1000 router to protect the route processor from excessive traffic. The engineer wants to rate-limit SSH traffic to 100 kbps with a burst of 8000 bytes, and ensure that any traffic exceeding the rate is dropped. The engineer applies the following policy:

policy-map COPP-POLICY

class SSH-CLASS

police 100000 8000 exceed-action drop

After applying the service-policy to the control plane, the engineer notices that SSH sessions intermittently disconnect during large file transfers over SCP. What is the most likely cause?

⚠ Common exam trap

Watch out — candidates often confuse the units of the police command, assuming the burst is in bits or kilobytes, when it is actually in bytes, leading to an undersized burst for the traffic profile.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The police rate is configured in bits per second, but the burst size is too small for SCP transfers, causing packets to be dropped.

The police command uses bits per second for the rate and bytes for the burst. A 100 kbps rate with an 8000-byte burst is too restrictive for SCP file transfers, which generate bursts of SSH packets larger than 8000 bytes. The policer drops excess packets, causing SSH sessions to disconnect intermittently. Increasing the burst size or rate would resolve the problem.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Control Plane Policing does not support the exceed-action drop keyword; the correct action is transmit.

    Why it's wrong here

    Control Plane Policing fully supports the exceed-action drop keyword, which is commonly used to discard traffic exceeding the configured rate. The transmit action would allow excess traffic, defeating the purpose of policing. The keyword is valid, so this is not the cause of the disconnects.

  • ✗

    The service-policy must be applied to the control plane with the input keyword, otherwise SSH traffic is not policed.

    Why it's wrong here

    When applying a service-policy to the control plane, the input keyword is not used; the policy is applied directly with service-policy input under control-plane configuration, but the syntax is service-policy input policy-name. The absence of the keyword would cause a configuration error, not intermittent drops. The scenario states the policy is applied, so this is not the issue.

  • ✗

    The police rate is configured in kilobits per second, but the burst size is in kilobytes, causing a mismatch that drops all SSH packets.

    Why it's wrong here

    The police command interprets the rate as bits per second, not kilobits per second, and the burst as bytes, not kilobytes. There is no unit mismatch that would drop all SSH packets. The issue is that the burst is too small for the traffic pattern, not a unit conversion error, so this explanation is incorrect.

  • ✓

    The police rate is configured in bits per second, but the burst size is too small for SCP transfers, causing packets to be dropped.

    Why this is correct

    The police command specifies the rate in bits per second (100000 bps = 100 kbps) and the burst in bytes (8000 bytes). During large SCP transfers, the burst of SSH packets can exceed 8000 bytes, causing the policer to drop packets and disconnect sessions. Increasing the burst size would allow more data before policing, resolving the intermittent drops.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

Go deeper

Related to this question

About these practice questions

One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.