Courseiva
Security →hardMultiple Choice

350-401 Security Practice Question

A security team is deploying Control Plane Policing (CoPP) on a Cisco ASR 1000 router to protect the route processor from excessive traffic. They notice that after applying a CoPP policy, OSPF adjacency with a directly connected neighbor flaps intermittently. Which action should the engineer take to resolve the issue while maintaining control plane protection?

⚠ Common exam trap

The trap here is assuming that removing CoPP or applying a blanket high rate is acceptable, rather than tuning the specific class that is being dropped.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Add a class-map matching OSPF traffic and associate it with a policer that has a higher committed information rate.

CoPP uses class-maps and policy-maps to rate-limit traffic destined to the control plane. If the default policer for routing protocols is too low, OSPF hellos can be dropped, causing adjacency flaps. Creating a dedicated class for OSPF and assigning a policer with a higher committed information rate allows legitimate routing traffic while still protecting the route processor.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Add a class-map matching OSPF traffic and associate it with a policer that has a higher committed information rate.

    Why this is correct

    OSPF hello and LSA traffic to the route processor must be permitted at a sufficient rate to maintain adjacency. Creating a class-map for OSPF and assigning a policer with an adequate CIR ensures control plane protection remains in place while allowing legitimate routing protocol traffic, which resolves the flapping caused by the default policer dropping OSPF packets.

  • ✗

    Configure OSPF authentication on the interface to reduce the volume of OSPF packets processed.

    Why it's wrong here

    OSPF authentication verifies neighbor identity but does not reduce the rate of hello packets required to maintain adjacency, nor does it prevent CoPP from dropping them. The flapping is caused by policer drops, not by unauthenticated neighbors, so enabling authentication will not resolve the issue while CoPP remains overly restrictive.

  • ✗

    Remove the CoPP policy from the control plane and rely on ACLs on the management interface.

    Why it's wrong here

    Removing CoPP entirely eliminates the protection the security team requires and does not address the root cause, which is an overly restrictive policer for OSPF. ACLs on a management interface cannot police transit control plane traffic destined to the route processor, so this approach neither preserves protection nor reliably fixes the adjacency flapping.

  • ✗

    Change the CoPP policy to use a police rate of 8000 pps for all traffic classes.

    Why it's wrong here

    Applying a uniform high policer to every class defeats the purpose of differentiated control plane protection and may allow malicious traffic to overwhelm the route processor. It also does not specifically address OSPF traffic, so adjacency stability is not guaranteed and the security posture is weakened by removing granular policing.

Visual reference

R1 R2 R3 R4 10 100 10 100 OSPF picks R1→R2→R4 (cost 20) over R1→R3→R4 (cost 200)

Quick reference

Routing Protocol Comparison

ProtocolMetricMax HopsAlgorithmType
RIP v2Hop count15Bellman-FordDistance vector
OSPFCost (bandwidth)UnlimitedDijkstra (SPF)Link state
EIGRPComposite metricUnlimitedDUALHybrid
IS-ISCostUnlimitedDijkstraLink state
BGPPolicy / attributesUnlimitedPath vectorPath vector

RIP's 15-hop limit makes it unsuitable for large networks. OSPF and EIGRP dominate modern enterprise deployments.

Go deeper

Related to this question

About these practice questions

This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.