350-401 Security Practice Question
A security team is deploying Control Plane Policing (CoPP) on a Cisco ASR 1000 router to protect the route processor from excessive traffic. They notice that after applying a CoPP policy, OSPF adjacency with a directly connected neighbor flaps intermittently. Which action should the engineer take to resolve the issue while maintaining control plane protection?
⚠ Common exam trap
The trap here is assuming that removing CoPP or applying a blanket high rate is acceptable, rather than tuning the specific class that is being dropped.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Add a class-map matching OSPF traffic and associate it with a policer that has a higher committed information rate.
CoPP uses class-maps and policy-maps to rate-limit traffic destined to the control plane. If the default policer for routing protocols is too low, OSPF hellos can be dropped, causing adjacency flaps. Creating a dedicated class for OSPF and assigning a policer with a higher committed information rate allows legitimate routing traffic while still protecting the route processor.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Add a class-map matching OSPF traffic and associate it with a policer that has a higher committed information rate.
Why this is correct
OSPF hello and LSA traffic to the route processor must be permitted at a sufficient rate to maintain adjacency. Creating a class-map for OSPF and assigning a policer with an adequate CIR ensures control plane protection remains in place while allowing legitimate routing protocol traffic, which resolves the flapping caused by the default policer dropping OSPF packets.
- ✗
Configure OSPF authentication on the interface to reduce the volume of OSPF packets processed.
Why it's wrong here
OSPF authentication verifies neighbor identity but does not reduce the rate of hello packets required to maintain adjacency, nor does it prevent CoPP from dropping them. The flapping is caused by policer drops, not by unauthenticated neighbors, so enabling authentication will not resolve the issue while CoPP remains overly restrictive.
- ✗
Remove the CoPP policy from the control plane and rely on ACLs on the management interface.
Why it's wrong here
Removing CoPP entirely eliminates the protection the security team requires and does not address the root cause, which is an overly restrictive policer for OSPF. ACLs on a management interface cannot police transit control plane traffic destined to the route processor, so this approach neither preserves protection nor reliably fixes the adjacency flapping.
- ✗
Change the CoPP policy to use a police rate of 8000 pps for all traffic classes.
Why it's wrong here
Applying a uniform high policer to every class defeats the purpose of differentiated control plane protection and may allow malicious traffic to overwhelm the route processor. It also does not specifically address OSPF traffic, so adjacency stability is not guaranteed and the security posture is weakened by removing granular policing.
Visual reference
Quick reference
Routing Protocol Comparison
| Protocol | Metric | Max Hops | Algorithm | Type |
|---|---|---|---|---|
| RIP v2 | Hop count | 15 | Bellman-Ford | Distance vector |
| OSPF | Cost (bandwidth) | Unlimited | Dijkstra (SPF) | Link state |
| EIGRP | Composite metric | Unlimited | DUAL | Hybrid |
| IS-IS | Cost | Unlimited | Dijkstra | Link state |
| BGP | Policy / attributes | Unlimited | Path vector | Path vector |
RIP's 15-hop limit makes it unsuitable for large networks. OSPF and EIGRP dominate modern enterprise deployments.
Go deeper
Related to this question
Learn chapter
Route Redistribution and Filtering
Key term
Control Plane Policing
Control Plane Policing is a Cisco security feature that protects a router or switch by rate-limiting the traffic that the device's processor must handle, preventing it from being overwhelmed.
Key term
Control Plane Protection
Control Plane Protection (CoPP) is a security feature on Cisco routers and switches that filters traffic destined to the device's control plane to prevent attacks and ensure stability.
About these practice questions
This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.