Courseiva
mediumMultiple Choice

350-401 Practice Question: Is troubleshooting an issue where a Cisco router…

A network engineer is troubleshooting an issue where a Cisco router is not responding to SNMP polls from a network management station (NMS) at 192.168.1.50. The router has a CoPP policy that includes a class-map matching SNMP traffic (UDP port 161). The engineer checks the CoPP statistics and sees that SNMP packets from the NMS are being dropped. The engineer wants to allow SNMP from the NMS while still protecting the control plane. Which configuration change should the engineer make?

⚠ Common exam trap

Cisco often tests the concept that CoPP ACLs are processed in order, and candidates may incorrectly assume that increasing the police rate or removing the policy entirely is the solution, rather than understanding that a specific permit entry for the trusted host must be placed before the deny statement.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Modify the CoPP ACL to include a permit statement for UDP port 161 from host 192.168.1.50 before the deny statement.

The CoPP policy is dropping SNMP packets from the NMS because the class-map matching SNMP traffic (UDP port 161) is applied without an exception for the specific management station. By modifying the ACL to include a permit statement for UDP port 161 from host 192.168.1.50 before the deny statement, the router will match and allow those packets before they hit the drop action, preserving control plane protection while permitting the NMS polls.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Modify the CoPP ACL to include a permit statement for UDP port 161 from host 192.168.1.50 before the deny statement.

    Why this is correct

    The CoPP policy evaluates control-plane traffic using an ordered ACL; if the class-map references an ACL with a deny hit for the NMS's source, SNMP from 192.168.1.50 is not classified into the intended class and may fall through to a default drop action. Inserting a permit statement for UDP port 161 from that host before the existing deny entry ensures the class-map matches correctly, allowing the traffic to be policed under the appropriate CoPP class. This is the only option that directly fixes the selective source-based drop while preserving the security policy.

  • ✗

    Increase the police rate for the CoPP class that matches SNMP traffic.

    Why it's wrong here

    Increasing the police rate would allow more SNMP traffic in total, but the problem is that packets from the NMS are being dropped specifically, not that the overall rate is too low. This option is tempting because raising the police rate is a standard way to reduce drops when a class-map is rate-limiting legitimate traffic, and it would be correct if the router were dropping all SNMP packets due to exceeding a configured bandwidth limit. However, the stem indicates selective dropping of only the NMS’s traffic, which requires an ACL-based permit within the class-map, not a rate adjustment.

  • ✗

    Remove the CoPP policy from the control plane and rely on interface ACLs.

    Why it's wrong here

    Interface ACLs are applied to forwarding-plane interfaces and are designed to filter transit traffic, not to police the often CPU-punted traffic destined to the route processor. Removing CoPP and relying solely on interface ACLs exposes the control plane to packet floods, because interface ACLs typically do not filter local traffic destined to the CPU unless explicitly configured on a loopback or via control-plane filtering, and they lack CoPP's per-class rate-limiting granularity. Thus this option weakens security without resolving the NMS reachability problem.

  • ✗

    Change the SNMP port on the router to a non-standard port to avoid the CoPP policy.

    Why it's wrong here

    Changing the SNMP port on the router only shifts the UDP service to a different number; the NMS would also need to be reconfigured, and the CoPP ACL may still deny the traffic if the matched entry uses a broader match (such as source-IP-based deny or a global deny for the management subnet). Even if the new port happens to avoid the current CoPP deny, this is a workaround that masks the root cause — the precedence and matching logic inside the CoPP class-map — rather than correcting it. The real issue is the ACL order, not the transport port.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.