mediumMultiple Choice
350-401 Practice Question: Given the following CoPP configuration: class-map…
Given the following CoPP configuration:
class-map match-all COPP_ICMP match access-group name ICMP_ACL ! policy-map COPP_POLICY
class COPP_ICMP
police 8000 conform-action transmit exceed-action drop ! control-plane service-policy input COPP_POLICY
What is the effect?
⚠ Common exam trap
Cisco often tests the misconception that 'match-all' is required for class-maps with a single match condition, but it is optional and the configuration is valid; the trap here is that candidates think the class-map is missing a match-all statement, but it is explicitly present.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
All ICMP traffic to the control plane is rate-limited to 8000 bps.
The CoPP policy matches ICMP traffic via the class-map and applies a police rate of 8000 bps to the control plane. The 'conform-action transmit exceed-action drop' ensures that traffic within the rate is forwarded, while excess traffic is dropped, effectively rate-limiting ICMP to the control plane.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
All ICMP traffic to the control plane is rate-limited to 8000 bps.
Why this is correct
The correct interpretation is that the policy-map applies a police command to the class containing ICMP traffic destined for the control plane, setting a committed information rate (CIR) of 8000 bps. The conform-action transmit allows traffic within the rate, while the exceed-action drop causes any excess ICMP packets to be discarded, so the net effect is a hard rate limit on ICMP control-plane traffic.
- ✗
ICMP traffic is permitted unconditionally.
Why it's wrong here
The presence of the police command with an exceed-action drop means ICMP traffic is not permitted unconditionally. The policy either transmits traffic within the configured 8000 bps rate or drops traffic that exceeds that rate, so there is no unconditional permit behavior for ICMP toward the control plane.
- ✗
The policy is applied to all interfaces, not just the control plane.
Why it's wrong here
This option misreads the configuration context. The service-policy statement is explicitly placed under the control-plane configuration mode, not globally or on physical interfaces. This restricts the policy's application to traffic destined to the control plane (i.e., the router's CPU), not to all interfaces traversing the device.
- ✗
The class-map is missing a match-all statement.
Why it's wrong here
The claim that the class-map is missing a match-all statement is factually wrong because the configuration explicitly includes match-all in the class-map. With match-all, all match conditions must be satisfied for a packet to be classified into that class; here it correctly matches only ICMP protocol traffic, so the classification is valid.
Go deeper
Related to this question
About these practice questions
One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.