mediumMultiple Choice
350-401 Practice Question: An enterprise network uses a Cisco Catalyst 9300…
An enterprise network uses a Cisco Catalyst 9300 switch as a distribution layer device. The network team notices that ICMP echo requests from a monitoring server (192.168.1.100) to the switch's management IP are being dropped intermittently. The switch has a CoPP policy that includes a class-map matching ICMP traffic. The engineer checks the CoPP statistics and sees that ICMP packets from the monitoring server are being dropped by the policy. What is the most likely cause of this issue?
⚠ Common exam trap
Many candidates assume CoPP drops are always due to CPU overload or a misconfigured ACL, but the key clue is the intermittent nature and the specific class-map match, pointing directly to an overly restrictive policer rate.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The CoPP policy is policing ICMP traffic to a rate that is too low for the monitoring server's traffic.
The CoPP policy is policing ICMP traffic to a rate that is too low for the monitoring server's traffic. CoPP (Control Plane Policing) protects the switch's CPU by rate-limiting control plane traffic, including ICMP. When the policer rate is set too low, even legitimate ICMP echo requests from the monitoring server are dropped, causing intermittent reachability issues.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The CoPP policy is policing ICMP traffic to a rate that is too low for the monitoring server's traffic.
Why this is correct
CoPP (Control Plane Policing) uses an MQC policy with policers to rate-limit traffic destined to the switch CPU. A monitoring server’s ICMP packets (e.g., ping to the management IP) are classified into a class that matches ICMP; if the configured police rate (e.g., committed information rate) is too low, packets exceeding the burst are immediately dropped. The drop counters in 'show policy-map control-plane' confirm that the traffic was admitted to the control plane but then policed, not blocked earlier.
- ✗
An ACL applied to the management interface is blocking ICMP from the monitoring server.
Why it's wrong here
An interface ACL applied to the management SVI or out-of-band Ethernet port would drop ICMP packets during inbound line-card processing, before they reach the control plane. Such drops would not appear in the CoPP 'show policy-map' drop counters, and would instead show as ACL deny counters on the interface. Since the evidence shows drops exactly under the CoPP policy (e.g., in the ICMP class), an ACL is not the root cause.
- ✗
The monitoring server is sending ICMP packets with a TTL of 1, causing them to be dropped.
Why it's wrong here
If the monitoring server set IP TTL=1, the ICMP packet would be discarded as expired only if it needs to be routed by an intermediate hop; but for directly connected management traffic to the switch's IP, TTL is not decremented. More importantly, a TTL-based drop would occur on the routing path (with an ICMP TTL exceeded reply) and would not appear in the switch’s CoPP drop counters. The CoPP statistics prove the packets reached the control plane and were then policed, so TTL=1 cannot be the explanation.
- ✗
The switch's CPU is overloaded, causing CoPP to drop all packets.
Why it's wrong here
CoPP drop counters are tied to the policer’s configured rate and burst, not to the CPU load percentage. Even when the CPU is deliberately pegged, if the ICMP traffic rate is within the policed CIR, the packets are admitted; if the CPU has no buffers or is slow, the drops would show as CPU input queue drops or at the interface, not as CoPP 'policy drops'. Therefore, stating that CPU overload causes CoPP to drop all packets conflates CoPP rate-limiting with true resource exhaustion.
Go deeper
Related to this question
Learn chapter
Network Monitoring and Troubleshooting Tools
Key term
Control Plane Policing
Control Plane Policing is a Cisco security feature that protects a router or switch by rate-limiting the traffic that the device's processor must handle, preventing it from being overwhelmed.
Key term
Control Plane Protection
Control Plane Protection (CoPP) is a security feature on Cisco routers and switches that filters traffic destined to the device's control plane to prevent attacks and ensure stability.
About these practice questions
Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.