hardMultiple Select
350-401 Practice Question: Which three statements about CoPP configuration…
Which three statements about CoPP configuration and operation are true? (Choose three.)
⚠ Common exam trap
350-401 often tests the specific commands and application points for CoPP, and candidates may confuse it with interface ACLs or assume it only supports IPv4.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
CoPP uses a class map to classify traffic destined for the control plane.
Option A is correct because CoPP (Control Plane Policing) relies on a class map to identify and classify traffic that is destined to the control plane, typically using ACLs or match statements to select protocols such as routing updates, management traffic, or ICMP. Option B is correct because the rate-limiting action in CoPP is implemented by configuring the 'police' command inside a policy map, which enforces a committed information rate (CIR) and burst parameters on the classified control-plane traffic. Option C is correct because the 'control-plane' global configuration command enters control plane configuration mode, where the service policy is attached to the control plane using the 'service-policy' command. Option D is not correct because CoPP is not applied with 'ip access-group' on a control plane interface; instead, the policy map is attached under control plane configuration mode with 'service-policy'. Option E is not correct because CoPP can match and police more than IPv4 traffic, including IPv6, ARP, and other non-IP control-plane protocols, depending on the platform and class-map configuration.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
CoPP uses a class map to classify traffic destined for the control plane.
Why this is correct
CoPP class maps identify control-plane traffic by matching ACLs or protocols, separating it into classes. The policy map then applies actions per class, satisfying the requirement to classify traffic destined for the control plane before rate-limiting it.
- ✓
CoPP uses the 'police' command within a policy map to rate-limit traffic.
Why this is correct
CoPP applies the 'police' command inside a policy map to enforce rate limiting on control-plane traffic, satisfying the requirement to constrain traffic destined for the device's CPU. Classification occurs via class maps, then policing drops or marks excess packets, protecting the control plane from floods without affecting data-plane forwarding.
- ✓
The 'control-plane' command is used to enter control plane configuration mode.
Why this is correct
Entering global configuration and issuing the control-plane command places the device into control plane configuration mode, from which service-policy statements are attached. This satisfies the stem's requirement about how CoPP configuration is entered and structured.
- ✗
CoPP is applied using the 'ip access-group' command on the control plane interface.
Why it's wrong here
CoPP attaches via the control-plane policy-map with 'service-policy', not 'ip access-group', which binds ACLs to interfaces for data-plane filtering. It is tempting because ACLs underpin CoPP classification, but the correct attachment mechanism is the control-plane service-policy.
- ✗
CoPP can only filter IPv4 traffic.
Why it's wrong here
CoPP classifies IPv4, IPv6 and non-IP control traffic such as ARP and CDP through its ACLs, so an IPv4-only restriction is false. It is tempting because many examples show IPv4 ACLs, but the correct statements cover multiple protocol families on the control plane.
Go deeper
Related to this question
Learn chapter
Network Access Control and AAA
Key term
Control Plane Policing
Control Plane Policing is a Cisco security feature that protects a router or switch by rate-limiting the traffic that the device's processor must handle, preventing it from being overwhelmed.
Key term
Control Plane Protection
Control Plane Protection (CoPP) is a security feature on Cisco routers and switches that filters traffic destined to the device's control plane to prevent attacks and ensure stability.
About these practice questions
Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.