Courseiva
mediumMultiple Select

350-401 Practice Question: Which two statements about Control Plane Policing…

Which two statements about Control Plane Policing (CoPP) are true? (Choose two.)

⚠ Common exam trap

350-401 often tests where CoPP is applied — candidates assume it goes on physical interfaces like a normal service policy, but CoPP is attached to the control plane interface to protect the route processor.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

CoPP uses ACLs to match traffic destined for the control plane.

Option A is correct because CoPP relies on class maps built from ACLs (or NBAR, QoS groups, etc.) to classify and match traffic that is destined to the control plane, such as routing protocol, management, and ICMP packets processed by the route processor. Option B is correct because CoPP is implemented by attaching a service policy to the control plane interface using the global configuration command 'service-policy input <policy-name>' under 'control-plane' (or 'control-plane host/subinterface'), which is the standard deployment point. Option C is false because CoPP can both rate-limit and drop or police excess traffic via the policer actions (transmit, drop, set precedence), not merely rate-limit. Option D is false because CoPP protects the control plane, not the data plane, and it is applied to the control plane interface rather than all physical interfaces. Option E is false because CoPP can match IPv4, IPv6, MPLS, and non-IP traffic through appropriate ACLs and class maps, so it is not limited to IPv4.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    CoPP uses ACLs to match traffic destined for the control plane.

    Why this is correct

    CoPP classifies control-plane-bound traffic using ACLs, which match packets destined to the router itself, such as routing protocols and management traffic. These ACL matches feed the class maps that define which traffic the policy subsequently rate-limits.

  • ✓

    CoPP is applied as a service policy on the control plane interface.

    Why this is correct

    CoPP is attached as a service policy on the control plane interface, not on physical data interfaces. This placement lets the policy police traffic punted to the route processor, satisfying the stem's requirement by filtering packets destined for the control plane itself.

  • ✗

    CoPP can only be used to rate-limit traffic, not to drop it.

    Why it's wrong here

    CoPP both rate-limits and drops or marks excess traffic matching its class maps, using policers with conform, exceed and violate actions. Rate-limiting-only is tempting because policing is commonly associated with bandwidth caps, but CoPP's purpose is protecting the route processor, which requires dropping abusive control traffic.

  • ✗

    CoPP is applied to all physical interfaces to protect the data plane.

    Why it's wrong here

    CoPP attaches to the control plane, policing traffic destined to the route processor; applying it to physical interfaces would police transit traffic, which is data plane policing. Interface attachment is tempting because interface ACLs and QoS policies are configured there, but CoPP's target is the control plane itself.

  • ✗

    CoPP can only filter IPv4 traffic.

    Why it's wrong here

    CoPP class maps match multiple protocols including IPv6, ARP, MPLS and non-IP control traffic, not IPv4 alone. IPv4-only is tempting because many ACL examples use IPv4 headers, but CoPP operates on the control plane's protocol mix, so IPv6 neighbour discovery and routing adjacencies can equally be policed.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

Quick reference

Routing Protocol Comparison

ProtocolMetricMax HopsAlgorithmType
RIP v2Hop count15Bellman-FordDistance vector
OSPFCost (bandwidth)UnlimitedDijkstra (SPF)Link state
EIGRPComposite metricUnlimitedDUALHybrid
IS-ISCostUnlimitedDijkstraLink state
BGPPolicy / attributesUnlimitedPath vectorPath vector

RIP's 15-hop limit makes it unsuitable for large networks. OSPF and EIGRP dominate modern enterprise deployments.

Go deeper

Related to this question

About these practice questions

Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on 350-401

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Which three statements about Control Plane Policing (CoPP) are true? (Choose three.)

medium
  • ✓ A.CoPP applies QoS policy-map logic to traffic that is destined to the control plane of the router.
  • ✓ B.CoPP is configured under the 'control-plane' global configuration mode.
  • ✓ C.CoPP can be applied to both IPv4 and IPv6 traffic in a single policy-map.
  • D.CoPP is applied to traffic transiting the router, not to traffic originated by the router.
  • E.The default action for CoPP is to permit all control-plane traffic.

Why A: Option A is correct because CoPP uses the MQC (Modular QoS CLI) framework — class-maps to classify and policy-maps to define actions — applied specifically to traffic punted to the route processor's control plane (e.g., routing protocols, management, ICMP). Option B is correct because CoPP is attached with the service-policy command under the global control-plane configuration mode (control-plane / service-policy input <name>), which is the only place a CoPP policy can be bound. Option C is correct because a single CoPP policy-map can contain match statements for both IPv4 and IPv6 (and other protocols such as ARP or MPLS), allowing one unified policy to police both address families. Option D is not correct because CoPP targets traffic destined to the control plane, not transit (data-plane) traffic, which is handled by normal interface QoS. Option E is not correct because there is no implicit permit-all default for CoPP; if a policy is applied, unmatched traffic falls to the class-default action defined in the policy-map, and once CoPP is configured, only explicitly permitted or policed classes are handled as defined.

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.