mediumMultiple Choice
350-401 Practice Question: Is configuring CoPP on a Cisco router to protect…
A network engineer is configuring CoPP on a Cisco router to protect the control plane from excessive traffic. The router experiences high CPU utilization due to SSH and SNMP traffic. The engineer creates a class-map to match SSH (TCP/22) and SNMP (UDP/161) and applies a policy-map that polices this traffic to 1 Mbps. After applying the policy, legitimate SSH sessions from the management station start dropping intermittently. What is the most likely cause?
⚠ Common exam trap
Cisco often tests the misconception that a single police rate applied to a class-map containing multiple protocols is sufficient, when in reality the aggregate rate must account for the combined peak traffic of all matched protocols.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The police rate of 1 Mbps is too low for the combined SSH and SNMP traffic from the management station.
The most likely cause is that the police rate of 1 Mbps is too low for the combined SSH and SNMP traffic from the management station. CoPP polices all traffic matching the class-map (SSH and SNMP) as a single aggregate flow. If the management station generates bursts of SSH and SNMP traffic that together exceed 1 Mbps, the policer will drop packets, causing legitimate SSH sessions to drop intermittently.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The police rate of 1 Mbps is too low for the combined SSH and SNMP traffic from the management station.
Why this is correct
The police rate of 1 Mbps is insufficient for the aggregated SSH (TCP/22) and SNMP (UDP/161) control-plane traffic generated by the management station. Under CoPP, the policer uses a token bucket that drops packets exceeding the committed information rate, and if the peak management traffic exceeds 1 Mbps, legitimate packets will be dropped, causing timeouts or loss of management access. The correct remedy is to raise the police rate above the expected combined throughput, not to change the classification or action.
- ✗
The CoPP policy is applied to the wrong interface, affecting transit traffic instead of control plane traffic.
Why it's wrong here
CoPP policies are attached to the device's control plane, not to a physical or logical interface. A policy-map applied to an interface would police transit traffic, not the CPU-bound packets that CoPP is meant to protect; in fact, CoPP uses 'control-plane' global configuration with 'service-policy input'. Since the problem is with control-plane traffic drops, applying the policy to an interface would not fix the issue and would be an invalid configuration, making this option incorrect.
- ✗
The class-map should match on DSCP values instead of port numbers to be effective.
Why it's wrong here
Matching by port number is a valid and standard way to classify control-plane traffic in a class-map. For example, SSH and SNMP are identified by their well-known port numbers, which directly correspond to the protocols; DSCP matching relies on IP header marking that may not be present or reliable from management stations. The class-map is not the problem — the police rate is — so this option is wrong because it misidentifies the root cause.
- ✗
The policy-map should use the 'drop' action instead of 'police' to protect the control plane.
Why it's wrong here
Using 'police' in CoPP is the accepted method to rate-limit control-plane traffic while allowing a conforming rate. If the action were changed to 'drop', the router would unconditionally discard all packets matching the class, including legitimate SSH and SNMP, resulting in complete loss of management access rather than just occasional drops when the rate is exceeded. The correct approach is to keep 'police' and adjust the rate, not to replace it with 'drop'.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.